Cybersecurity & Fraud: Rising Scam Patterns as Digital Wallet Adoption Increases
Nepal's digital wallet users have nearly quadrupled since 2020. The scammers noticed too. Here's what the current wave of fraud actually looks like — and how to keep your money out of it.
1. Wallet Growth and Fraud Growth Are Moving Together
Nepal's digital wallet numbers tell a genuine success story. Nepal Rastra Bank's own oversight data shows the number of digital wallet users climbing from roughly 6.27 million in 2020 to over 23.4 million by mid-2024 — nearly a fourfold increase in just four years, reflecting real, rapid adoption across QR payments, bill settlement, and peer-to-peer transfers. That growth is exactly what financial inclusion policy has been aiming for.
But every new payment rail that gets built also becomes a new surface for fraud, and Nepal's cybercrime numbers have grown in step. Nepal recorded 18,926 cybercrime cases in a recent fiscal year — an average of 52 cases every single day — with online financial fraud representing a significant and growing share of that total. This isn't a coincidence or a sign that digital payments are inherently unsafe; it's the predictable pattern seen in every market where digital financial adoption outpaces the public's collective experience in recognizing manipulation. More people online, transacting more often, with more of them being first-time digital finance users, simply means more targets for scammers to test against.
2. The Current Fraud Patterns, Explained
Nepal's Cyber Bureau and independent cybersecurity researchers have flagged several distinct, repeating patterns rather than a single type of scam. Recognizing the pattern is the fastest way to spot it before it costs you money.
Fake QR stickers ("quishing")
Scammers physically place a fraudulent QR sticker directly over a legitimate merchant's real QR code — in restaurants, parking areas, and shops — so a scan that looks completely normal actually routes payment to the scammer's own account instead of the business you intended to pay. The scam relies entirely on the fact that one printed square looks identical to another at a glance.
SMS phishing ("smishing") impersonating banks and wallets
Nepal's Cyber Bureau has issued repeated public warnings about fraudulent SMS messages sent through compromised bulk-messaging accounts, arriving under shortcodes designed to look official. These messages typically claim your account or wallet has been suspended or will be locked within hours, creating urgency that pushes you to click a link and "verify" your details on what is actually a cloned, fake version of a legitimate bank or wallet's website — capturing your login credentials the moment you type them in.
Vishing: phone calls impersonating official support
A caller claiming to represent your bank, wallet provider, or even the police contacts you directly, often citing a fabricated "problem" with your account, and asks you to confirm sensitive details over the phone — an OTP, an MPIN, or a full card number — to "resolve" it. Legitimate institutions do not call to request these details; the request itself is the scam.
Remote-access app manipulation
In a more technically involved variation, a scammer posing as customer support convinces a victim to install a legitimate remote-access application, then uses that access to view the victim's screen, capture saved credentials, and operate their banking or wallet apps directly in real time — all while the victim believes they're being "helped."
Fake loan, job, and prize offers
Unsolicited messages offering an unusually easy loan, a job with an upfront "processing fee," or a prize requiring a small payment to "unlock" continue to circulate, exploiting exactly the same urgency and reward psychology as SMS phishing, just through a different opening line.
3. Why Fraud Rises Alongside Adoption, Specifically
It isn't just "more users, therefore more fraud" in a simple sense — a few specific dynamics make this growth phase particularly exploitable.
- A large first-time-user population: a meaningful share of Nepal's newest digital wallet users are using formal digital financial services for the first time in their lives, without the years of accumulated skepticism that experienced internet users have built up around phishing attempts.
- Data protection gaps: Nepal does not yet have a comprehensive, dedicated data protection law governing how digital financial platforms collect, store, and share personal data, which researchers have flagged as a factor that can increase exposure to identity theft and unauthorized transaction risk industry-wide.
- Organized, cross-border operations: some of the more sophisticated fraud campaigns rely on infrastructure — compromised bulk SMS accounts, cloned websites, credential servers — hosted or operated outside Nepal, complicating both detection and enforcement.
- System-level oversight still maturing: a major 2025 investigation into billions of rupees moved through digital wallet accounts under the guise of remittance payments highlighted that anti-money-laundering monitoring across the fast-growing digital payments sector hadn't kept pace with monitoring in traditional banking — a systemic issue distinct from, but related to, the consumer-facing scams covered above.
