The expansion of digital services has increased exposure to cybercrime, particularly phishing-based hacking and personal data theft. This study analyzes Indonesian criminal-law regulation of illegal access and personal data misuse, evaluates law-enforcement implementation under the Electronic Information and Transactions framework, and examines criminal liability in Decision Number 958/Pid.Sus/2020/PN Pbr. A normative juridical design was applied using statutory, conceptual, and case approaches, with secondary legal materials consisting of legislation, legal literature, and the court decision. The analysis shows that current cybercrime regulation operates through an integrated framework combining Law Number 1 of 2024 on Electronic Information and Transactions and Law Number 27 of 2022 on Personal Data Protection. Enforcement nevertheless remains constrained by offender anonymity, digital-evidence complexity, and cross-border jurisdiction. The examined decision established criminal responsibility for phishing and carding, but the sentence of one year and two months was relatively limited when viewed against the present legal framework. Effective enforcement should therefore combine proportional punishment, stronger digital-forensic capacity, and mechanisms that restore victims' economic and privacy rights.
Copyrights © 2026