South Asia today is at a crossroads. With more than 800 million internet users, the region has become one of the fastest growing digital ecosystems in the world. E-commerce, digital banking, mobile payments, and social media have transformed daily life. Yet alongside this digital transformation lies a darker reality: cybercrime. From online banking fraud in Bangladesh and India, to dark web drug markets in Pakistan and Nepal, to extremist propaganda networks in Sri Lanka, the region is facing a cybercrime surge that threatens financial stability, social trust, and even national security.
Almost every country in South Asia has passed legislation to address cybercrime. Bangladesh introduced the Cyber Security Act in 2023, India relies on the Information Technology Act of 2000 (with amendments in 2008), Pakistan enacted the Prevention of Electronic Crimes Act in 2016, Sri Lanka passed its Computer Crimes Act in 2007, and Nepal has its Electronic Transactions Act from 2006.
On paper, this looks promising. In practice, however, these laws are fragmented, unevenly enforced, and in many cases outdated. Very few of them adequately cover emerging challenges such as AI-driven attacks, cryptocurrency-based fraud, or the rapid spread of disinformation campaigns. Definitions of crimes vary, penalties differ, and jurisdictions often overlap. This makes regional cooperation difficult, even though cybercriminals routinely operate across borders.
Passing laws is the easy part; enforcing them is the real challenge. Prosecutors and judges across South Asia often lack training in digital forensics, chain of custody, or the technicalities of evidence such as call detail records, blockchain transactions, or metadata extracted from devices. Forensic laboratories are few, tools are outdated, and technical experts are in short supply.
Meanwhile, cybercrime is rarely confined within one country. Hackers in Pakistan can target financial institutions in Bangladesh, while a radicalization cell in India can recruit followers through encrypted apps hosted on servers in Europe. To prosecute these crimes effectively, investigators and prosecutors need quick access to data across borders. Yet the existing mechanism—Mutual Legal Assistance Treaties (MLATs), is slow, bureaucratic, and often politically influenced. By the time evidence is shared, it is frequently too late.
The Bangladesh Bank SWIFT heist of 2016 remains one of the most glaring examples. Hackers stole $81 million through fraudulent transfers. Despite global collaboration, prosecution has been painfully slow due to attribution challenges and lack of coordination.
Similarly, online radicalization cases in Bangladesh and India show how difficult it is to prosecute extremists who rely on encrypted apps like Telegram and WhatsApp. Even when suspects are identified, gathering admissible digital evidence that can hold up in court proves extremely difficult.
In Pakistan, investigations into child exploitation material on the dark web revealed weak cooperation with Europol and Interpol, which delayed prosecutions and left networks of abusers operating for far too long.
India has built relatively stronger cyber forensics infrastructure with institutions like CERT-In and NCIIPC, but it struggles with a massive backlog of cases. Bangladesh is investing in BGD e-GOV CIRT and has improved capacity, yet judiciary awareness is still low. Pakistan has strict laws but weak enforcement. Sri Lanka and Nepal lag behind in both infrastructure and training.
What emerges is a patchwork of uneven progress, strong laws without strong enforcement.
If South Asia is to confront cybercrime seriously, firstly they should have a regional cooperation by creating a South Asian Cybercrime Prosecutors’ Network, perhaps under SAARC or BIMSTEC and modeled under EUROPOL’s EC3. Rules should be harmonised for digital evidence, including chain of custody and hash verification, so that evidence collected in one country can be admissible in another. Creating “fast lanes” (in urgent cases) in order to streamline cross-border evidence requests especially to fight financial crimes and terrorism should be implemented. Prosecutors and judges should be trained on efficient digital forensics, OSINT, and dark web monitoring. There should be specialised prosecutorial units established in every country. Finally, it has to be ensured that cyber laws protect citizens from crime without becoming tools for suppressing free speech or dissent.
Cybercrime is not an abstract, futuristic problem—it is already undermining financial systems, exposing children to exploitation, and enabling violent extremism. South Asia cannot afford to treat this as a secondary issue. Laws alone are not enough; without skilled prosecutors, digitally literate judges, reliable forensic tools, and strong regional cooperation, cybercriminals will always be one step ahead.
The region now faces a choice: remain a patchwork of fragmented responses, or build a united, tech-enabled, and victim-centered framework for prosecuting cybercrime. The political will and institutional reforms must come first, but the cost of inaction will be paid by millions of citizens whose trust in the digital future is already at risk.
The writer is a Prosecutor at International Crimes Tribunal




