The Justice Corner is a leading law firm in Bangladesh, offering specialized legal services to both local and international clients. We serve as trusted advisors to prominent businesses, companies, and banks.

Blog Details

Cyber Crime in Bangladesh: Laws, Penalties and Legal Remedies

Cyber Crime in Bangladesh: Laws, Penalties and Legal Remedies

Cyber Crime in Bangladesh: Laws, Penalties and Legal Remedies

Cybercrime has become an increasingly important area of criminal law in Bangladesh as banking, e-commerce, social media, digital communications and government services increasingly depend on digital systems.

As of 2026, the principal legislation governing cyber offences in Bangladesh is the Cyber Security Act, 2026. The Act replaced the Cyber Security Ordinance, 2025, which itself had replaced the Cyber Security Act, 2023. The 2026 Act is deemed to have come into force from 21 May 2025.

The current framework covers offences such as unauthorised access or hacking, attacks against critical information infrastructure, cyber fraud, cyber terrorism, online sexual harassment and blackmailing, certain hate-related cyber activities, cyber gambling and other specified digital offences. It also establishes a procedure for investigation, digital forensic evidence, trial before Cyber Tribunals and appeals.

This guide explains cybercrime laws in Bangladesh, common cyber offences, penalties, investigation, bail, trial procedure and legal remedies available to victims and accused persons.

What Is Cybercrime in Bangladesh?

Cybercrime generally refers to criminal conduct involving computers, digital devices, computer systems, networks, electronic communications or cyberspace.

Under the current Cyber Security Act, 2026, the statutory framework is broad enough to cover technologies including digital devices, artificial intelligence technologies, blockchain, large language models, machine-vision systems and other modern computing technologies.

Examples of conduct that may amount to cybercrime include:

Unauthorised access to a computer or digital system

Hacking

Destruction or alteration of digital data

Attacks against critical information infrastructure

Cyber fraud

Cyber terrorism

Online blackmailing

Sextortion

Revenge pornography

Certain forms of digital child sexual-abuse material

Cyber-related financial fraud

Certain forms of online gambling

Cyber-related religious or ethnic hate activities

Digital activities specifically criminalised by the Cyber Security Act

The exact offence depends on the conduct, evidence and statutory provision applicable to the particular case.

What Is the Main Cybercrime Law in Bangladesh?

The principal statute is the Cyber Security Act, 2026 (Act No. 81 of 2026).

The Act expressly repealed the Cyber Security Ordinance, 2025 and the Cyber Security (Amendment) Ordinance, 2025. It also replaced the Cyber Security Act, 2023.

The 2026 Act also contains transitional provisions explaining how certain cases filed under the repealed 2023 law are to be treated. Some specified pending cases continue under the relevant tribunal framework, while proceedings concerning certain repealed offences are cancelled under the statutory transition provisions.

Cyber Security Act, 2026 — Bangladesh Laws

Other Laws That May Apply to Cybercrime

The Cyber Security Act is not necessarily the only law relevant to conduct occurring online.

Depending on the facts, a case may also involve:

The Penal Code, 1860

The Code of Criminal Procedure, 1898

The Evidence Act, 1872

The Information and Communication Technology Act, 2006

The Personal Data Protection Act, 2026

Laws dealing with financial crimes, fraud, pornography, child protection or other specific offences

Section 42 of the Cyber Security Act provides that, unless the Act provides otherwise, relevant provisions of the Code of Criminal Procedure, Evidence Act and Information and Communication Technology Act apply to proceedings under the Act.

Major Cyber Offences Under the Cyber Security Act, 2026

1. Illegal Access to Critical Information Infrastructure

Critical Information Infrastructure, or CII, refers to infrastructure whose disruption or compromise could adversely affect areas such as public safety, economic security, public health, national security, territorial integrity or sovereignty.

Section 17 criminalises specified unauthorised access and harmful activities involving CII.

Depending on the conduct, the maximum punishment can be:

Up to 5 years' imprisonment, or

Up to Tk 50 lakh fine, or

Both.

Where unauthorised access causes the specified forms of damage or interference described in the provision, the maximum punishment can rise to:

7 years' imprisonment, or

Tk 1 crore fine, or

Both.

