Journal of International Islamic Law, Human Right and Public Policy
Vol. 4 No. 3 (2026): September

MISUSE OF TAXPAYER DATA FOR PHISING SCAMS

Nuradi Budi Prakoso (Universitas Islam Batik Surakarta)
Hanuring Ayu (Universitas Islam Batik Surakarta)
Hafid Zakaria (Universitas Islam Batik Surakarta)



Article Info

Publish Date
20 Jul 2026

Abstract

The rapid development of Indonesia's digital taxation ecosystem has simultaneously introduced new vulnerabilities that were previously absent in conventional tax administration systems. This research examines the misuse of taxpayer data as the primary instrument in phishing schemes, a phenomenon that not only inflicts financial and psychological harm on individual victims, but also erodes public trust in tax institutions and undermines the broader success of digital government transformation. This study employs a juridical-empirical method with a descriptive-analytical character, integrating statutory and conceptual approaches. The research yields three principal findings. First, taxpayer data occupies a uniquely strategic position as information collected under legal obligation, simultaneously encompassing identity, financial, and asset data, making it a high-value target whose misuse erodes the public trust that underpins Indonesia's self-assessment taxation paradigm. Second, the misuse of taxpayer data in phishing practices occurs through five primary modes, namely counterfeit website creation, mass deceptive messaging, malicious application distribution, voice phishing, and spear phishing, all of which exploit a five-phase exploitation chain and employ psychological manipulation techniques grounded in institutional authority, artificial urgency, and data-driven personalization. Third, the effectiveness of existing regulations, including the Electronic Information and Transactions Law, Law Number 27 of 2022 on Personal Data Protection, and the General Tax Provisions Law, remains insufficient due to fragmentation of legal substance, limited institutional enforcement capacity, and low legal awareness among taxpayers. This research recommends the accelerated operationalization of the Personal Data Protection Authority, the establishment of an integrated cross-institutional phishing detection and response system, and the strengthening of international legal cooperation as integral components of a systemic and sustainable data protection strategy.

Copyrights © 2026






Journal Info

Abbrev

ojs

Publisher

Subject

Religion Law, Crime, Criminology & Criminal Justice

Description

This journal emphasizes specifics in the discourse of Islamic Law and Humanity, as well as communicating actual and contemporary research and problems related to Islamic studies. This journal openly accepts contributions from experts from related scientific disciplines. All articles published do not ...