This study aims to analyze the allocation of legal responsibility between banks and customers for losses caused by social engineering in digital banking transactions under Articles 1365 and 1366 of the Indonesian Civil Code and Financial Services Authority Regulation (POJK) Number 22 of 2023. This study employs normative legal research using statutory and conceptual approaches. The results indicate that responsibility cannot be determined solely from the fact that a customer disclosed authentication information. The assessment must consider the bank’s duty to maintain system security, provide adequate risk information and education, detect anomalous transactions, and respond effectively to complaints, while also considering the customer’s contribution to the occurrence or escalation of the loss. Four analytical indicators are proposed: the sophistication of the modus operandi, the availability of warnings, compliance with security procedures, and the bank’s response to complaints. POJK Number 22 of 2023 provides an important sectoral framework for consumer protection, but its provisions remain relatively general and do not establish a uniform quantitative formula for allocating liability. Therefore, the principles of unlawful acts and negligence under the Civil Code should be harmonized with the prudential, consumer-protection, and information-security obligations imposed by POJK Number 22 of 2023 to provide a more predictable and proportionate framework for resolving social-engineering disputes.
Copyrights © 2026