During the demonstrations rejecting the revision of the TNI Law in Jakarta and Surabaya, a number of demonstrators reported that their accounts were suddenly logged out of Whatsapp. This is not the first time this has happened.
29 Mar 2025 19:30 WIB · English
The accounts of several protest participants opposing the revision of the Indonesian National Armed Forces Law, or UU TNI, were suddenly logged out of WhatsApp during a demonstration in front of the Parliament Building in Jakarta on Thursday (27/3/2025), as tensions escalated. Similar incidents were also reported by protest participants opposing the revision of UU TNI in Surabaya, East Java. Are they being targeted by certain parties for hacking?
The existence of an account of a protester who was logged out of Whatsapp was received and then uploaded by an account on the platform "X" named @barengwarga, after the demonstration rejecting the revision of the TNI Law in Jakarta, Thursday. In the upload titled "Recap Information Today", it was written that some of the protesters' Whatsapp was logged out after the police pushed them back.
During the protest, the police forcibly dispersed the crowd on Thursday night. Chaos inevitably ensued. Bareng Warga is a community that has been consistently critical of government policies. Not only has it been vocal in criticizing the revision of the Military Law, but this community also opposed the 12 percent VAT at the end of last year.
:quality(80):watermark(https://cdn-content.kompas.id/umum/kompas_main_logo.png,-16p,-13p,0)/https://kompasmedia.site/images/2025/03/29/539ddd92760c21560906734b293c7fb4-20250327DNU18.jpg)
In addition to Jakarta, reports of protesters rejecting the revision of the TNI Law being logged out of Whatsapp also emerged from Surabaya. In an upload by one of the accounts on "X", Monday (3/24/2025), a screenshot was shared showing a cellphone with the caption "You have logged out of Whatsapp". "Several cellphones of the masses in Surabaya have been tapped, be careful, friends," wrote the account owner.
On that day, a protest rejecting the revision of the TNI Law indeed took place in Surabaya. The demonstration, carried out by students from various campuses united under the Front Anti-Militarism (FAM), ended in chaos.
With these incidents, is it true that the protesters rejecting the revision of the TNI Law became the target of hacking?
:quality(80):watermark(https://cdn-content.kompas.id/umum/kompas_main_logo.png,-16p,-13p,0)/https://kompasmedia.site/images/2025/03/25/652198548cbe9abe536d7b35504cfe8d-RUU_TNI_06.jpg)
SAFEnet Director Nenden Sekar Arum, when contacted on Saturday (29/3/2025), stated that her organization had received reports of alleged hacking incidents in Jakarta and Surabaya. SAFEnet, an organization focused on advocating for digital security and rights, is currently investigating the matter further.
From the temporary investigation, if we look at the pattern that occurred, Nenden continued, it was indicated as a network disruption, although he did not rule out the possibility of hacking attempts on the protesters. The indication of a network disruption was because looking at the case in Surabaya, as far as the information received by SAFEnet, those who were logged out were not only activists, but on a wider scale, namely the general public and online motorcycle taxi drivers who happened to be passing by.
"If the specific numbers affected are related to the protest participants, it could be a sign of a more targeted operation to disrupt their coordination. However, if it is random and widespread, it is highly likely to be a network disruption," explained Nenden.
:quality(80):watermark(https://cdn-content.kompas.id/umum/kompas_main_logo.png,-16p,-13p,0)/https://asset.kgnewsroom.com/photo/pre/2025/02/18/c307adff-c3d8-4b45-8e97-6d9ba700031b_jpg.jpg)
Nevertheless, according to Nenden, there is a worst-case scenario beyond all those possibilities, namely the likelihood of a specific device intentionally used to disrupt connections within a certain radius. Such technology has the capability to attack the Whatsapp application protocol on a large scale.
From the existing references, according to him, the method is not impossible. Because, often surveillance operations are packaged as if "targeted" or specifically targeted, even though the effects are mass.
Kompas notes that this is not the first time that an activist's account has been removed from WhatsApp.
During the mass demonstrations rejecting the extension of the president's term in March 2022, a number of student activists claimed to have experienced something similar. The Whatsapp account suddenly came out with a statement that the number had been operated on another device. This was as stated by the Coordinator of the All-Indonesian Student Executive Board (BEM SI) at that time, Kaharuddin.
