OJK Urged to Verify Digital Evidence in BCA QRIS Dispute

Swan.my.id - Jakarta, the BCA QRIS transaction dispute has prompted a call for the Financial Services Authority (OJK) to ensure that digital security checks are carried out effectively, rather than relying only on general security reminders.
Uchok Sky Khadafi highlighted the risks of hacking, malware, and account takeover in digital banking transactions. He said OJK should ensure that the examination of the relevant digital systems can clarify how a disputed payment occurred.
The dispute involves Bambang Suryadi, who said his account balance fell by Rp6 million through a QRIS payment he did not make. BCA, however, stated that the transaction was valid after its system recorded the use of the correct BCA ID and PIN.
How the BCA QRIS Transaction Dispute Started
Bambang discovered the Rp6 million deduction on Wednesday, March 18, 2026. Digital transaction records in myBCA showed that the payment went to QRIS merchant Naya Cepat Topup at 13:43:14 Western Indonesia Time.
The transaction was marked successful and carried reference number 9527120260318134309856QRS0371247926. The record showed that the payment reduced Bambang’s account balance by Rp6 million.
Bambang had previously filed a complaint by telephone on the same day. His complaint was registered under Request ID 1979238184. He also said he had lost another Rp1 million through a mysterious transaction in early February 2026.
BCA Relies on System Records and PIN Use
In a letter numbered 5919/HBS2-CRM/IV/2026 and dated April 7, 2026, BCA stated that the transaction was valid. The bank’s management said the payment was made through myBCA using the correct BCA ID and PIN.
BCA based its position on supporting data recorded by the bank’s system. However, Bambang denied making the payment, creating a dispute over whether the system records alone sufficiently explain who initiated the transaction and how access was obtained.
Calls for a More Thorough Digital Examination
Uchok asked OJK not to stop at security appeals. He urged the regulator to make sure that an effective examination of the digital system takes place when a customer continues to deny a disputed transaction.
The concerns include possible hacking, malware, and account takeover. These risks can complicate the assessment of a digital payment because the presence of a correct user ID and PIN does not, by itself, explain the circumstances surrounding a disputed transaction.
According to CBA, banks need to be able to explain the technical evidence behind a transaction when a customer denies making the payment. Such evidence is important in determining whether the transaction resulted from authorized customer activity or unauthorized access.
The case therefore places attention on the role of technical verification in banking complaints. A clear examination could help explain the transaction trail, while also giving both the customer and the bank a stronger basis for resolving the dispute.
Why Technical Evidence Matters
Digital transaction records are central to banking disputes, but customers and regulators may also need a broader explanation of the security events surrounding a payment. This includes examining the possibility of compromised access, as raised in the call for OJK oversight.
For the BCA QRIS transaction dispute, the main question remains how the Rp6 million payment was initiated while Bambang maintained that he never made it. OJK’s role is being questioned because the complaint was not resolved through the bank’s existing mechanism.
A clear and effective examination could help establish whether the available records fully account for the transaction. It could also clarify what technical evidence should be presented when a customer challenges the validity of a digital payment.
What Remains to Be Clarified
The available positions remain different. BCA considers the payment valid because its system recorded the correct BCA ID and PIN, while Bambang rejects the transaction and says his balance was reduced without authorization.
Uchok’s request focuses on verification rather than security reminders alone. The outcome depends on whether the digital examination can provide a convincing explanation of the transaction and address the risks of hacking, malware, or account takeover.