Bank Syariah Indonesia (BSI)'s mobile banking application, BSI Mobile, experienced a disruption starting Monday, May 8, 2023, and had not fully recovered by Wednesday afternoon, May 10, 2023.
BSI management stated they were performing application maintenance.
"We inform you that Bank Syariah Indonesia is currently performing system maintenance, resulting in temporary inaccessibility. The system will return to normal as soon as possible," said BSI management on Tuesday, May 9, 2023.
However, Heru Sutadi, Executive Director of the ICT Institute, suggested the possibility of a cyberattack on BSI Mobile.
"It's highly likely that BSI experienced a cyberattack, possibly resulting in a system lockout, or it's not impossible that they were hit by ransomware," Heru told Katadata on Tuesday, May 9, 2023.
This alleged cyberattack on the application system appears to be the first of its kind for BSI.
According to BSI's sustainability report, they identified over a thousand cybercrime threats throughout 2022, but none involved ransomware attacks.
In 2022, BSI detected 1,767 attempts of phishing/social engineering against its customers.
Phishing is a cybercrime involving the sending of fake website addresses to customers, designed to closely resemble legitimate websites.
This aims to deceive customers into entering their personal information on the fake website, such as usernames, passwords, PIN numbers, and so on.
Social engineering is a form of phishing where perpetrators contact customers via phone, text message, or other media, directing them to specific websites for similar data theft purposes.
Throughout 2022, BSI also identified 232 suspected skimming cases on the Prima ATM network and 64 cases on the Bersama ATM network.
Skimming is an attempt to steal ATM card data. This cybercrime can be committed by installing hidden cameras on ATMs to capture customers' PIN numbers.
Skimming can also be done by installing a special device in the ATM card slot to digitally copy customer ATM card data.
Despite these findings, BSI claims that customer data security remains intact.
"Throughout 2022, there were no complaints regarding customer data loss with material impact, and no breaches of customer privacy," stated BSI management in their sustainability report released last month (April 28, 2023).
BSI also stated that they have a Chief Information Security Officer (CISO) group responsible for safeguarding customer data and privacy.
"The CISO routinely conducts security awareness activities, strengthens security parameters (firewall, waf, threatintel), performs penetration testing as required, and performs take-down services to detect fraud. CISO mitigation is carried out through Digital Threat Monitoring, a layered security test," said BSI.