A teacher in Lalitpur lost tens of thousands of rupees from her mobile wallet in under ten minutes. A shopkeeper in Butwal had his entire ConnectIPS balance wiped out after responding to what looked like a routine bank notification. These aren't rare, isolated incidents — Nepal's Cyber Bureau has recorded hundreds of complaints specifically involving eSewa, Khalti, and bank account fraud in recent reporting periods. This post walks through exactly how these scams work and what genuinely protects your wallet.
Why Digital Wallets Have Become a Fraud Target
As mobile banking and e-wallet usage has exploded in Nepal, scammers have followed the money, exploiting the convenience of anonymous, quick transactions and the fact that many users are still relatively new to digital finance. The Cyber Bureau has explicitly noted that fraud activities have been increasing as scammers actively exploit digital payment platforms, reflected in a rising number of police cases year over year.
The Fake Support Call: Still the Most Common Trick
The single most frequent scam pattern involves someone calling and claiming to be from eSewa or Khalti customer support, often with a caller ID spoofed to look legitimate. Common scripts include claims that your account will be blocked unless you "verify" immediately, offers of surprise cashback or bonus amounts that require sharing your identity or OTP to claim, or congratulations on being selected as a "top merchant" eligible for an upgrade — all designed to create urgency or excitement that overrides caution. In some documented cases, scammers have even impersonated senior company officials directly, successfully convincing high-profile targets, including a former police officer and a government joint secretary, to hand over sensitive account details.
Phishing Links: The Fastest-Growing Threat
SMS and WhatsApp phishing has become one of the fastest-growing attack vectors specifically because it requires no phone conversation at all. A crafted message mimics an official alert — sometimes using spoofed sender IDs that appear identical to genuine bank or wallet notifications, occasionally even landing in the same message thread as real past communications — warning that your account faces suspension unless you click a link and verify immediately. The link leads to a fake login page nearly identical to the real one; entering your credentials there hands them directly to the attacker, sometimes triggering a real OTP on the legitimate site simultaneously, which the fake page then also captures.
The Lockout Trick
A more deliberate variant involves a scammer repeatedly entering incorrect passwords on your account to trigger a temporary lock, then calling you shortly afterward pretending to help resolve the very issue they caused, using that manufactured urgency to extract your OTP or reset credentials.
The Rules That Actually Protect You
- Never share your OTP, PIN, or password with anyone — not a caller, not a message, not even someone claiming to be official support. Legitimate providers will never ask for this information over the phone or via SMS.
- Hang up and call back through the official number — if you get a suspicious call, disconnect and dial the number printed on your card or listed on the provider's official website yourself, rather than trusting the number that called you.
- Check URLs carefully before entering any credentials — fraudsters register look-alike domains such as esewa-support.com or khalti.app.login.com that are easy to mistake for the real thing at a glance.
- Enable two-factor authentication wherever it's offered — this adds a meaningful barrier even if your password is somehow compromised.
- Treat unexpected cashback, refund, or prize messages with suspicion — legitimate rewards don't require you to share sensitive identity or account details to "claim" them.
If You Suspect You've Been Targeted
Act within the first hour if possible, since early response meaningfully improves the odds of recovering funds or freezing further damage. Lock your affected accounts, reset your passwords immediately, and revoke any active login sessions you don't recognize. Report the incident to your specific wallet or bank's fraud hotline directly, and file a complaint with Nepal Police's Cyber Bureau, which maintains a dedicated hotline and online portal for exactly this kind of case. Preserve evidence — screenshots of the suspicious message, call logs, and transaction details — since this documentation matters for both the investigation and any potential recovery process.
A Word for Protecting Older Family Members
Older users, particularly those less familiar with how digital wallets and scams typically operate, are disproportionately targeted and successfully deceived. If you have parents or older relatives using eSewa or Khalti, it's worth having a direct conversation with them specifically about the OTP-sharing rule — it's the single piece of advice that stops the largest share of these scams before any money changes hands.
Final Thoughts
Nepal's wallet fraud landscape follows a small number of repeating patterns — fake support calls, phishing links, and manufactured urgency — rather than constantly reinventing itself. The single most effective defense is remarkably simple: no legitimate bank or wallet will ever ask for your OTP, PIN, or password, over any channel. Treat any request for that information, however convincing the caller or message sounds, as an immediate red flag.
Discussion