2. Unauthorised Access or Hacking

Section 18 addresses unauthorised access to computers, digital devices, computer systems and networks.

Depending on the specific conduct covered by the provision, the offence can carry imprisonment of up to 5 years, a fine of up to Tk 50 lakh, or both.

Hacking cases can therefore involve significant criminal consequences even where the alleged conduct does not involve a traditional physical crime.

3. Cyber Fraud

Section 21 deals with cyber fraud.

The provision covers specified unauthorised manipulation or creation of digital information, files, programs, electronic documents and other digital activities. It also expressly addresses certain activities involving digital money, electronic currency, cryptocurrency, SIMs registered in another person's identity, mobile banking, hundi-related activity and gambling portals.

The maximum punishment is:

2 years' imprisonment, or

Tk 20 lakh fine, or

Both.

4. Cyber Fraudulent Deception

Section 22 separately addresses fraud through cyberspace.

The statutory definition covers specified manipulation, deletion, addition or alteration of information in computer programs, systems, networks, digital devices, e-commerce or social-media systems for obtaining financial or other benefits or causing harm through deception.

The maximum punishment is:

5 years' imprisonment, or

Tk 50 lakh fine, or

Both.

5. Cyber Terrorism

Section 23 addresses specified cyber activities intended to threaten national security, sovereignty or territorial integrity, create fear among the public, or cause serious harm through digital systems.

The maximum punishment under the provision is:

10 years' imprisonment, or

Tk 1 crore fine, or

Both.

Because of the seriousness of the allegation, cyber-terrorism cases can involve extensive investigation and digital-forensic examination.

Online Blackmail, Sextortion and Revenge Porn

One of the important areas covered by the current law is online sexual harassment, blackmailing, revenge pornography and sextortion.

Section 25 covers specified conduct involving the transmission, publication or dissemination—or threats to disseminate—harmful digital material for purposes including:

Blackmailing

Sexual harassment

Revenge pornography

Sextortion

Digital child sexual-abuse material

The provision also expressly covers material that has been created or edited using artificial intelligence.

For the basic offence, the maximum punishment is:

2 years' imprisonment, or

Tk 10 lakh fine, or

Both.

Where the offence is committed against a woman or a child under 18, the maximum punishment can be:

5 years' imprisonment, or

Tk 20 lakh fine, or

Both.

This is particularly relevant to cases involving threats to publish private photographs, videos, recordings or AI-generated material.

Religious or Ethnic Hate-Related Cyber Offences

Section 26 addresses specified online publication or dissemination of religious, communal or ethnic hatred-related material where the conduct is connected with violence, public concern, disorder or directions toward criminal activity.

The maximum punishment is:

2 years' imprisonment, or

Tk 10 lakh fine, or

Both.

The provision is directed at conduct meeting its statutory requirements; ordinary criticism or disagreement should not automatically be treated as an offence merely because it occurs online.

Cyber Gambling

The Cyber Security Ordinance, 2025 contained provisions concerning online gambling, and the current 2026 framework continues to regulate specified cyber-space gambling activities.

The relevant provision covers activities such as creating or operating gambling portals or applications, participating in online gambling, facilitating or encouraging gambling and specified advertising or promotion.

The precise punishment should be determined from the current statutory provision applicable to the alleged conduct.

Assisting a Cybercrime

A person does not necessarily avoid criminal liability simply because they did not personally carry out the principal cyber activity.

Section 27 provides that a person who assists in committing an offence under the Cyber Security Act commits an offence and may receive the punishment prescribed for the underlying offence.

This can be relevant where multiple people are alleged to have participated in a cybercrime.

False Cybercrime Cases and Complaints

Section 28 addresses knowingly initiating a case or complaint under the Act without lawful or reasonable grounds with the intention of causing harm to another person.

The provision provides for punishment corresponding to the punishment prescribed for the underlying offence.

Therefore, filing a cybercrime complaint is not something that should be done merely as a threat or means of harassment.

Is Cybercrime a Cognizable Offence?

Not every offence under the Cyber Security Act has the same procedural classification.

Section 46 divides offences into cognizable and non-cognizable categories.

