Cyber Crime in Bangladesh: Laws, Penalties and Legal Remedies
Cyber Crime in Bangladesh: Laws, Penalties and Legal Remedies
Cybercrime has become an increasingly important area of criminal law in Bangladesh as banking, e-commerce, social media, digital communications and government services increasingly depend on digital systems.
As of 2026, the principal legislation governing cyber offences in Bangladesh is the Cyber Security Act, 2026. The Act replaced the Cyber Security Ordinance, 2025, which itself had replaced the Cyber Security Act, 2023. The 2026 Act is deemed to have come into force from 21 May 2025.
The current framework covers offences such as unauthorised access or hacking, attacks against critical information infrastructure, cyber fraud, cyber terrorism, online sexual harassment and blackmailing, certain hate-related cyber activities, cyber gambling and other specified digital offences. It also establishes a procedure for investigation, digital forensic evidence, trial before Cyber Tribunals and appeals.
This guide explains cybercrime laws in Bangladesh, common cyber offences, penalties, investigation, bail, trial procedure and legal remedies available to victims and accused persons.
What Is Cybercrime in Bangladesh?
Cybercrime generally refers to criminal conduct involving computers, digital devices, computer systems, networks, electronic communications or cyberspace.
Under the current Cyber Security Act, 2026, the statutory framework is broad enough to cover technologies including digital devices, artificial intelligence technologies, blockchain, large language models, machine-vision systems and other modern computing technologies.
Examples of conduct that may amount to cybercrime include:
Unauthorised access to a computer or digital system
Hacking
Destruction or alteration of digital data
Attacks against critical information infrastructure
Cyber fraud
Cyber terrorism
Online blackmailing
Sextortion
Revenge pornography
Certain forms of digital child sexual-abuse material
Cyber-related financial fraud
Certain forms of online gambling
Cyber-related religious or ethnic hate activities
Digital activities specifically criminalised by the Cyber Security Act
The exact offence depends on the conduct, evidence and statutory provision applicable to the particular case.
What Is the Main Cybercrime Law in Bangladesh?
The principal statute is the Cyber Security Act, 2026 (Act No. 81 of 2026).
The Act expressly repealed the Cyber Security Ordinance, 2025 and the Cyber Security (Amendment) Ordinance, 2025. It also replaced the Cyber Security Act, 2023.
The 2026 Act also contains transitional provisions explaining how certain cases filed under the repealed 2023 law are to be treated. Some specified pending cases continue under the relevant tribunal framework, while proceedings concerning certain repealed offences are cancelled under the statutory transition provisions.
Cyber Security Act, 2026 — Bangladesh Laws
Other Laws That May Apply to Cybercrime
The Cyber Security Act is not necessarily the only law relevant to conduct occurring online.
Depending on the facts, a case may also involve:
The Penal Code, 1860
The Code of Criminal Procedure, 1898
The Evidence Act, 1872
The Information and Communication Technology Act, 2006
The Personal Data Protection Act, 2026
Laws dealing with financial crimes, fraud, pornography, child protection or other specific offences
Section 42 of the Cyber Security Act provides that, unless the Act provides otherwise, relevant provisions of the Code of Criminal Procedure, Evidence Act and Information and Communication Technology Act apply to proceedings under the Act.
Major Cyber Offences Under the Cyber Security Act, 2026
1. Illegal Access to Critical Information Infrastructure
Critical Information Infrastructure, or CII, refers to infrastructure whose disruption or compromise could adversely affect areas such as public safety, economic security, public health, national security, territorial integrity or sovereignty.
Section 17 criminalises specified unauthorised access and harmful activities involving CII.
Depending on the conduct, the maximum punishment can be:
Up to 5 years' imprisonment, or
Up to Tk 50 lakh fine, or
Both.
Where unauthorised access causes the specified forms of damage or interference described in the provision, the maximum punishment can rise to:
7 years' imprisonment, or
Tk 1 crore fine, or
Both.
2. Unauthorised Access or Hacking
Section 18 addresses unauthorised access to computers, digital devices, computer systems and networks.
Depending on the specific conduct covered by the provision, the offence can carry imprisonment of up to 5 years, a fine of up to Tk 50 lakh, or both.