:quality(80)/https://asset.kgnewsroom.com/photo/pre/2022/04/22/15504e12-21c8-4b87-9aa1-2a549b6b2462_png.png)
If it is true that all these incidents were the result of hacking, it means that the list of cyber attacks on activists is getting longer.
In mid-2021, the social media accounts of five members of the University of Indonesia Student Executive Board (BEM UI), consisting of 3 Whatsapp accounts, 1 Telegram account, and 1 Instagram account, were hacked. The attack occurred after they uploaded a picture of President Joko Widodo accompanied by criticism of his track record of statements that contradicted his policies with the title "Jokowi: The King of Lip Service".
In the same year, the social media accounts of activists from Indonesia Corruption Watch (ICW), the Legal Aid Institute (LBH), and Lokataru were also terrorized when they were holding a press conference criticizing the national insight test (TWK) as one of the requirements for the change of status of Corruption Eradication Commission (KPK) employees to state civil servants (ASN). Similar attacks also hit several KPK employees who did not pass the TWK.
A year earlier, activist Ravio Patra's Whatsapp account was suspected of being hacked. Despite having done double security with fingerprints and two-way verification, Ravio's Whatsapp account could still be hacked by a party whose whereabouts are still unknown.
:quality(80):watermark(https://cdn-content.kompas.id/umum/kompas_main_logo.png,-16p,-13p,0)/https://asset.kgnewsroom.com/photo/pre/2021/10/28/Cover-Turvis-HKT_1635435552_jpg.jpg)
Citing research conducted by the Partnership, attacks or threats using electronic means were one of the five highest types of attacks against human rights defenders from November 2014 to December 2023. The other four attacks were judicial harassment or misuse of the law to silence criticism, then terror and threats, expulsion or disbandment, and persecution.
Executive Director of the Institute for Study and Advocacy (Elsam) Wahyudi Djafar, is of the view that digital attacks have become a threat to democracy and human rights activists. One form is the takeover of short message application accounts such as Whatsapp or social media accounts.
The hacking doesn't stop there. After someone's account is hacked, what often happens is doxing or the dissemination of personal information to the public without permission. "The personal data is opened as a form of pressure or intimidation by embarrassing the activist or individual being targeted," Wahyudi said.
:quality(80)/https://asset.kgnewsroom.com/photo/pre/2019/11/21/b417b11b-bf21-4469-8814-10600fec032f_jpg.jpg)
From a regulatory perspective, Wahyudi said, hacking accompanied by doxing is subject to criminal penalties as regulated in the Law on Information and Electronic Transactions (UU ITE).
However, so far, reports of alleged hacking to the police have never been followed up to completion.
The incomplete report is suspected to have occurred because the hackers are state agents or security forces. The action is also expected to be more massive because they periodically update special monitoring devices or machines that are increasingly sophisticated so that they are able to penetrate the security systems of various applications.
On the other hand, society does not have a mechanism to ensure that state apparatus or security forces do not use surveillance tools to intrude on citizens for security reasons. In fact, what the citizens do is not related to national security threats.
"In my opinion, today's situation is quite worrying. We do not have any rules on privacy protection for surveillance carried out by state apparatus. There is also no accountability for the use of surveillance tools in the name of national security and intelligence work," explained Wahyudi.
:quality(80):watermark(https://cdn-content.kompas.id/umum/kompas_main_logo.png,-16p,-13p,0)/https://asset.kgnewsroom.com/photo/pre/2024/05/28/1f547dac-ddde-48e5-9b36-5dc53d06e5b5_jpg.jpg)
Likewise, Amnesty International Indonesia Executive Director Usman Hamid is of the view that alleged hacking or cyber attacks on activists still have the potential to continue to occur.
Not only to intimidate, but also to prevent the targeted party from continuing their actions. Because, the actions carried out are what the perpetrators do not want.
"So, if the victim's activity is to reject the TNI Law, then the perpetrators are people who could be interested parties behind the TNI Law," said Usman.
According to Usman, cyber attacks through hacking of personal numbers and social media accounts are very worrying for democracy in Indonesia.
As a result, the V-Dem democracy index, which is recognized as very credible in the world, has now placed Indonesia no longer as a democracy, but rather an electoral autocracy because the Indonesian political system only has elections. Meanwhile, there is no space for civil liberties for activists and critical citizens. In addition, there is no political space for opposition parties in parliament.
Writer:
Norbertus Arya Dwiangga MartiarEditor:
A. Ponco Anggoro