The Act specifies that offences under sections:

17

18(1)(c)

19

20

21

22

23

25

are cognizable, while offences under the other specified provisions are non-cognizable.

The same section also distinguishes between bailable and non-bailable offences.

Which Cyber Offences Are Bailable?

Section 46 specifically classifies certain offences as bailable or non-bailable.

Under the current statutory framework:

Non-bailable offences include specified offences under:

Section 17

Section 18(1)(c)

Section 19

Section 22

Section 23

Bailable offences include specified offences under:

Section 18(1)(a) and (b)

Section 20

Section 21

Section 24

Section 25

Section 26

The classification is important because the legal approach to bail differs between bailable and non-bailable offences.

A person should therefore identify the exact section mentioned in the case rather than assuming that every cybercrime is either bailable or non-bailable.

Investigation of Cybercrime Cases

Cybercrime investigations can involve both traditional criminal investigation and specialised digital-forensic work.

Under section 31, cyber offences are investigated by police officers or designated investigating officers. In appropriate circumstances, the Tribunal may form a joint investigation team involving investigative agencies, law-enforcement agencies and other relevant agencies.

Investigators may examine:

Computers

Mobile phones

Digital devices

Social-media accounts

Email accounts

Server information

Network information

Transaction records

Digital documents

Electronic communications

Metadata

Digital payment records

Other relevant digital evidence

Time Limit for Cybercrime Investigation

Section 32 provides a specific investigation timeline.

An investigating officer is required to complete an investigation within 90 days from the date of receiving responsibility for investigating the offence.

The Act also provides mechanisms concerning specialised assistance in collecting evidence and conducting investigations.

The existence of a statutory timeline does not mean every case will necessarily conclude within 90 days in practice; the applicable statutory procedure and any lawful extension or related judicial process must be considered.

Search and Seizure in Cybercrime Cases

Digital evidence can be extremely fragile because data may be deleted, altered or encrypted.

Section 34 permits an authorised police officer, after recording reasons and obtaining a search warrant from the appropriate Tribunal, Chief Judicial Magistrate or Chief Metropolitan Magistrate, to undertake specified searches and obtain relevant digital evidence.

The provision can involve obtaining traffic data and customer information from service providers and dealing with electronic communications in accordance with the statutory framework.

Search and Arrest Without Warrant in Certain Hacking Cases

Section 35 creates a special mechanism for circumstances involving cyberattacks or unauthorised access where there is a risk that evidence may be deleted, altered, destroyed or made inaccessible.

In such circumstances, after recording reasons, the police may have powers specified by the section to:

Enter and search the relevant location

Seize computers and digital equipment

Seize relevant documents or evidence

Search persons present

Arrest a person where the statutory conditions are satisfied

After arrest, the person must be produced before the nearest Magistrate or Tribunal within the constitutional and statutory time limit, generally within 24 hours excluding necessary journey time.

Digital Forensic Evidence

Digital evidence is often central to cybercrime litigation.

Section 43 provides that forensic evidence obtained or collected under the Act can be treated as evidence in judicial proceedings, subject to the statutory framework. It also requires preservation of digital forensic evidence prepared by a digital forensic laboratory.

The Tribunal or Appellate Tribunal may also seek expert opinions from persons experienced in areas such as:

Computer science

Digital forensics

Electronic communications

Data protection

 

Can Screenshots Be Used as Evidence?

Screenshots, messages, photographs, emails and other electronic records may become relevant evidence, but producing a screenshot does not automatically establish every fact that the screenshot appears to show.

Questions can arise concerning:

Authenticity

Source

Identification of the account

Integrity of the file

Date and time

Whether the material was altered

Chain of custody

Metadata

Digital forensic verification

The Evidence Act and the special evidentiary provisions of the Cyber Security Act must therefore be considered when assessing digital evidence. Section 42 makes the Evidence Act applicable where the Cyber Security Act does not provide otherwise.

Where Are Cybercrime Cases Tried?

Section 41 provides that offences under the Cyber Security Act are to be tried only by a Cyber Tribunal.

A person aggrieved by a judgment of the Cyber Tribunal may appeal to the Cyber Appellate Tribunal.