Hacking cases can therefore involve significant criminal consequences even where the alleged conduct does not involve a traditional physical crime.
3. Cyber Fraud
Section 21 deals with cyber fraud.
The provision covers specified unauthorised manipulation or creation of digital information, files, programs, electronic documents and other digital activities. It also expressly addresses certain activities involving digital money, electronic currency, cryptocurrency, SIMs registered in another person's identity, mobile banking, hundi-related activity and gambling portals.
The maximum punishment is:
2 years' imprisonment, or
Tk 20 lakh fine, or
Both.
4. Cyber Fraudulent Deception
Section 22 separately addresses fraud through cyberspace.
The statutory definition covers specified manipulation, deletion, addition or alteration of information in computer programs, systems, networks, digital devices, e-commerce or social-media systems for obtaining financial or other benefits or causing harm through deception.
The maximum punishment is:
5 years' imprisonment, or
Tk 50 lakh fine, or
Both.
5. Cyber Terrorism
Section 23 addresses specified cyber activities intended to threaten national security, sovereignty or territorial integrity, create fear among the public, or cause serious harm through digital systems.
The maximum punishment under the provision is:
10 years' imprisonment, or
Tk 1 crore fine, or
Both.
Because of the seriousness of the allegation, cyber-terrorism cases can involve extensive investigation and digital-forensic examination.
Online Blackmail, Sextortion and Revenge Porn
One of the important areas covered by the current law is online sexual harassment, blackmailing, revenge pornography and sextortion.
Section 25 covers specified conduct involving the transmission, publication or dissemination—or threats to disseminate—harmful digital material for purposes including:
Blackmailing
Sexual harassment
Revenge pornography
Sextortion
Digital child sexual-abuse material
The provision also expressly covers material that has been created or edited using artificial intelligence.
For the basic offence, the maximum punishment is:
2 years' imprisonment, or
Tk 10 lakh fine, or
Both.
Where the offence is committed against a woman or a child under 18, the maximum punishment can be:
5 years' imprisonment, or
Tk 20 lakh fine, or
Both.
This is particularly relevant to cases involving threats to publish private photographs, videos, recordings or AI-generated material.
Religious or Ethnic Hate-Related Cyber Offences
Section 26 addresses specified online publication or dissemination of religious, communal or ethnic hatred-related material where the conduct is connected with violence, public concern, disorder or directions toward criminal activity.
The maximum punishment is:
2 years' imprisonment, or
Tk 10 lakh fine, or
Both.
The provision is directed at conduct meeting its statutory requirements; ordinary criticism or disagreement should not automatically be treated as an offence merely because it occurs online.
Cyber Gambling
The Cyber Security Ordinance, 2025 contained provisions concerning online gambling, and the current 2026 framework continues to regulate specified cyber-space gambling activities.
The relevant provision covers activities such as creating or operating gambling portals or applications, participating in online gambling, facilitating or encouraging gambling and specified advertising or promotion.
The precise punishment should be determined from the current statutory provision applicable to the alleged conduct.
Assisting a Cybercrime
A person does not necessarily avoid criminal liability simply because they did not personally carry out the principal cyber activity.
Section 27 provides that a person who assists in committing an offence under the Cyber Security Act commits an offence and may receive the punishment prescribed for the underlying offence.
This can be relevant where multiple people are alleged to have participated in a cybercrime.
False Cybercrime Cases and Complaints
Section 28 addresses knowingly initiating a case or complaint under the Act without lawful or reasonable grounds with the intention of causing harm to another person.
The provision provides for punishment corresponding to the punishment prescribed for the underlying offence.
Therefore, filing a cybercrime complaint is not something that should be done merely as a threat or means of harassment.
Is Cybercrime a Cognizable Offence?
Not every offence under the Cyber Security Act has the same procedural classification.
Section 46 divides offences into cognizable and non-cognizable categories.
The Act specifies that offences under sections:
17
18(1)(c)
19
20
21
22
23
25
are cognizable, while offences under the other specified provisions are non-cognizable.
The same section also distinguishes between bailable and non-bailable offences.
Which Cyber Offences Are Bailable?
