Cybersecurity research podcast
Cryptocurrency as a Payment Method for Ransomware Cybercrime Lockbit Ransomware and the Implementation of Cyberlaw and Cybersecurity
Using a normative legal analysis of Indonesian criminal, electronic-information and personal-data law, the paper argues that cryptocurrency enables LockBit ransom payments, while leaked wallet addresses and blockchain forensics can support tracing and possible wallet freezes. Enforcement remains difficult because attackers use TOR/VPN and international perpetrators present jurisdictional difficulties, while Indonesian regulations are not yet specific to cryptocurrency ransom and do not fully capture double extortion.
Episode 31 Aug 2026 · Paper 19 Jul 2026 · Legalita · VERSION of RECORD
Research summary
A technical explanation of the paper's research question, method, reported findings and limitations. The analysis treats cryptocurrency in Indonesia as a regulated crypto-asset commodity rather than legal tender. On that basis, LockBit transactions do not qualify as legal payments, although they may remain valid as commodity exchanges carrying civil risks.…
Directly addresses LockBit ransom payments, response controls, and Indonesian cyberlaw, but practitioner value is limited by a normative legal method and operational claims that lack clear validation, baselines, or reproducible tracing results.
Paper details
Authors: Seri Mughni Sulubara , Rizky Maulana , Nurkhalisah
Transcript
Highlighting follows the podcast. Select any word to seek.
Cryptocurrency as a Payment Method for Ransomware Cybercrime Lockbit Ransomware and the Implementation of Cyberlaw and Cybersecurity. In 2026, Seri Mughni Sulubara, Rizky Maulana and Nurkhalisah examine cryptocurrency ransom payments in LockBit attacks, their treatment under Indonesian law and accountability within the surrounding ecosystem. The study also aims to formulate recommendations for strengthening cybersecurity policy and practice in Indonesia.
LockBit uses an affiliate-based ransomware model. The operators supply encryption tools, leak infrastructure and negotiation support, while affiliates conduct intrusions. The described revenue model gives affiliates 80% of a ransom and the operators a 20% commission. Cryptocurrency suits this structure because transfers are pseudonymous, cross borders and are relatively difficult to trace through conventional financial systems. Even so, blockchain transactions can be analyzed, wallets mapped and some crypto assets frozen.
The research asks how cryptocurrency functions within LockBit ransom operations, whether Indonesian cyberlaw adequately addresses those payments and how cybersecurity policy and practice could be strengthened. The dilemma is practical as well as legal: ransom payments may be treated as support for crime or as an emergency right, while also creating potential money-laundering or sanctions exposure. Incidents affecting Indonesia’s National Data Center and Bank Syariah Indonesia provide the setting for that question, including service disruption and leaked personal data.
The authors use a normative legal approach. In plain English, they analyze LockBit-related legal questions using Indonesian criminal, electronic-information and personal-data law. They use that analysis to characterize cryptocurrency ransom payments, assess existing cyberlaw regulation and formulate coordinated responses for government, law enforcement and the digital industry.
The analysis treats cryptocurrency in Indonesia as a regulated crypto-asset commodity rather than legal tender. On that basis, LockBit transactions do not qualify as legal payments, although they may remain valid as commodity exchanges carrying civil risks. Refusing payment can weaken the ransomware business incentive but leave victims facing prolonged downtime and a permanent risk of data loss when backups are inadequate. Paying may create exposure to money-laundering rules or international sanctions.
The technical evidence discussed includes a leak containing 60,000 LockBit Bitcoin addresses. The analysis says those addresses reveal transaction patterns that investigators can trace. More broadly, blockchain records can support wallet mapping and, in some international operations, asset freezing. Attackers' use of network anonymity tools still makes enforcement difficult. The analysis also identifies the possibility of freezing wallets through PPATK and Bappebti.
The analysis applies an Indonesian legal framework to ransomware that spans criminal law, extortion, personal-data protection and crypto-asset regulation. Those regimes cannot be considered separately. Practical enforcement is also difficult: the analysis notes no recorded successful Indonesian cases against foreign hackers and says perpetrators in Russia or Ukraine are difficult to reach.
For defenders, the weaknesses identified include poor network segmentation, weak patch management and the absence of secure, regularly tested backups. Organizational gaps also include limited incident rehearsal, unclear response procedures and no established policy for accepting or refusing ransom demands. During an incident, preserve wallet details, ransom communications and forensic evidence, then report through established law-enforcement and cyber-response channels. IP traces, crypto wallets and screenshots of leak sites can form part of the evidence. A refusal policy can lead to prolonged downtime, while inadequate backups create a permanent risk of data loss.
The contribution is a combined view of ransomware response, cryptocurrency evidence and the Indonesian legal regimes that apply. Organizations can connect recovery and escalation policy by preparing tested backups, rehearsing incident decisions and retaining evidence such as IP traces and crypto-wallet information. They should account for prolonged downtime after refusing payment and for enforcement difficulty when attackers use network anonymity tools.