Cryptocurrency as a Payment Method for Ransomware Cybercrime Lockbit Ransomware and the Implementation of Cyberlaw and Cybersecurity. In 2026, Seri Mughni Sulubara, Rizky Maulana and Nurkhalisah examine cryptocurrency ransom payments in LockBit attacks, their treatment under Indonesian law and accountability within the surrounding ecosystem. The study also aims to formulate recommendations for strengthening cybersecurity policy and practice in Indonesia. LockBit uses an affiliate-based ransomware model. The operators supply encryption tools, leak infrastructure and negotiation support, while affiliates conduct intrusions. The described revenue model gives affiliates 80% of a ransom and the operators a 20% commission. Cryptocurrency suits this structure because transfers are pseudonymous, cross borders and are relatively difficult to trace through conventional financial systems. Even so, blockchain transactions can be analyzed, wallets mapped and some crypto assets frozen. The research asks how cryptocurrency functions within LockBit ransom operations, whether Indonesian cyberlaw adequately addresses those payments and how cybersecurity policy and practice could be strengthened. The dilemma is practical as well as legal: ransom payments may be treated as support for crime or as an emergency right, while also creating potential money-laundering or sanctions exposure. Incidents affecting Indonesia's National Data Center and Bank Syariah Indonesia provide the setting for that question, including service disruption and leaked personal data. The authors use a normative legal approach. In plain English, they analyze LockBit-related legal questions using Indonesian criminal, electronic-information and personal-data law. They use that analysis to characterize cryptocurrency ransom payments, assess existing cyberlaw regulation and formulate coordinated responses for government, law enforcement and the digital industry. The analysis treats cryptocurrency in Indonesia as a regulated crypto-asset commodity rather than legal tender. On that basis, LockBit transactions do not qualify as legal payments, although they may remain valid as commodity exchanges carrying civil risks. Refusing payment can weaken the ransomware business incentive but leave victims facing prolonged downtime and a permanent risk of data loss when backups are inadequate. Paying may create exposure to money-laundering rules or international sanctions. The technical evidence discussed includes a leak containing 60,000 LockBit Bitcoin addresses. The analysis says those addresses reveal transaction patterns that investigators can trace. More broadly, blockchain records can support wallet mapping and, in some international operations, asset freezing. Attackers' use of network anonymity tools still makes enforcement difficult. The analysis also identifies the possibility of freezing wallets through PPATK and Bappebti. The analysis applies an Indonesian legal framework to ransomware that spans criminal law, extortion, personal-data protection and crypto-asset regulation. Those regimes cannot be considered separately. Practical enforcement is also difficult: the analysis notes no recorded successful Indonesian cases against foreign hackers and says perpetrators in Russia or Ukraine are difficult to reach. For defenders, the weaknesses identified include poor network segmentation, weak patch management and the absence of secure, regularly tested backups. Organizational gaps also include limited incident rehearsal, unclear response procedures and no established policy for accepting or refusing ransom demands. During an incident, preserve wallet details, ransom communications and forensic evidence, then report through established law-enforcement and cyber-response channels. IP traces, crypto wallets and screenshots of leak sites can form part of the evidence. A refusal policy can lead to prolonged downtime, while inadequate backups create a permanent risk of data loss. The contribution is a combined view of ransomware response, cryptocurrency evidence and the Indonesian legal regimes that apply. Organizations can connect recovery and escalation policy by preparing tested backups, rehearsing incident decisions and retaining evidence such as IP traces and crypto-wallet information. They should account for prolonged downtime after refusing payment and for enforcement difficulty when attackers use network anonymity tools.