The Cyber Tribunal is established under the framework of the Information and Communication Technology Act, 2006, as recognised by the Cyber Security Act.

Procedure of a Cybercrime Case

A cybercrime case may generally progress through the following stages:

Complaint or information regarding the alleged cybercrime

Registration/initiation of the criminal case where legally appropriate

Investigation by the authorised investigating officer

Collection and preservation of digital evidence

Search and seizure where legally authorised

Examination of witnesses and digital evidence

Forensic analysis

Submission of the investigation report

Cognizance by the Cyber Tribunal under the applicable procedure

Framing of charge where appropriate

Prosecution evidence

Cross-examination of witnesses

Examination of the accused under the applicable criminal procedure

Defence evidence where applicable

Arguments

Judgment

Sentence or acquittal

Appeal where legally available

Section 39 also imposes confidentiality requirements concerning information obtained during investigations.

Legal Remedies for Victims of Cybercrime

A person affected by cybercrime should consider taking action quickly because digital evidence can disappear rapidly.

Depending on the circumstances, possible legal steps include:

1. Report the Crime

The victim can report the incident to the appropriate law-enforcement authority and provide the relevant information and evidence.

2. Preserve Digital Evidence

The victim should preserve:

Screenshots

URLs

Usernames and account IDs

Emails

Messages

Transaction records

Payment receipts

Call records where lawfully available

Original files

Relevant device information

Dates and times of incidents

Original digital material should be preserved whenever possible.

3. Seek Investigation

A criminal complaint can lead to investigation by the competent authority where the alleged conduct falls within the applicable criminal framework.

4. Seek Appropriate Judicial Relief

Depending on the nature of the matter, a victim may pursue remedies through the criminal justice system and, where another legal cause of action exists, potentially through civil or other appropriate proceedings.

5. Protect Financial Accounts

Where the cybercrime involves financial fraud, the affected person should promptly contact the relevant bank, mobile financial service provider or payment service and report the suspicious transaction.

Legal action and financial-security measures can often need to proceed simultaneously.

What Should a Person Do If Intimate Images Are Used for Blackmail?

Cases involving sextortion or threats to publish intimate material require immediate action.

A victim should generally:

Preserve the messages and original evidence.

Avoid deleting relevant communications before preserving them.

Record the account name, profile URL and other identifying information.

Preserve evidence of payment demands or threats.

Report the account or content to the relevant platform where appropriate.

Contact law enforcement.

Seek advice from a lawyer regarding the applicable criminal provisions.

If the victim is a child, seek immediate child-protection assistance and legal support.

Section 25 specifically covers specified online blackmailing, sextortion, revenge pornography and related conduct, including certain AI-generated or AI-edited material.

Can a Cybercrime Accused Get Bail?

Yes, depending on the offence.

The current Cyber Security Act expressly classifies specified offences as bailable and others as non-bailable under section 46.

For a bailable offence, the applicable statutory framework provides a stronger basis for release on bail subject to the law.

For a non-bailable offence, bail is a judicial matter and depends on the applicable criminal procedure, the statutory offence, evidence, circumstances of the accused and other relevant considerations.

Therefore, the first step in assessing bail is to determine the exact section under which the person has been charged or arrested.

Can a Cybercrime Case Be Quashed?

The possibility of challenging a criminal proceeding depends on the circumstances and procedural stage.

Where the legal requirements for exercising the High Court Division's inherent jurisdiction are satisfied, an accused may have a remedy under the applicable criminal procedure framework.

However, quashing is not an automatic remedy merely because the accused disputes the allegations.

Questions involving disputed facts, authenticity of evidence and credibility of witnesses may ordinarily require consideration through the appropriate trial process rather than being resolved solely through an extraordinary jurisdiction.

Can a Cybercrime Case Be Compromised?

Not every cybercrime is legally treated as a private dispute capable of being withdrawn simply because the complainant and accused reach an agreement.

Whether an offence is compoundable or whether proceedings can otherwise be terminated depends on the applicable statutory provisions and the nature and stage of the case.

A private settlement therefore does not automatically terminate a cybercrime prosecution.

