Nepal Cybercrime Arrests and Legal Framework
Nepal's cybercrime caseload has exploded 757% in four years, but its 2006 laws can't keep pace.

Nepal is logging nearly 52 cybercrime complaints every single day. That number comes straight from the Cyber Bureau, and it is not slowing down in any meaningful way. Complaints rose from 2,301 in the 2019–20 fiscal year to 19,730 in 2023–24. That is a 757% increase in four years. The slight dip to 18,926 cases in 2024–25 is a statistical fluctuation. Superintendent of Police Deepak Raj Awasthi, the Cyber Bureau's spokesperson, said the number "is still alarmingly high." The dip reflects reporting gaps or how case management is being distributed, while actual criminal activity continues at pace. The core problem here is simple: enforcement is accelerating, but the legal framework governing that enforcement was written before smartphones existed in Nepal. Think of it like a fire brigade that has upgraded to modern trucks but is still operating under rules written for bucket chains — the crew is better, but the rulebook is holding them back. That gap is measurable, it is growing, and real people are paying for it.
Facebook Is Still the Main Stage, but TikTok Is Coming Fast
If you want to understand where Nepal's cybercrime caseload is coming from, start with the platforms.
Facebook and Messenger together accounted for 9,829 incidents in 2024–25 alone. Across the five-year period covered in a 2025 applied data science study of 53,474 reported cases, those two platforms made up nearly 73% of all reported incidents. That is a dominant share by any measure.
But TikTok's trajectory is the one investigators should be watching. It recorded 3,086 incidents in 2024–25 and showed growth of over 3,000% in associated criminal activity across the study period. No other platform comes close to that rate of change. WhatsApp, Telegram, and Instagram round out the top five, each carrying thousands of cases.
The offence types breaking down across these platforms include:
- Social media harassment and impersonation
- Online financial fraud (fake stores, fake investments, advance-payment scams)
- Sextortion and revenge porn
- Phishing and identity theft
- "Parcel from abroad" customs fraud
That last category is worth pausing on. Organised fraud rings running fake cryptocurrency investment schemes were averaging substantial losses per victim in 2024. The composition of the caseload has shifted toward coordinated financial crime operations. And from 2024 onward, the Cyber Bureau started prosecuting cases involving AI-generated explicit images. That category emerged years after Nepal's primary cybercrime statute was drafted.
A 2006 Law Being Asked to Do 2025 Work
Nepal does not have a standalone cybercrime act. The primary law is the Electronic Transactions Act, passed in 2006. It is supported by the National Penal Code (2017) and the Privacy Act (2018), but neither of those fills the gap the ETA leaves.
Chapter 9 of the ETA covers computer-related offences:
- Section 44: Piracy or destruction of computer source code
- Section 45: Unauthorised access
- Section 46: Damage to computer systems and data
- Section 47: Publication of illegal materials in electronic form
These provisions made reasonable sense for the threat environment of 2006. Nepal's legal framework has stagnated while the threat environment has transformed.
Prosecutors handling AI-generated explicit imagery are currently combining ETA Section 47 with Section 295 of the Muluki Criminal Code. That is creative lawyering, and it is producing some results. Using two provisions from two separate acts to prosecute a category of crime that neither act explicitly anticipated signals legislative absence.
Cryptocurrency is banned by Nepal Rastra Bank, but there is no dedicated cybercrime statute for it. Cases get routed through general financial crime provisions. Convictions have happened (more on that below), but the legal basis is improvised. A draft AI law is reportedly in development, though no confirmed timeline is publicly available.
Old laws can be amended. The problem is that amendments have arrived far too slowly for a caseload that grew 757% in four years. The law and the crime are like two trains on the same track — one has accelerated dramatically, and the other has remained stationary.
What Enforcement Actually Looks Like on the Ground
Here is what arrests and operations have looked like in practice recently.
The SMC app scam (2025–26): Eleven people arrested, including one Chinese national. The scheme targeted more than 70,000 people, generated 255 group complaints, and caused losses of approximately Rs 120.8 million. Suspects posed as partners of Universal Pictures, Warner Bros., and Disney.
Wolf 777 gaming platform (June 2024): Six arrested in Kathmandu. Investigators identified Rs 240 million in unaccounted digital transactions. Every suspect was under 30.
Cryptocurrency operations: Two Indian nationals were arrested for conducting transactions worth over Rs 1.5 billion, run out of a grocery store in Lalitpur. A separate family was convicted and sentenced to three years under the Muluki Criminal Code. A group of 23 Indian nationals operating a crypto trading and betting ring from Budhanilkantha had a case filed against them, with investigation ongoing.
