Strengthening Nepal’s Response to Cybercrime

The rapid expansion of digital technology has brought enormous benefits to Nepal, but it has also created new opportunities for cybercrime, online fraud, hacking, identity theft, harassment, misinformation, financial crime, and other forms of digital abuse. As more citizens, businesses, government institutions, and financial services move online, cybersecurity has become a matter of national importance.

Nepal Police’s Cyber Bureau has an important responsibility to investigate cybercrime and protect citizens from digital threats. However, the growing number and sophistication of cyber incidents raises a serious question: Is Nepal’s existing cybercrime system sufficiently equipped to protect the public and respond effectively?

The issue should not simply be about blaming one department. We need to examine the entire system—from reporting and investigation to digital forensics, prosecution and international cooperation.

In many traditional settings, including the Kathmandu Valley, heavy investment in stone rituals, elaborate pujas, expensive gemstones, or public devotions can become performative. Society often rewards the display of religiosity with trust and social status, which bad actors can use as a shield as per the findings from detail survey done by group of sociologists. They also found that criminals, corrupt officials, or predatory figures leverage grand public participation in religious and cultural events to construct a pious public image, making society less likely to question their private or financial dealings..

This is a dangerous evolution in modern fraud and character assassination: the fusion of high social status, financial resources, and accessible digital tools.

When bad actors leverage public piety or social standing as a shield, they often use their capital to wage subtle, high-impact campaigns against those who challenge them. Synthetic media—such as deepfakes, manipulated audio, and generated imagery—has drastically lowered the cost of orchestrating these attacks.

Who is responsible?

The first question in any serious cybercrime case should be: Who is responsible?

Cybercriminals may operate individually, through organized groups, or from outside Nepal. Some crimes may involve networks that use multiple countries, anonymous accounts, fraudulent identities, cryptocurrency, encrypted communication, or compromised devices.

Therefore, investigators need the technical capacity to establish who actually carried out an offence and whether there was any organized coordination behind it.

What evidence exists?

The second question is: What concrete evidence exists?

Cybercrime investigations must be based on evidence such as digital records, server logs, transaction records, device analysis, IP information, communications, metadata, financial trails, and other forms of digital forensics.

Accusations alone are not sufficient. Nor should people be labelled criminals merely because of their political views, nationality, ideology, or association with a particular group.

The strength of a cybercrime investigation ultimately depends on the quality of the evidence and the ability of investigators to preserve, analyse and present that evidence properly.

Why are investigations sometimes ineffective?

Another important question is why existing mechanisms may struggle to identify, investigate and prosecute cybercriminals efficiently.