Section 46 specifically classifies certain offences as bailable or non-bailable.
Under the current statutory framework:
Non-bailable offences include specified offences under:
Section 17
Section 18(1)(c)
Section 19
Section 22
Section 23
Bailable offences include specified offences under:
Section 18(1)(a) and (b)
Section 20
Section 21
Section 24
Section 25
Section 26
The classification is important because the legal approach to bail differs between bailable and non-bailable offences.
A person should therefore identify the exact section mentioned in the case rather than assuming that every cybercrime is either bailable or non-bailable.
Investigation of Cybercrime Cases
Cybercrime investigations can involve both traditional criminal investigation and specialised digital-forensic work.
Under section 31, cyber offences are investigated by police officers or designated investigating officers. In appropriate circumstances, the Tribunal may form a joint investigation team involving investigative agencies, law-enforcement agencies and other relevant agencies.
Investigators may examine:
Computers
Mobile phones
Digital devices
Social-media accounts
Email accounts
Server information
Network information
Transaction records
Digital documents
Electronic communications
Metadata
Digital payment records
Other relevant digital evidence
Time Limit for Cybercrime Investigation
Section 32 provides a specific investigation timeline.
An investigating officer is required to complete an investigation within 90 days from the date of receiving responsibility for investigating the offence.
The Act also provides mechanisms concerning specialised assistance in collecting evidence and conducting investigations.
The existence of a statutory timeline does not mean every case will necessarily conclude within 90 days in practice; the applicable statutory procedure and any lawful extension or related judicial process must be considered.
Search and Seizure in Cybercrime Cases
Digital evidence can be extremely fragile because data may be deleted, altered or encrypted.
Section 34 permits an authorised police officer, after recording reasons and obtaining a search warrant from the appropriate Tribunal, Chief Judicial Magistrate or Chief Metropolitan Magistrate, to undertake specified searches and obtain relevant digital evidence.
The provision can involve obtaining traffic data and customer information from service providers and dealing with electronic communications in accordance with the statutory framework.
Search and Arrest Without Warrant in Certain Hacking Cases
Section 35 creates a special mechanism for circumstances involving cyberattacks or unauthorised access where there is a risk that evidence may be deleted, altered, destroyed or made inaccessible.
In such circumstances, after recording reasons, the police may have powers specified by the section to:
Enter and search the relevant location
Seize computers and digital equipment
Seize relevant documents or evidence
Search persons present
Arrest a person where the statutory conditions are satisfied
After arrest, the person must be produced before the nearest Magistrate or Tribunal within the constitutional and statutory time limit, generally within 24 hours excluding necessary journey time.
Digital Forensic Evidence
Digital evidence is often central to cybercrime litigation.
Section 43 provides that forensic evidence obtained or collected under the Act can be treated as evidence in judicial proceedings, subject to the statutory framework. It also requires preservation of digital forensic evidence prepared by a digital forensic laboratory.
The Tribunal or Appellate Tribunal may also seek expert opinions from persons experienced in areas such as:
Computer science
Digital forensics
Electronic communications
Data protection
Can Screenshots Be Used as Evidence?
Screenshots, messages, photographs, emails and other electronic records may become relevant evidence, but producing a screenshot does not automatically establish every fact that the screenshot appears to show.
Questions can arise concerning:
Authenticity
Source
Identification of the account
Integrity of the file
Date and time
Whether the material was altered
Chain of custody
Metadata
Digital forensic verification
The Evidence Act and the special evidentiary provisions of the Cyber Security Act must therefore be considered when assessing digital evidence. Section 42 makes the Evidence Act applicable where the Cyber Security Act does not provide otherwise.
Where Are Cybercrime Cases Tried?
Section 41 provides that offences under the Cyber Security Act are to be tried only by a Cyber Tribunal.
A person aggrieved by a judgment of the Cyber Tribunal may appeal to the Cyber Appellate Tribunal.
The Cyber Tribunal is established under the framework of the Information and Communication Technology Act, 2006, as recognised by the Cyber Security Act.
