TINJAUAN HUKUM PIDANA TERHADAP KEJAHATAN RANSOMWARE DALAM PERSPEKTIF UNDANG-UNDANG NOMOR 19 TAHUN 2016 DAN UNDANG-UNDANG NOMOR 1 TAHUN 2023 | ELECTRONIC THESES AND DISSERTATION

Electronic Theses and Dissertation

Universitas Syiah Kuala

    SKRIPSI

TINJAUAN HUKUM PIDANA TERHADAP KEJAHATAN RANSOMWARE DALAM PERSPEKTIF UNDANG-UNDANG NOMOR 19 TAHUN 2016 DAN UNDANG-UNDANG NOMOR 1 TAHUN 2023


Pengarang

T. Andrian Firdaus - Personal Name;

Dosen Pembimbing

Aldisa Melissa - 199107152022032015 - Dosen Pembimbing I



Nomor Pokok Mahasiswa

2103101010216

Fakultas & Prodi

Fakultas Hukum / Ilmu Hukum (S1) / PDDIKTI : 74201

Subject
-
Kata Kunci
-
Penerbit

Banda Aceh : Fakultas Hukum., 2026

Bahasa

No Classification

-

Literature Searching Service

Hard copy atau foto copy dari buku ini dapat diberikan dengan syarat ketentuan berlaku, jika berminat, silahkan hubungi via telegram (Chat Services LSS)

Kejahatan ransomware yang mengenkripsi data semakin mengancam keamanan cyber Indonesia, dibuktikan serangan ransomware terhadap Pusat Data Nasional pada Juni 2024 yang melumpuhkan 210 instansi pemerintah. Sementara Pasal 30 ayat (1) UU ITE, Pasal 32 ayat (1) UU ITE dan Pasal 332 ayat (1) KUHP belum mengatur secara jelas tentang delik kejahatan ransomware secara eksplisit atau secara khusus.

Tujuan penulisan skripsi ini adalah untuk menjelaskan kualifikasi delik terhadap ransomware menurut Undang-Undang Nomor 19 Tahun 2016 dan Undang-Undang Nomor 1 Tahun 2023, serta untuk menjelaskan harmonisasi Undang-Undang Nomor 19 Tahun dan Undang-Undang Nomor 1 Tahun 2023 dalam penanggulangan kejahatan ransomware.

Penelitian ini menggunakan metode yuridis-normatif dengan pendekatan perbandingan perundang-undangan dan doktrinal yang menganalisis persamaan dan perbedaan aturan serta mengidentifikasi kelebihan dan kekurangan dari masing-masing kebijakan hukum. Data yang diperoleh menggunakan pendekatan perundang-undangan, pendekatan konseptual yang memberikan sudut pandang analisa penyelesaian permasalahan dalam penelitian hukum dilihat dari aspek konsep-konsep hukum yang melatar belakanginya.

Hasil penelitian menjelaskan bahwa kualifikasi delik pada kejahatan ransomware dapat dikualifikasikan sebagai delik formil berdasarkan unsur-unsur pada Pasal 30 ayat (1) UU ITE untuk fase akses ilegal dan Pasal 32 ayat (1) UU ITE untuk fase enkripsi data, sementara Pasal 332 ayat (1) KUHP hanya menjangkau fase penerobosan sistem tanpa mengatur enkripsi paksa data. Harmonisasi ketiga pasal tersebut diwujudkan melalui model kumulatif-komplementer berdasarkan asas lex specialis derogat legi generali yang menempatkan UU ITE sebagai instrumen utama yang tidak dapat digantikan oleh KUHP, mengingat KUHP tidak mengatur perbuatan manipulasi dan enkripsi paksa data elektronik yang merupakan karakteristik utama serangan ransomware.

Disarankan kepada pembuat Undang-Undang untuk memperjelas rumusan pada Pasal 30 ayat (1) UU ITE terkait teknik infiltrasi ransomware dan menegaskan bahwa enkripsi paksa data masuk dalam kualifikasi perbuatan "mengubah" dan "menyembunyikan" dalam Pasal 32 ayat (1) UU ITE. Disarankan kepada penegak hukum untuk melakukan penyesuaian antara Pasal 30 ayat (1), Pasal 32 ayat (1) UU ITE dan Pasal 332 ayat (1) KUHP perlu ditegaskan penerapan kumulatif-komplementer ketiganya, di mana UU ITE sebagai lex specialis tidak dapat digantikan oleh KUHP dalam penanggulangan kejahatan ransomware.

Ransomware attacks, which encrypt electronic data and render it inaccessible, have become an increasingly serious threat to Indonesia’s cybersecurity. This is evidenced by the ransomware attack on the National Data Center (Pusat Data Nasional) in June 2024, which disrupted the operations of 210 government institutions. However, Article 30(1) and Article 32(1) of Law No. 19 of 2016 concerning Electronic Information and Transactions (ITE Law), as well as Article 332(1) of Law No. 1 of 2023 concerning the Criminal Code (KUHP), do not explicitly or specifically regulate ransomware as a distinct criminal offense. This thesis aims to examine the legal classification of ransomware offenses under Law No. 19 of 2016 and Law No. 1 of 2023, and to analyze the harmonization of these two statutes in addressing and combating ransomware-related cybercrime. This study employs a normative juridical research method using statutory comparative and doctrinal approaches. These approaches are utilized to analyze the similarities and differences between the relevant legal provisions and to identify the respective strengths and weaknesses of each legal policy. The research relies on statutory and conceptual approaches, with the latter providing an analytical framework for resolving legal issues based on the underlying legal concepts. The findings demonstrate that ransomware may be classified as a formal offense (delik formil). The illegal access phase falls within the scope of Article 30(1) of the ITE Law, while the data encryption phase is covered by Article 32(1) of the ITE Law. By contrast, Article 332(1) of the Criminal Code is limited to unauthorized system intrusion and does not encompass the compulsory encryption of electronic data. The harmonization of these provisions is achieved through a cumulative-complementary model based on the principle of lex specialis derogat legi generali, under which the ITE Law functions as the primary legal instrument and cannot be supplanted by the Criminal Code. This is because the Criminal Code does not regulate the manipulation and forced encryption of electronic data, which constitute the defining characteristics of ransomware attacks. Accordingly, it is recommended that the legislature clarify the wording of Article 30(1) of the ITE Law to expressly encompass ransomware infiltration techniques and explicitly affirm that the forced encryption of electronic data falls within the scope of the acts of “altering” and “concealing” as provided under Article 32(1) of the ITE Law. It is further recommended that law enforcement authorities adopt a cumulative-complementary application of Article 30(1), Article 32(1) of the ITE Law, and Article 332(1) of the Criminal Code, while reaffirming that the ITE Law, as the lex specialis, remains the primary legal basis and cannot be replaced by the Criminal Code in the prosecution and prevention of ransomware offenses.

Citation



    SERVICES DESK