The financial recovery numbers tell an important story. Victims got back several million rupees in 2023–24. That jumped to Rs 92.6 million in 2024–25. By the early months of 2025–26, the figure had already reached Rs 190 million. Operational capacity is genuinely improving.
Then there is the case of Prasan Nepal, a Nepali national based in North Carolina, arrested in April 2025 and charged in connection with the 764 violent extremist network's child exploitation enterprise. He faces potential life imprisonment under US law. A case like that falls entirely outside the reach of Nepal's ETA.
The Places Where Complaints Go to Die
Fraud is the fastest-growing category in Nepal's cybercrime caseload, and it is also where the legal framework shows its biggest cracks.
Fraud complaints went from 4,255 in 2023–24 to 6,740 in 2024–25. Early months of 2025–26 already showed 7,379 victims reporting. That growth rate is steep, and these cases are among the most legally demanding to prosecute.
Telegram is a good case study for where the system breaks down. There were 1,509 Telegram-related cases in 2024–25, and the dominant offence type was fraud. Investigators could not obtain usable user data from the platform. The ETA provides no mechanism to compel foreign platforms to cooperate. Nepal also lacks a mutual legal assistance treaty framework capable of closing that gap quickly. So those 1,509 cases start at a structural disadvantage that no amount of good police work fully overcomes.
The penalty structure of the ETA was calibrated to a narrower, smaller-scale threat. An organised fraud ring running Rs 1.5 billion through a grocery store front is operating in a different order of magnitude from what the Act's drafters had in mind.
The gap is most visible in the distance between 18,926 complaints in a single year and the number of those cases that reach a concluded prosecution. Arrests are happening, but convictions lag far behind. That conversion rate is where the framework's limits are most measurable.
The People Carrying the Weight of a Broken System
Women make up 44.32% of all cybercrime victims in Nepal's reported data. The offences they face disproportionately (blackmail, sextortion, revenge porn, impersonation) are exactly the categories where the ETA is being stretched furthest and where statutory authority is weakest.
Male victimisation has risen as financial cybercrime has grown. In the earliest recorded period, male victims made up roughly 43% of reported cases. By 2023–24, that had reached 50%, tracking the growth of digital payment fraud and investment scams.
E-Sewa fraud complaints numbered 665 between 2020–21 and 2023–24. Then 266 more came in just the first part of 2024–25. These are real people whose cases flow into a system not designed for digital payment infrastructure at the scale Nepal now operates.
The Vianet breach exposed personal data for roughly 170,000 users. It was caused by a teenage hacker. No ransom was demanded, but the incident revealed how inadequately corporate data-protection obligations were defined under existing law.
Then there is the category that rarely gets discussed: coerced participants in cross-border fraud rings who are simultaneously victims and suspects. The ETA treats that situation with a blunt, one-size approach. And the 70,000-plus people swept up in the SMC app scam illustrate just how fast a single organised operation can overwhelm a complaint-and-arrest response model.
What Reform Actually Has to Fix
Financial recoveries jumped from Rs 9.94 million in 2023–24 to Rs 190 million in the early months of 2025–26 alone. Enforcement capacity is moving in the right direction. But operational capability has outrun the legal framework that governs what investigators can actually do with what they find. That is a strange and uncomfortable position to be in. Here is what a real reform path has to address.
A purpose-built cybercrime statute. Not another amendment to the ETA. A dedicated law that defines offences at the scale and specificity that organised financial crime, AI-generated content, and platform-based harassment actually require. This is the baseline.
Platform data cooperation. Without a legal mechanism to compel or negotiate with Telegram, WhatsApp, and similar services, entire case categories will remain under-investigated regardless of how many arrests the Cyber Bureau makes. This requires domestic legislation with extraterritorial teeth, bilateral agreements, and most likely both together.
Cryptocurrency regulation. The improvised approach (using general financial crime provisions) has produced at least one conviction, yet Rs 1.5 billion-scale operations need a purpose-built regulatory and prosecutorial framework to be handled consistently.
Cross-border jurisdiction. Cases involving actors across Nepal, India, Cambodia, and the United States within a single network expose a mutual legal assistance gap that no domestic law reform alone can close. Treaty-level coordination is a parallel requirement, as essential as any domestic reform.
Speed. The draft AI law signals that lawmakers are aware of the problem. Awareness falls short of reform. A caseload growing at 52 complaints per day does not wait for a comfortable legislative calendar.
The Cyber Bureau is doing more with less than it should have to. Financial recoveries are up sharply. Organised operations are being dismantled. Enforcement capacity and legal authority are two different things, and right now Nepal has one developing faster than the other.