Procedure of a Cybercrime Case
A cybercrime case may generally progress through the following stages:
Complaint or information regarding the alleged cybercrime
Registration/initiation of the criminal case where legally appropriate
Investigation by the authorised investigating officer
Collection and preservation of digital evidence
Search and seizure where legally authorised
Examination of witnesses and digital evidence
Forensic analysis
Submission of the investigation report
Cognizance by the Cyber Tribunal under the applicable procedure
Framing of charge where appropriate
Prosecution evidence
Cross-examination of witnesses
Examination of the accused under the applicable criminal procedure
Defence evidence where applicable
Arguments
Judgment
Sentence or acquittal
Appeal where legally available
Section 39 also imposes confidentiality requirements concerning information obtained during investigations.
Legal Remedies for Victims of Cybercrime
A person affected by cybercrime should consider taking action quickly because digital evidence can disappear rapidly.
Depending on the circumstances, possible legal steps include:
1. Report the Crime
The victim can report the incident to the appropriate law-enforcement authority and provide the relevant information and evidence.
2. Preserve Digital Evidence
The victim should preserve:
Screenshots
URLs
Usernames and account IDs
Emails
Messages
Transaction records
Payment receipts
Call records where lawfully available
Original files
Relevant device information
Dates and times of incidents
Original digital material should be preserved whenever possible.
3. Seek Investigation
A criminal complaint can lead to investigation by the competent authority where the alleged conduct falls within the applicable criminal framework.
4. Seek Appropriate Judicial Relief
Depending on the nature of the matter, a victim may pursue remedies through the criminal justice system and, where another legal cause of action exists, potentially through civil or other appropriate proceedings.
5. Protect Financial Accounts
Where the cybercrime involves financial fraud, the affected person should promptly contact the relevant bank, mobile financial service provider or payment service and report the suspicious transaction.
Legal action and financial-security measures can often need to proceed simultaneously.
What Should a Person Do If Intimate Images Are Used for Blackmail?
Cases involving sextortion or threats to publish intimate material require immediate action.
A victim should generally:
Preserve the messages and original evidence.
Avoid deleting relevant communications before preserving them.
Record the account name, profile URL and other identifying information.
Preserve evidence of payment demands or threats.
Report the account or content to the relevant platform where appropriate.
Contact law enforcement.
Seek advice from a lawyer regarding the applicable criminal provisions.
If the victim is a child, seek immediate child-protection assistance and legal support.
Section 25 specifically covers specified online blackmailing, sextortion, revenge pornography and related conduct, including certain AI-generated or AI-edited material.
Can a Cybercrime Accused Get Bail?
Yes, depending on the offence.
The current Cyber Security Act expressly classifies specified offences as bailable and others as non-bailable under section 46.
For a bailable offence, the applicable statutory framework provides a stronger basis for release on bail subject to the law.
For a non-bailable offence, bail is a judicial matter and depends on the applicable criminal procedure, the statutory offence, evidence, circumstances of the accused and other relevant considerations.
Therefore, the first step in assessing bail is to determine the exact section under which the person has been charged or arrested.
Can a Cybercrime Case Be Quashed?
The possibility of challenging a criminal proceeding depends on the circumstances and procedural stage.
Where the legal requirements for exercising the High Court Division's inherent jurisdiction are satisfied, an accused may have a remedy under the applicable criminal procedure framework.
However, quashing is not an automatic remedy merely because the accused disputes the allegations.
Questions involving disputed facts, authenticity of evidence and credibility of witnesses may ordinarily require consideration through the appropriate trial process rather than being resolved solely through an extraordinary jurisdiction.
Can a Cybercrime Case Be Compromised?
Not every cybercrime is legally treated as a private dispute capable of being withdrawn simply because the complainant and accused reach an agreement.
Whether an offence is compoundable or whether proceedings can otherwise be terminated depends on the applicable statutory provisions and the nature and stage of the case.
A private settlement therefore does not automatically terminate a cybercrime prosecution.
Appeal in a Cybercrime Case
A person aggrieved by a judgment of the Cyber Tribunal may appeal to the Cyber Appellate Tribunal under section 41 of the Cyber Security Act.
The precise procedure and limitation period should be checked against the applicable statutory provisions and the judgment or order concerned.
