ReportJuly 28, 202610 min read

Phishing Benchmarks for Indonesian Organisations: What Published Data Shows

A synthesis of published 2025 and 2026 figures from BSSN and the Verizon DBIR, assembled for Indonesian security teams who need defensible external reference points. Not original research, and the gaps are stated as plainly as the numbers.

What this is, and what it is not

This is a synthesis of publicly published figures, not original research. Every number below is attributed to its source, and where no credible published figure exists we say so rather than estimating. We have deliberately not published aggregate data from Claro customers.

That matters because benchmark documents get cited. A phish-prone figure quoted in a board pack or a supervisory submission needs a traceable source, and a vendor-authored number with no stated methodology is not one. If you take figures from this page, cite the original source rather than us.

The most useful finding is a gap. **No public, sector-level phish-prone benchmark for Indonesia currently exists.** Global benchmarks are published, and Indonesian national threat telemetry is published, but nothing bridges them. If you need an Indonesian sector comparison today, you have to generate it from your own baseline, which is covered in the last section.

The human element: what the Verizon DBIR 2026 reports

The Verizon Data Breach Investigations Report is the most widely cited source for human-factor benchmarks and is global rather than Indonesia-specific. Its 2026 edition reports that 62 percent of breaches involved the human element, and that social engineering was the third most frequent breach pattern at 16 percent of all breaches.

We have deliberately not quoted a financial-services-specific human-factor percentage here. Secondary sources circulate one, but it appears to restate the DBIR's prior-year general figure of 60 percent rather than a sector breakdown, and we could not verify it against the primary report. The DBIR does publish industry sections, so if you need a financial-services figure, take it from the report itself rather than from any secondary summary including this one.

The figure worth carrying into a board discussion is the first one. If roughly six in ten breaches involve a person, then human risk is not a training line item, it is a majority share of the risk surface.

Simulation click rates, and why channel changes them

The DBIR 2026 reports median simulation click rates of 1.4 percent for email and 2 percent for phone-centric phishing, meaning a roughly 40 percent higher click rate when the attacker moves off the inbox. It also reports that 41 percent of social engineering breaches now involve vectors other than email.

On volume, it reports large organisations seeing a median of 48 SMS-based phishing campaigns targeting mobile devices per year, against a median of 12 for smaller organisations. Roughly a quarter of social action vectors came from social media or phones.

Two cautions before you compare your own numbers to these. Median simulation click rates are heavily shaped by which vendors contributed data and how each defines a click, so they are not a like-for-like target. And a low email click rate says nothing about your exposure on WhatsApp, which for most Indonesian organisations is the busier channel.

Indonesian national telemetry: what BSSN reports

BSSN reported approximately 5.2 billion anomalous internet traffic events directed at Indonesia between January and mid-November 2025, an average of around 182 per second. Of those, 93.78 percent were categorised as malware activity. Note the sourcing: these are official BSSN statements reported through Indonesian media in December 2025, not figures taken from a BSSN publication. At the time of writing, BSSN's most recent published Lanskap Keamanan Siber report covers 2024.

The most frequently detected malware families in 2025 were Mirai Botnet, followed by Remcos RAT and generic trojans. BSSN has also highlighted attackers using AI to make phishing more convincing, including deepfake voice, fabricated video and personalised messaging.

Read what this does and does not tell you. It is network-level telemetry, so it measures attack volume against Indonesia, not how often Indonesian employees fall for phishing. It is evidence of exposure, not of susceptibility, and conflating the two produces board reporting that cannot withstand a follow-up question.

Reading the two sources together

The global data says most breaches run through people, and that attackers are moving off email. The Indonesian data says the volume aimed at this country is very large and dominated by malware, led by a botnet family and trojans. Those are consistent, and together they point somewhere specific.

Mirai recruits devices into botnets, and trojans require a person to install them. In Indonesia the dominant delivery mechanism for that installation is the malicious Android APK circulated through WhatsApp, disguised as an invitation, receipt or tax document. That is the point where national telemetry and human risk actually meet.

The practical implication is that an email-only awareness programme is measuring the wrong channel. If national telemetry is dominated by malware whose main consumer delivery route is a messaging app, then WhatsApp and SMS susceptibility is not an advanced consideration, it is the baseline.

Building your own baseline, since no Indonesian sector benchmark exists

Given the gap, the defensible approach is an internal baseline rather than a borrowed number. Run an unannounced baseline campaign in Bahasa Indonesia, using scenarios drawn from what circulates locally rather than translated English templates, and record click, submit and report rates separately.

Segment before you compare. A single organisation-wide percentage hides the distribution that matters, which is usually concentrated in specific departments and roles. Track the trend across at least three campaigns, because one campaign is a measurement and three is a direction.

Then define your metric in writing and keep the definition stable. Whether an open counts, whether reports offset clicks, and how repeat clickers are weighted all change the number. A documented internal definition trended over four quarters is more defensible to a supervisor than any external benchmark you could quote.

Sources, and how to cite them

Global human-factor and simulation figures on this page are from the Verizon Data Breach Investigations Report 2026, a primary published document covering more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries. Cite it directly: Verizon, 2026 Data Breach Investigations Report, published 2026, at verizon.com/business/resources/reports/dbir. Its industry sections are the correct place to look for a financial-services breakdown.

Indonesian threat-volume figures require a more careful citation, because the 2025 numbers have not yet appeared in a BSSN publication. They are official BSSN statements carried by Indonesian media in December 2025. If you need a citable BSSN document rather than a press statement, the most recent published edition is Lanskap Keamanan Siber Indonesia 2024, issued by BSSN with Id-SIRTII/CC in February 2025, at bssn.go.id. Expect a 2025 edition in due course, and prefer it over this page once it exists.

The distinction matters more than it might appear. An official statement reported in the press is genuine and attributable, but it is not a document with a stated methodology, and a supervisor or auditor may reasonably ask which one you relied on. Where we could only reach a figure through secondary reporting we have said so on this page rather than presenting it as though we had read the primary source.

Key takeaways

  • This is a synthesis of published sources, not Claro customer data. The DBIR is a primary published document; the BSSN 2025 figures are official statements via press, since no BSSN publication covers 2025 yet.
  • No public sector-level phish-prone benchmark for Indonesia currently exists; that gap is the most useful finding here.
  • Verizon DBIR 2026: 62 percent of breaches involved the human element, and social engineering was 16 percent of breaches.
  • DBIR 2026 median simulation click rates were 1.4 percent for email and 2 percent for phone-centric phishing, and 41 percent of social engineering breaches used non-email vectors.
  • BSSN reported roughly 5.2 billion anomalous traffic events aimed at Indonesia in 2025, 93.8 percent malware-related, led by Mirai Botnet and trojans.
  • BSSN telemetry measures exposure, not susceptibility. Do not present attack volume as evidence of workforce risk.
  • Because no local benchmark exists, build an internal baseline in Bahasa Indonesia with a documented metric definition and trend it.

Frequently asked questions

  • No credible public figure exists for Indonesia specifically. Global medians are published, most recently 1.4 percent for email and 2 percent for phone-centric simulations in the Verizon DBIR 2026, but these are not Indonesian sector figures and vendor definitions of a click differ. The defensible answer is to establish your own baseline.

Build a program that sticks

Claro helps you run simulation, training, and reporting in one place.

Request a demo