Appeal in a Cybercrime Case

A person aggrieved by a judgment of the Cyber Tribunal may appeal to the Cyber Appellate Tribunal under section 41 of the Cyber Security Act.

The precise procedure and limitation period should be checked against the applicable statutory provisions and the judgment or order concerned.

A convicted person should obtain a certified copy of the judgment promptly and consult a lawyer regarding the applicable appellate deadline.

Cybercrime and Online Defamation

Not every offensive, insulting or defamatory social-media statement should automatically be described as a Cyber Security Act offence.

The legal classification depends on the content, conduct, applicable statutory provision and surrounding facts.

A statement published online may potentially raise issues under other laws, including the Penal Code's defamation provisions, even where the conduct does not fall within a specific offence under the Cyber Security Act.

The distinction is important because not every online dispute is necessarily a cybercrime under the Cyber Security Act.

Cybercrime and Personal Data

Cybercrime can also overlap with unlawful collection, disclosure, misuse or compromise of personal information.

Bangladesh's legal framework now includes the Personal Data Protection Act, 2026, which operates alongside the Cyber Security Act in the broader digital legal environment.

Therefore, a data breach or misuse of personal information may require analysis under more than one statute depending on the facts.

Cyber Security Act 2026: Selected Penalties

Cyber offenceRelevant sectionMaximum punishment
Unauthorised access to CIISection 17Up to 5 years + Tk 50 lakh, or both
Specified harmful conduct involving CIISection 17Up to 7 years + Tk 1 crore, or both
Unauthorised access/hackingSection 18Up to 5 years + Tk 50 lakh, or both
Cyber fraudSection 21Up to 2 years + Tk 20 lakh, or both
Cyber deception/fraudSection 22Up to 5 years + Tk 50 lakh, or both
Cyber terrorismSection 23Up to 10 years + Tk 1 crore, or both
Online blackmail/sextortion etc.Section 25Up to 2 years + Tk 10 lakh, or both
Section 25 offence against woman/childSection 25(3)Up to 5 years + Tk 20 lakh, or both
Specified religious/ethnic hate-related cyber offenceSection 26Up to 2 years + Tk 10 lakh, or both

The table provides the statutory maximums for selected offences; the actual sentence in an individual case depends on the applicable provision, evidence and circumstances.

Cybercrime Case vs Ordinary Criminal Case

IssueCybercrime caseOrdinary criminal case
Principal specialised lawCyber Security Act, 2026Relevant criminal/special law
EvidenceOften includes digital and forensic evidenceDepends on offence
InvestigationPolice/investigating officer with specialised digital proceduresGeneral criminal investigation framework
Investigation periodSpecific 90-day statutory frameworkDepends on applicable law
Trial forumCyber TribunalDepends on offence
AppealCyber Appellate TribunalRelevant appellate court
Digital forensicsSpecifically recognisedDepends on case and applicable law
Special search powersProvided in specified circumstancesGeneral CrPC framework, subject to special laws

Practical Advice for a Cybercrime Victim

If you believe you have been the victim of a cybercrime:

1. Preserve the evidence.
Do not immediately delete messages, accounts, emails or files that may later be important.

2. Record the timeline.
Write down when the incident occurred and what happened.

3. Preserve transaction information.
For financial fraud, keep bank statements, transaction IDs, payment receipts and communications.

4. Preserve account information.
Record usernames, profile links, phone numbers, email addresses and other relevant identifiers.

5. Secure your accounts.
Change passwords and activate appropriate multi-factor authentication where possible.

6. Report financial fraud immediately.
Contact the relevant financial institution or payment service without unnecessary delay.

7. Make a formal complaint where appropriate.
Provide organised evidence to the relevant law-enforcement authority.

8. Consult a lawyer for serious allegations.
This is particularly important where the matter involves arrest, search, seizure, blackmail, financial loss or criminal prosecution.

Practical Advice for a Person Accused of Cybercrime

A person accused of cybercrime should:

Obtain the FIR or complaint information.

Identify the exact statutory provision alleged.

Determine whether the offence is bailable or non-bailable.

Obtain legal advice before making substantive statements.

Preserve potentially exculpatory digital evidence.

Avoid deleting or altering potentially relevant data.

Avoid contacting or threatening the complainant.