4. How Regulators and Platforms Are Responding
Nepal Rastra Bank has been actively tightening the rules around QR-based payments specifically, given how central QR has become to daily transactions.
- NepalQR Code Standardization Framework and Guidelines: this NRB directive requires QR service providers and financial institutions to apply the same fraud and risk management protocols to QR transactions as any other legitimate payment mode, including velocity checks — automated limits on unusual transaction frequency or size — built directly into the platform.
- No customer-side QR fees: NRB has barred QR service providers from charging customers any fee under any heading, closing off one avenue scammers previously used to disguise fraudulent charges as legitimate service costs.
- Mandatory incident reporting: licensed PSOs and PSPs are required to notify NRB promptly in the event of a major cyber-attack or systemic fraud incident, rather than handling it purely internally.
- Cyber Bureau public advisories: Nepal Police's Cyber Bureau regularly issues specific, named warnings about active scam campaigns — including real examples of fraudulent SMS wording — to help the public recognize live threats as they're happening, not just after the fact.
- Platform-level commitments: licensed digital wallets increasingly state explicitly, in their own communications, that they will never ask a customer for their OTP, MPIN, or password — a small but useful signal, since any message or call that does ask for these is immediately identifiable as fraudulent by that standard alone.
5. A Practical Protection Checklist
- After scanning any QR code, always check the merchant name displayed on your confirmation screen before approving payment — if it doesn't match the business in front of you, cancel immediately.
- Never share your OTP, MPIN, password, or CVV with anyone, including someone claiming to call from your bank, wallet provider, or the police — legitimate institutions do not ask for these.
- Don't click links in unsolicited SMS messages claiming urgent account issues; instead, open your banking or wallet app directly, or call the official number printed on your card or the provider's verified website.
- Never install a remote-access application at the request of an unsolicited caller, regardless of how convincing their "support" explanation sounds.
- Treat any loan, job, or prize offer that requires an upfront payment to "unlock" your reward as fraudulent by default.
- Enable transaction alerts on every linked account so you're notified the moment any transfer happens, not after checking your balance days later.
- Use a strong device lock and avoid saving your MPIN or password anywhere an installed app could read it, including notes apps or screenshots.
- Periodically search only your provider's official app store listing or verified website for support contact numbers, rather than trusting a number found via a general web search, which scammers sometimes manipulate to rank highly.
6. What to Do If You've Already Been Scammed
- Contact your bank or wallet provider's official support line right away to request an immediate freeze or block on the affected account, before the funds move further.
- Change your password and MPIN for the affected account and any other account where you've reused the same credentials.
- File a complaint with Nepal Police's Cyber Bureau as soon as possible, providing screenshots of the fraudulent message, call details, or transaction records as evidence.
- Keep all evidence — SMS screenshots, transaction IDs, call logs — rather than deleting them, since these details are what investigators need to trace the fraud.
- Alert your contacts if the scam involved a compromised messaging account or app, since fraud campaigns sometimes attempt to use one victim's accounts to reach others.
7. Frequently Asked Questions
Will my bank or wallet provider ever call and ask for my OTP?
No. Licensed banks and digital wallets in Nepal do not call customers to request an OTP, MPIN, password, or full card number. Any call, message, or email asking for these should be treated as fraudulent regardless of how official it appears.
How can I tell if a QR code has been tampered with?
You generally can't tell from looking at the sticker itself — the safeguard is checking the merchant name that appears on your app's confirmation screen after scanning, before you approve the payment. If the name doesn't match the business you're standing in, don't proceed.
Is it safe to use digital wallets in Nepal at all, given the rise in fraud?
Yes, for the overwhelming majority of transactions. The rise in fraud reflects growth in the number of targets and increasingly organized scam tactics, not an inherent flaw in licensed, NRB-regulated payment infrastructure. Following basic precautions — verifying merchant names, never sharing OTPs, and ignoring urgent unsolicited messages — addresses the vast majority of current scam patterns.
Where do I report a suspected scam in Nepal?
Suspected fraud and cybercrime can be reported to Nepal Police's Cyber Bureau, which investigates digital financial fraud and issues public advisories on active scam campaigns. Your bank or wallet provider's official support channel should also be contacted immediately to attempt to freeze or reverse an affected transaction.
Discussion