Digital Safety · NRB Advisory · Updated August 2026
On 4 August 2026, Nepal Rastra Bank issued a fresh public advisory on digital financial security. None of it is complicated, but almost none of it is optional either. Here is what the central bank actually said, translated into a checklist you can act on today.
Nepal Rastra Bank does not issue digital security advisories for the sake of paperwork. It issues them when the gap between how fast people are adopting mobile banking and how carefully they are protecting it starts to widen. On 4 August 2026, the central bank published a public notice urging digital financial discipline across internet banking, mobile banking, QR payments and digital wallets, and it was specific about both what to do and how criminals are actually getting in.
Quick answer
NRB's 4 August 2026 advisory asks every digital banking user to use strong, unique passwords, avoid PINs based on your phone number or birth date, turn on multi-factor authentication, download apps only from official stores, and avoid public Wi-Fi and screen-sharing apps during transactions. Separately, NRB has also reminded users to inform their bank immediately after changing their registered mobile number or email address, since that contact detail is what protects your OTPs and login alerts.
What NRB announced, and why now
The timing lines up with a broader pattern this year: internet banking, mobile banking, QR payments and digital wallets have all been growing at record pace in Nepal, and NRB has framed this advisory as a direct response to that growth, not to any single publicized incident. The central bank's own reasoning is straightforward: as digital transactions become the default rather than the exception, account safety depends less on the bank's back-end systems and more on how carefully individual users protect their usernames, passwords, PINs and one-time passwords.
The security checklist NRB wants you to follow
Stripped of formal language, the advisory reduces to a short list of habits. None of these require technical skill, and most take under a minute to set up.
Do this
- Use a unique password mixing upper and lower case letters, numbers and symbols, avoiding your own name or family details
- Set a transaction PIN that has nothing to do with your phone number, birth date or a simple sequence
- Turn on multi-factor authentication and biometric login wherever your app supports it
- Download banking apps only from the official Google Play Store, Apple App Store, or your bank's verified website
- Change your password and PIN periodically rather than keeping the same ones for years
- Update your registered mobile number and email with your bank the same day either one changes
Avoid this
- Reusing your banking password for email, social media or messaging apps
- Letting your browser auto-save your password on a banking website
- Installing unofficial or third-party apps on the phone you use for banking
- Granting unfamiliar apps permissions they do not clearly need
- Using remote screen-sharing apps while logged into mobile banking
- Conducting banking transactions over public or unsecured Wi-Fi
How fraudsters actually try to get in
NRB's advisory does not just list good habits, it also names the mechanics behind common attacks, which is useful because it tells you what each habit is actually defending against.
| Method | What it means in plain terms |
|---|---|
| Guessing | Trying passwords built from your publicly known details, such as your name, phone number or birth date |
| Harvesting | Tricking you into typing your real credentials into a fake website or app that looks like your bank's |
| Password cracking | Using automated tools to work out a password from stolen, encrypted data |
| Password spraying | Trying a handful of very common passwords across a huge number of accounts at once |
| Credential stuffing | Reusing your username and password from a breach on another website against your bank login |
Beyond these technical methods, NRB has separately warned that a large share of real-world losses come from a simpler route: convincing a victim to voluntarily authorize a transfer, hand over an OTP, or install a screen-sharing app, no hacking required, just a convincing phone call, message or fake support interaction.
Red flags to watch for
Artificial urgency
A caller or message insists you must act immediately, "your account will be blocked in ten minutes," or similar pressure. Legitimate banks do not force split-second decisions.
Any request for your OTP or PIN
No genuine bank employee needs your one-time password, PIN or full password to help you. A request for any of these, however official-sounding, is the clearest fraud signal there is.
A request to install screen-sharing software
"Support" asking you to install a remote-access or screen-mirroring app is a direct way for a fraudster to watch you log in and capture your credentials in real time.
An unexpected link in SMS or a messaging app
Even a link that looks like your bank's domain can be a lookalike. Open your bank's app or type its known web address directly instead of tapping a forwarded link.
Remember this one rule
Your bank will never call, text or email you to ask for your password, PIN, or a one-time password. If someone claiming to be from your bank asks for any of these, end the interaction and contact your bank directly using the number printed on your card or its official website.
If you think you have already been targeted
- Contact your bank immediately through its official hotline to freeze mobile banking access and flag the account, before doing anything else.
- Change your password and PIN from a different, trusted device if your banking app is still accessible.
- Do not delete anything. Screenshots of suspicious messages, calls or transactions help your bank and investigators trace what happened.
- File a complaint with NRB's Financial Customer Protection Unit at 01-5719605 if your bank does not resolve the issue satisfactorily.
- Report to the police cyber bureau for cases involving financial loss, since a formal report is usually required for any recovery process.
Mistakes and misconceptions
"Biometric login alone keeps me safe"
Biometric authentication is one layer, not a complete defense. If a fraudster convinces you to authorize a transfer yourself, or captures your credentials through a fake site before biometric login even triggers, fingerprint or face unlock will not stop the loss.
"Sharing my OTP is fine if I called the bank first"
Genuine bank staff never need your OTP read aloud to them, regardless of who initiated the call. Treat any OTP request, from either direction, as a red flag.
"I would recognize a fake banking app or website"
Modern phishing sites and cloned apps are visually near-identical to the real thing. The safer habit is checking the source, official app store listing or typed URL, rather than trusting how a page or app looks.
Frequently asked questions
What did Nepal Rastra Bank's August 2026 digital security advisory actually say?
It urged users of internet banking, mobile banking, QR payments and digital wallets to use strong unique passwords, avoid predictable PINs, enable multi-factor and biometric authentication, download apps only from official sources, avoid public Wi-Fi and screen-sharing apps during transactions, and change credentials periodically.
Why did NRB issue this advisory now?
NRB tied the notice to the rapid, ongoing growth of digital financial services in Nepal, reasoning that as more of the population's money moves through mobile apps and QR payments, individual security habits matter more for preventing fraud.
Will my bank ever ask for my OTP or password over the phone?
No. A legitimate bank representative never needs your OTP, PIN, or full password to assist you. Any call, message or email requesting these should be treated as fraudulent.
What should I do if I changed my phone number and forgot to update my bank?
Update it immediately, in person at a branch if needed. NRB has specifically flagged outdated registered mobile numbers and email addresses as a common way OTPs and security alerts end up going to the wrong person.
What is credential stuffing, and does it affect me?
It is when attackers take a username and password leaked from a breach on one website and try the same combination on other services, including banking apps. It affects anyone who reuses the same password across multiple accounts, which is why NRB recommends a banking password that is not used anywhere else.
Who do I contact if I suspect banking fraud in Nepal?
Contact your bank's official hotline immediately to freeze access, then escalate to NRB's Financial Customer Protection Unit at 01-5719605 if unresolved, and file a report with the police cyber bureau for cases involving financial loss.
The bottom line
None of NRB's August 2026 advisory is new in spirit, security professionals have recommended unique passwords, multi-factor authentication and caution around unsolicited requests for years, but the specificity is useful. The advisory works because it turns abstract caution into a short, concrete checklist: a password that is actually yours, a PIN with no personal meaning, multi-factor authentication turned on, apps from official sources only, and an unwavering rule that no one, ever, needs your OTP read aloud to them. Apply those five habits today rather than after something goes wrong.
Discussion