A convicted person should obtain a certified copy of the judgment promptly and consult a lawyer regarding the applicable appellate deadline.
Cybercrime and Online Defamation
Not every offensive, insulting or defamatory social-media statement should automatically be described as a Cyber Security Act offence.
The legal classification depends on the content, conduct, applicable statutory provision and surrounding facts.
A statement published online may potentially raise issues under other laws, including the Penal Code's defamation provisions, even where the conduct does not fall within a specific offence under the Cyber Security Act.
The distinction is important because not every online dispute is necessarily a cybercrime under the Cyber Security Act.
Cybercrime and Personal Data
Cybercrime can also overlap with unlawful collection, disclosure, misuse or compromise of personal information.
Bangladesh's legal framework now includes the Personal Data Protection Act, 2026, which operates alongside the Cyber Security Act in the broader digital legal environment.
Therefore, a data breach or misuse of personal information may require analysis under more than one statute depending on the facts.
Cyber Security Act 2026: Selected Penalties
| Cyber offence | Relevant section | Maximum punishment |
|---|---|---|
| Unauthorised access to CII | Section 17 | Up to 5 years + Tk 50 lakh, or both |
| Specified harmful conduct involving CII | Section 17 | Up to 7 years + Tk 1 crore, or both |
| Unauthorised access/hacking | Section 18 | Up to 5 years + Tk 50 lakh, or both |
| Cyber fraud | Section 21 | Up to 2 years + Tk 20 lakh, or both |
| Cyber deception/fraud | Section 22 | Up to 5 years + Tk 50 lakh, or both |
| Cyber terrorism | Section 23 | Up to 10 years + Tk 1 crore, or both |
| Online blackmail/sextortion etc. | Section 25 | Up to 2 years + Tk 10 lakh, or both |
| Section 25 offence against woman/child | Section 25(3) | Up to 5 years + Tk 20 lakh, or both |
| Specified religious/ethnic hate-related cyber offence | Section 26 | Up to 2 years + Tk 10 lakh, or both |
The table provides the statutory maximums for selected offences; the actual sentence in an individual case depends on the applicable provision, evidence and circumstances.
Cybercrime Case vs Ordinary Criminal Case
| Issue | Cybercrime case | Ordinary criminal case |
|---|---|---|
| Principal specialised law | Cyber Security Act, 2026 | Relevant criminal/special law |
| Evidence | Often includes digital and forensic evidence | Depends on offence |
| Investigation | Police/investigating officer with specialised digital procedures | General criminal investigation framework |
| Investigation period | Specific 90-day statutory framework | Depends on applicable law |
| Trial forum | Cyber Tribunal | Depends on offence |
| Appeal | Cyber Appellate Tribunal | Relevant appellate court |
| Digital forensics | Specifically recognised | Depends on case and applicable law |
| Special search powers | Provided in specified circumstances | General CrPC framework, subject to special laws |
Practical Advice for a Cybercrime Victim
If you believe you have been the victim of a cybercrime:
1. Preserve the evidence.
Do not immediately delete messages, accounts, emails or files that may later be important.
2. Record the timeline.
Write down when the incident occurred and what happened.
3. Preserve transaction information.
For financial fraud, keep bank statements, transaction IDs, payment receipts and communications.
4. Preserve account information.
Record usernames, profile links, phone numbers, email addresses and other relevant identifiers.
5. Secure your accounts.
Change passwords and activate appropriate multi-factor authentication where possible.
6. Report financial fraud immediately.
Contact the relevant financial institution or payment service without unnecessary delay.
7. Make a formal complaint where appropriate.
Provide organised evidence to the relevant law-enforcement authority.
8. Consult a lawyer for serious allegations.
This is particularly important where the matter involves arrest, search, seizure, blackmail, financial loss or criminal prosecution.
Practical Advice for a Person Accused of Cybercrime
A person accused of cybercrime should:
Obtain the FIR or complaint information.
Identify the exact statutory provision alleged.
Determine whether the offence is bailable or non-bailable.
Obtain legal advice before making substantive statements.
Preserve potentially exculpatory digital evidence.
Avoid deleting or altering potentially relevant data.
Avoid contacting or threatening the complainant.
