The Web of Digital Crime in Nepal: Challenges and Measures for Building a Secure Digital Society
September 3, Kathmandu.
Information and communication technology has become the foundation of modern governance, economy, and social life. Digital services have expanded rapidly in Nepal. Its use has increased in government services, banking, electronic payments, social media, education, and business. Along with this, the risk of cybercrime has also increased.
Cybercrime is no longer just a technology problem. It has become an issue related to the rule of law, national security, economic stability, personal privacy, and human rights.
According to the Nepal Police, 20,526 complaints related to cybercrime were registered in the fiscal year 2025/26. In the fiscal year 2024/25, the number of such complaints was 18,926. In the fiscal year 2023/24, 19,730 complaints were registered. This shows that the problem remains at a consistently high level.
The nature of cybercrime is multidimensional. Unauthorized access, data theft, website hacking, identity theft, online fraud, phishing, misuse of social media, cyberbullying, blackmail, and privacy violations are its main forms.
Recent data shows that social media has become a significant medium for this. In the fiscal year 2025/26, 7,123 complaints related to Facebook and Messenger, 6,776 related to TikTok, 3,105 related to WhatsApp, and 1,031 related to Telegram were registered.
628 complaints related to Instagram were also filed. These statistics show that a large portion of cybercrime is linked to social media.
Another serious area of cybercrime is financial fraud. With the expansion of digital banking and electronic payments, incidents of phishing, social engineering, OTP fraud, fake trading platforms, and unauthorized access to bank and wallet accounts have increased.
The Financial Information Unit of Nepal Rastra Bank (Nepal’s central bank) has identified gift or parcel scams, identity misuse through social media, fake online businesses, OTP fraud, lottery scams, and unauthorized access to bank and wallet accounts as major trends in cyber-enabled fraud.
Nepal Rastra Bank’s latest publication states that police complaints regarding financial fraud and scams reached 7,723 in the fiscal year 2024/25, a significant increase from 4,112 in the previous year.
The basis of Nepal’s cyber legal structure is the Electronic Transactions Act, 2063 (2006 AD). This act was enacted to provide legal recognition to electronic transactions, electronic records, and digital authentication.
Sections 45 and 46 of the Act define unauthorized access to a computer and causing damage to computer and information systems, respectively, as offenses.
Section 47 makes provisions regarding the publication and transmission of illegal content in electronic form. Section 48 defines the breach of privacy of electronic records and information as an offense. Under Section 47, there is a provision for a fine of up to one hundred thousand rupees or imprisonment for up to five years, or both.
However, there are legal and practical challenges in the application of the Electronic Transactions Act. The Act is based on an older structure than the current complexity of digital technology. It is difficult for a single, old legal structure to adequately address new forms of cyberattacks such as artificial intelligence, deepfakes, crypto-related fraud, ransomware, cloud crime, digital identity theft, and cross-border cyberattacks.
Therefore, clear legal provisions are needed regarding the definition of cybercrime, classification of offenses, management of digital evidence, responsibilities of service providers, victim protection, and cross-border investigations. The law is not just a tool for crime control. It should also be a means of protecting civil rights.
Protection of freedom of expression and privacy is essential when controlling cybercrime. Criminalizing legitimate criticism, journalism, or civil expression in the name of cybercrime control is risky for democratic governance.
Advertisement
Therefore, the definition of cyber-related offenses must be clear, specific, and proportional. The law must clearly define the line between crime and criticism. The reliability of digital evidence must be maintained in investigation and prosecution. Judicial oversight must also be strong. This helps maintain a balance between cybersecurity and human rights.
The Government of Nepal has put forward a policy for building a secure and reliable cyberspace through the National Cybersecurity Policy, 2080 (2023 AD). Now the challenge is implementation. Cybersecurity should not be understood solely as the responsibility of the Nepal Police.
Coordination is necessary among communication and information technology agencies, Nepal Rastra Bank, the telecommunications sector, banks and financial institutions, digital wallets, internet service providers, educational institutions, and the private sector. A system for early notification of cyber incidents, risk identification, digital evidence preservation, and immediate response must be institutionalized. Investment in skilled manpower and state-of-the-art forensic infrastructure for cybersecurity must also be increased.
International cooperation is essential in the investigation of cybercrime. Criminals may reside outside Nepal and target Nepali citizens. Data may be on a server in another country. Financial assets may reach accounts in a third country.
The traditional concept of jurisdiction alone is not sufficient for such crimes. Exchange of digital evidence, mutual legal assistance, coordination with service providers, and international police cooperation are necessary. The cross-border nature of crypto-related crimes is also linked to this challenge.
The Financial Information Unit of Nepal Rastra Bank, in its strategic analysis for 2025, has mentioned an investigation related to an online financial and crypto fraud network exceeding three billion rupees connected to Nepal and India.
The first line of cyber defense is the citizens themselves. Strong and unique passwords must be used. Multi-factor authentication should be activated. OTPs, PINs, passwords, and banking details should not be shared with anyone. Suspicious links should not be opened. Unknown files should not be downloaded.
Sensitive personal information should not be disclosed on social media. If a call is received regarding a bank or wallet, it must be re-confirmed through official channels. Institutions must make regular security audits, data encryption, backup, access control, incident response plans, and security audits mandatory practices. Cybersecurity is not a one-time task. It is a continuous process.
For long-term solutions, improvements are needed at three levels. First, clear and human rights-friendly cyber laws must be formulated. Second, the institutional capacity for investigation, digital forensics, and prosecution must be enhanced.
Third, digital literacy must be expanded from schools to public administration. The latest data from the Nepal Police shows that out of 20,526 complaints in the fiscal year 2025/26, 161 cases were registered, and 155 people were arrested. The large discrepancy between complaints and cases should not be interpreted merely as evidence of weak investigation.
It also involves the nature of evidence, jurisdiction, victim cooperation, and other legal aspects. However, it clearly indicates the need to measure the effectiveness of the entire process from complaint to investigation, prosecution, and judicial outcome.
Cybercrime should not be accepted as an inevitable consequence of technology. Its control is possible. This requires legal clarity, institutional capacity, technological investment, citizen awareness, and international cooperation.
With the expansion of social media, new forms of cyberbullying, defamation, identity theft, and gender-based violence have emerged. The risk of fraud has increased with financial digitalization. Therefore, cybersecurity is no longer just a peripheral issue of development. It is a fundamental aspect of national security and good governance.
To build a secure digital society, the state must maintain a balance between rights and security. Citizens must adopt digital discipline. The private sector must increase security investments. And law enforcement agencies must update their capabilities along with technology. Only when all these aspects are integrated can Nepal build a reliable, secure, and rights-friendly cyberspace.
(Upreti is an Under Secretary of the Government of Nepal.)
For more: Web of Cybercrime in Nepal