Bhutan’s crime scene is no longer confined to the streets, homes and businesses. Mobile phones are becoming an increasingly common tool for cyber-related offences. According to the Royal Bhutan Police’s Statistical Yearbook 2025, the country recorded nearly 160 cyber-related criminal incidents last year. Most involved fraud, identity theft, online scams, harassment and impersonation, carried out through ordinary smartphones.
The message received online may look harmless. A delivery notification, a prize announcement, and an online shopping offer.
Or perhaps a request for a one-time password (OTP). But behind an ordinary-looking message can be a carefully designed attempt to gain access to personal information or money.
And the police figures show that these kinds of offences are increasingly changing Bhutan’s crime landscape.
Of the 159 cyber-related cases recorded last year, 158 involved crimes committed using digital platforms or devices, while only one involved a direct attack on a computer system.
This means most cases were not about criminals breaking into computer systems, but rather about using technology to commit crimes such as fraud, harassment and defamation.
Of the total cases, 116 were computer-related fraud and forgery, making up 73 per cent. Another 42 cases involved content-related acts, including harassment, defamation and blackmail.
One case involved an offence against the confidentiality, integrity and availability of computer systems.
Financial fraud was the most common type of cyber-related offence recorded by police.
OTP and banking fraud accounted for 30 cases, followed by identity theft and account takeover with 26 cases, and online financial fraud with another 26 cases.
Online marketplace scams were also significant, with 24 cases.
Other offences included cyberstalking and online harassment, online defamation, online gambling, impersonation, blackmail and sextortion, and online investment scams.
The figures show that cybercrime is not limited to one particular type of victim or one particular form of deception. Criminals/suspects are using different online platforms and methods depending on what they are trying to achieve.
HOW OFFENDERS OPERATED
Social engineering, where offenders manipulate or deceive a person into giving away information or taking an action, was the most common method. OTP theft through social engineering accounted for 28 cases.
Online harassment and defamation campaigns were the second most common method, with 22 cases, followed by fake online marketplaces with 19 cases.
Police also recorded 14 cases involving the misuse of CID or voter card details in the CPMS/BMS system.
Other methods included impersonating officials or telecom employees, lucky-draw and prize scams, sextortion and thre atening digital content, and investment or Ponzi schemes.
Mobile phones are at the centre of the offences committed. Mobile phones were involved in 126 cyber-related records, or 86.3 per cent of cases where technology was recorded. This means the device people use every day to communicate, shop, make payments and access their bank accounts is also becoming a common tool in cyber-related crime.
For many victims, cybercrime does not end with a suspicious message or a compromised account. It can result in lost money.
The police recorded financial loss in 104 of the 159 cases, or 65.4 per cent of all cyber-related incidents.
Another 55 cases did not involve monetary loss. The yearbook, however, does not provide the total amount of money lost through these cases.
And the risk is not confined to one place.
Thimphu recorded the highest number of cyber-related cases, at 61. This accounted for 38.4 per cent of the national total. Chhukha followed with 27 cases, and Sarpang recorded 11.
As online banking, digital payments, social media and online shopping become more common, the risks of cyber-related offences are also reaching smaller communities.
Tashi Dekar
Edited by Sonam Pem