Review search and seizure documentation.
Examine the authenticity and provenance of digital evidence.
Apply for bail where legally appropriate.
Monitor investigation and court proceedings.
Obtain the judgment promptly if convicted and consider the available appeal.
Frequently Asked Questions
What is the main cybercrime law in Bangladesh in 2026?
The principal specialised law is the Cyber Security Act, 2026, which replaced the Cyber Security Ordinance, 2025. The 2026 Act is deemed effective from 21 May 2025.
What is the punishment for hacking in Bangladesh?
Specified unauthorised-access offences under section 18 can carry up to 5 years' imprisonment, a fine of up to Tk 50 lakh, or both. More serious conduct involving critical information infrastructure can attract higher penalties under section 17.
Is cybercrime a bailable offence in Bangladesh?
It depends on the particular offence. Section 46 specifically classifies certain cyber offences as bailable and others as non-bailable.
Which court hears cybercrime cases?
Offences under the Cyber Security Act are tried by a Cyber Tribunal. Appeals from the Tribunal go to the Cyber Appellate Tribunal.
How long can a cybercrime investigation take?
Section 32 provides a general 90-day investigation period from the date the investigating officer receives responsibility for investigating the offence, subject to the applicable statutory procedure.
Can screenshots be evidence in a cybercrime case?
Digital screenshots and other electronic records can be relevant evidence, but their evidentiary value depends on issues such as authenticity, integrity, identification, provenance and applicable evidentiary rules. The Cyber Security Act expressly recognises digital forensic evidence.
What should I do if someone threatens to publish my private photographs?
Preserve the threats and original evidence, avoid deleting relevant communications, secure your accounts, report the matter to the appropriate authorities and obtain legal advice. Specified blackmailing, sextortion and revenge-porn conduct are expressly addressed by section 25 of the Cyber Security Act.
Can AI-generated content lead to a cybercrime case?
Potentially, yes. The Cyber Security Act expressly recognises AI technology within its digital framework and section 25 includes specified AI-generated or AI-edited material in the offences it covers.
Can a false cybercrime case have legal consequences?
Yes. Section 28 specifically addresses filing or causing a case or complaint to be filed without lawful or reasonable grounds with an intention to cause harm, subject to the statutory requirements of that provision.
Key Takeaways
The principal specialised cybercrime statute in Bangladesh is the Cyber Security Act, 2026.
The Act replaced the Cyber Security Ordinance, 2025 and the Cyber Security Act, 2023.
Cyber offences can include hacking, cyber fraud, cyber terrorism, online blackmail, sextortion, revenge pornography and other specified digital conduct.
Penalties vary substantially according to the offence.
Some cyber offences are bailable, while others are non-bailable.
Cybercrime investigations can involve digital forensics, electronic communications, devices, transaction records and other digital evidence.
The Act provides a general 90-day investigation period.
Cybercrime offences under the Act are tried by Cyber Tribunals.
Appeals from Cyber Tribunal judgments go to the Cyber Appellate Tribunal.
Digital forensic evidence is expressly recognised by the Act.
Victims should preserve digital evidence as early as possible.
Persons accused of cybercrime should identify the exact statutory charge and obtain legal advice promptly.
A complaint should not be filed merely to harass another person; the Act contains a specific provision concerning certain knowingly baseless complaints intended to cause harm.
Conclusion
Cybercrime law in Bangladesh has undergone significant changes since the repeal of the Cyber Security Act, 2023. The Cyber Security Act, 2026 is now the principal specialised framework and introduces a detailed structure covering cyber offences, investigation, digital evidence, specialised tribunals and appeals.
For victims, prompt preservation of electronic evidence is often critical. For accused persons, the exact statutory section, classification of the offence, evidence collected during investigation and applicable bail provisions can materially affect the legal process.
Because cybercrime cases can involve technically complex evidence as well as serious criminal penalties, the appropriate legal strategy depends on the facts of the individual case, the applicable statutory provision and the available evidence.
Authoritative Legal Sources
Cyber Security Act, 2026 — Bangladesh Laws
Bangladesh Laws — Ministry of Law, Justice and Parliamentary Affairs