Review search and seizure documentation.

Examine the authenticity and provenance of digital evidence.

Apply for bail where legally appropriate.

Monitor investigation and court proceedings.

Obtain the judgment promptly if convicted and consider the available appeal.

Frequently Asked Questions

What is the main cybercrime law in Bangladesh in 2026?

The principal specialised law is the Cyber Security Act, 2026, which replaced the Cyber Security Ordinance, 2025. The 2026 Act is deemed effective from 21 May 2025.

What is the punishment for hacking in Bangladesh?

Specified unauthorised-access offences under section 18 can carry up to 5 years' imprisonment, a fine of up to Tk 50 lakh, or both. More serious conduct involving critical information infrastructure can attract higher penalties under section 17.

Is cybercrime a bailable offence in Bangladesh?

It depends on the particular offence. Section 46 specifically classifies certain cyber offences as bailable and others as non-bailable.

Which court hears cybercrime cases?

Offences under the Cyber Security Act are tried by a Cyber Tribunal. Appeals from the Tribunal go to the Cyber Appellate Tribunal.

How long can a cybercrime investigation take?

Section 32 provides a general 90-day investigation period from the date the investigating officer receives responsibility for investigating the offence, subject to the applicable statutory procedure.

Can screenshots be evidence in a cybercrime case?

Digital screenshots and other electronic records can be relevant evidence, but their evidentiary value depends on issues such as authenticity, integrity, identification, provenance and applicable evidentiary rules. The Cyber Security Act expressly recognises digital forensic evidence.

What should I do if someone threatens to publish my private photographs?

Preserve the threats and original evidence, avoid deleting relevant communications, secure your accounts, report the matter to the appropriate authorities and obtain legal advice. Specified blackmailing, sextortion and revenge-porn conduct are expressly addressed by section 25 of the Cyber Security Act.

Can AI-generated content lead to a cybercrime case?

Potentially, yes. The Cyber Security Act expressly recognises AI technology within its digital framework and section 25 includes specified AI-generated or AI-edited material in the offences it covers.

Can a false cybercrime case have legal consequences?

Yes. Section 28 specifically addresses filing or causing a case or complaint to be filed without lawful or reasonable grounds with an intention to cause harm, subject to the statutory requirements of that provision.

Key Takeaways

The principal specialised cybercrime statute in Bangladesh is the Cyber Security Act, 2026.

The Act replaced the Cyber Security Ordinance, 2025 and the Cyber Security Act, 2023.

Cyber offences can include hacking, cyber fraud, cyber terrorism, online blackmail, sextortion, revenge pornography and other specified digital conduct.

Penalties vary substantially according to the offence.

Some cyber offences are bailable, while others are non-bailable.

Cybercrime investigations can involve digital forensics, electronic communications, devices, transaction records and other digital evidence.

The Act provides a general 90-day investigation period.

Cybercrime offences under the Act are tried by Cyber Tribunals.

Appeals from Cyber Tribunal judgments go to the Cyber Appellate Tribunal.

Digital forensic evidence is expressly recognised by the Act.

Victims should preserve digital evidence as early as possible.

Persons accused of cybercrime should identify the exact statutory charge and obtain legal advice promptly.

A complaint should not be filed merely to harass another person; the Act contains a specific provision concerning certain knowingly baseless complaints intended to cause harm.

Conclusion

Cybercrime law in Bangladesh has undergone significant changes since the repeal of the Cyber Security Act, 2023. The Cyber Security Act, 2026 is now the principal specialised framework and introduces a detailed structure covering cyber offences, investigation, digital evidence, specialised tribunals and appeals.

For victims, prompt preservation of electronic evidence is often critical. For accused persons, the exact statutory section, classification of the offence, evidence collected during investigation and applicable bail provisions can materially affect the legal process.

Because cybercrime cases can involve technically complex evidence as well as serious criminal penalties, the appropriate legal strategy depends on the facts of the individual case, the applicable statutory provision and the available evidence.

Authoritative Legal Sources

Cyber Security Act, 2026 — Bangladesh Laws

Bangladesh Laws — Ministry of Law, Justice and Parliamentary Affairs

Bangladesh Supreme Court