Daily activities in the digital realm expose content creators and young journalists to an increasingly diverse range of security risks. Tactics such as fake sponsorship offers, malicious APK files, doxing, and AI-driven face and voice manipulation were among the issues analyzed during the "Digital Security Training for Young Content Creators" workshop, part of the Gen Z Impact Fest 2026 event series.
Held concurrently in a room at the UC Hotel UGM, Yogyakarta, on Saturday (September 12, 2026), the session featured Asep Saefullah—a Digital Journalist Advisor (DJA) for International Media Support (IMS)—as the facilitator. He was joined by two speakers: Reren Indranila, founder of Celebrithink.com and a digital security trainer; and Arsito Hidayatullah, Executive Editor of Suara.com and a GNI fact-checking trainer.
At its core, the session focused on the practical needs of content creators and media managers regarding the protection of digital assets. Asep opened the session by outlining the shifting landscape of the local media business.
According to Asep, the decline in digital advertising revenue over the past three years has compelled media outlets and content creators to seek new income streams through programs, events, and community collaborations. Consequently, he noted, account security has become fundamental to the sustainability of the digital ecosystem.
"Digital security serves as the most fundamental pillar. You shouldn't let digital assets—built over years and boasting large followings—vanish in an instant simply due to negligence regarding basic cyber security measures," Asep said during his presentation at Gen Z Impact Fest on Saturday (September 12, 2026).
During her presentation, Reren outlined why content creators are attractive targets for cybercriminals. She noted that the habit of uploading content one to three times a day creates an exposed digital footprint. Accounts with thousands or even millions of followers hold significant economic value, making them prime targets for takeover attempts.
One notable tactic involves phishing disguised as sponsorship offers worth tens of millions of rupiah. Perpetrators may send malicious APK files or dangerous Excel documents masquerading as collaboration materials. Reren also recalled a past "love scam" incident involving a fake customer service job opening in the Jalan Gito-Gati area of Sleman.
Other threats arise from doxing and AI manipulation. Sensitive data—such as national ID numbers (NIK), addresses, contact details, and even old personal photos—can be disseminated without consent. Furthermore, deepfake and voice cloning technologies enable the fabrication of faces or voices to deceive victims and those around them.
"The five pillars of digital self-protection to keep in mind are: using long, unique passwords; enabling two-factor authentication; separating email identities; controlling personal information; and practicing delayed publishing and a 'three-second reflection' before uploading sensitive content," Reren explained during the session.
Arsito then supplemented the discussion with technical measures. Regarding passwords, for instance, he recommended using a passphrase—a sequence of four to five random words—because it is easier to remember and longer than conventional password patterns. Account holders are also advised to use encrypted password managers and to avoid storing passwords in apps like Notes, WhatsApp chats, or on public devices.
"Use a passphrase—a string of four to five random words forming a long phrase. It is easy for the owner to remember but extremely difficult for machines to crack using brute-force methods," Arsito said while demonstrating account security practices at the Gen Z Impact Fest 2026.
Arsito also emphasized the importance of verification prior to transactions or publishing content. For example, a potential partner's bank account can be checked via services like CekRekening.id, while photos or videos can be traced using reverse image search tools such as Google Lens. Similarly, examining metadata using Exif Viewer can help verify information regarding the time, date, and location where a photo was taken.
The application of these protocols was also discussed when Reren invited a participant to share their experience. Regarding coverage of mass protests in Yogyakarta, the participant noted that they would curate material before uploading it to social media. This delay in publication served to minimize the risk of doxxing and ensure the safety of both the journalist and their sources.
"Do not list personal phone numbers linked to banking or e-wallet accounts in your social media bio. When covering protests, curate your content first to determine what is safe to upload," Reren said, emphasizing the importance of controlling personal information.
For creators and journalists operating in the public sphere, delaying publication has evolved into more than just a content distribution strategy. A pause of a few minutes offers an opportunity to verify information, redact sensitive data, secure one's physical location, and consider the potential impact of the publication.
Furthermore, amidst escalating threats such as phishing, doxxing, and deepfakes, taking a three-second pause before hitting the upload button has ultimately become an integral part of digital safety itself.
© 2026 SUARA.COM - ALL RIGHTS RESERVED.