TRW KNOWLEDGE · LEGAL INFORMATION

Guide to Legal Aid for Cybercrime Victims in Bangladesh (2026 Update)

A detailed analysis of the legal framework and procedural pathways for cybercrime victims in Bangladesh to access state-supported legal assistance and representation.

Originally published 29 July 2026
2026 updateThis article retains its original publication date. Its structure, internal navigation and general information have been refreshed for 2026; current primary sources and advice should be checked before acting on any specific matter.

Introduction

The rapid digital transformation within the People's Republic of Bangladesh has fundamentally altered the socio-economic landscape, facilitating unprecedented connectivity and economic growth. However, this shift has also introduced a complex array of digital vulnerabilities, leading to a rise in cyber-enabled offenses. Cybercrime, encompassing a spectrum of illicit activities from unauthorized data access to online harassment and financial fraud, presents significant challenges to the traditional legal framework. For individuals who fall victim to these digital transgressions, the path to justice is often obscured by technical complexities and procedural hurdles. The provision of legal aid for cybercrime victims in Bangladesh is therefore a critical component of the national justice system, designed to ensure that the protections of the law are accessible to all, regardless of their technical proficiency or financial standing. This article examines the statutory foundations, institutional mechanisms, and procedural requirements that govern the delivery of legal assistance to those affected by cybercrime, specifically under the framework of the Cyber Security Act 2026.

The Evolution of Cyber Law in Bangladesh

The legal response to cybercrime in Bangladesh has undergone a significant transformation, reflecting the dynamic nature of digital threats and the evolving political landscape. The journey began with the Information and Communication Technology (ICT) Act of 2006, which was initially promulgated to facilitate the growth of the ICT sector and provide a legal basis for electronic transactions. However, as the digital landscape expanded and the nature of cyber threats became more sophisticated, the limitations of the ICT Act—particularly its controversial Section 57—became a focal point of legal debate. This led to the enactment of the Digital Security Act (DSA) in 2018, which aimed to provide a more comprehensive framework for national digital security. The DSA, however, faced significant criticism from civil society and international organizations for its perceived impact on freedom of expression. In response to these concerns and the changing technological environment, the government replaced the DSA with the Cyber Security Act (CSA) of 2023, which introduced more nuanced definitions of offenses and revised penalty structures to better align with international human rights standards.

The transition between these legislative instruments reflects a broader global trend where nations are struggling to balance the need for security with the protection of fundamental rights in the digital age. In Bangladesh, this process was accelerated by the political developments and the mass uprising in 2024, which demanded greater transparency and accountability in the application of digital security laws. The interim government responded by issuing a 2025 Ordinance that repealed some of the most restrictive provisions of the 2023 Act and established a commission to draft a new, rights-oriented cyber security law. This extensive consultative process culminated in the passage of the Cyber Security Act 2026 by the newly elected parliament. The 2026 Act is not merely a replacement but a foundational shift in how the state perceives digital governance, moving away from a purely security-centric approach to one that emphasizes the protection of individual digital rights and the integrity of the national digital infrastructure [1].

The Cyber Security Act 2026: A New Legal Paradigm

The Cyber Security Act 2026 introduces several critical provisions designed to enhance the protection of citizens in the digital realm. One of the most significant aspects of the 2026 Act is its specific focus on emerging technologies. The Act includes stricter penalties for the creation and dissemination of AI-generated disinformation and deepfakes, recognizing the potential of these technologies to cause widespread social and personal harm [1]. Penalties for such offenses can reach up to 10 years of imprisonment, reflecting the severity with which the state views the manipulation of digital content to deceive or harass individuals.

Furthermore, the Act clarifies the definitions of various cyber offenses, providing much-needed legal certainty for both investigators and the judiciary. For instance, the Act provides a precise definition of "Critical Information Infrastructure" (CII) and establishes specific protocols for its protection, with heavy penalties for any unauthorized access or interference that could jeopardize national security or public safety. It also addresses the complexities of digital forgery, distinguishing between simple data manipulation and the creation of fraudulent electronic records for financial gain. The inclusion of cyber-terrorism as a distinct offense reflects the growing concern over the use of digital platforms to incite violence or disrupt essential services. The Act also introduces provisions for the protection of personal data, setting the stage for a more comprehensive data privacy framework in the future.

One of the most innovative features of the Cyber Security Act 2026 is its procedural flexibility. It recognizes the cross-border nature of cybercrime and includes provisions for international cooperation in the investigation and prosecution of offenses. This allows Bangladeshi authorities to work more effectively with foreign law enforcement agencies and digital service providers to track perpetrators who may be operating outside the country's physical borders. For victims, this means a higher likelihood of redress in cases of international phishing scams or cross-border harassment. The Act also mandates the creation of a National Cyber Security Center, which serves as a central hub for incident response, threat intelligence, and public awareness, ensuring that the legal framework is supported by a robust technical infrastructure.

Institutional Framework: Operational Cyber Tribunals

To operationalize the statutory framework, the Government of Bangladesh has established specialized institutional mechanisms dedicated to the investigation and adjudication of cybercrimes. A landmark development in this regard is the establishment of operational Cyber Tribunals in all eight administrative divisions of the country [2]. These divisions include Dhaka, Chattogram, Rajshahi, Khulna, Barishal, Sylhet, Rangpur, and Mymensingh. The presence of these specialized courts at the divisional level ensures that victims across the country have localized access to judicial officers who possess specific training in cyber law and digital evidence.

The role of these tribunals is to expedite the legal process, addressing the inherent delays often associated with the traditional court system. Digital evidence is notoriously fragile and requires specialized handling; the Cyber Tribunals are equipped to evaluate technical forensics, such as IP logs, metadata, and encrypted communications, with the necessary expertise. The judicial officers presiding over these tribunals undergo rigorous training in digital forensics, electronic evidence laws, and the technical nuances of the Cyber Security Act 2026. This ensures that the technical complexities of a case do not lead to miscarriages of justice or unnecessary delays. The divisional structure also allows for a more efficient allocation of resources, as each tribunal can focus on the specific digital crime trends prevalent in its region.

In addition to the judiciary, the Bangladesh Police has expanded its dedicated cybercrime units, such as the Cyber Police Centre (CPC) and the Counter Terrorism and Transnational Crime (CTTC) unit's cyber division. These units are equipped with state-of-the-art forensic laboratories and are staffed by personnel trained in advanced digital investigation techniques. They work in close coordination with the Bangladesh Telecommunication Regulatory Commission (BTRC) to monitor digital traffic, block malicious content, and identify the sources of cyber threats. This coordinated approach is essential for tackling sophisticated crimes like large-scale financial fraud, coordinated disinformation campaigns, and state-sponsored cyber attacks. For the average citizen, these institutional developments mean that there is a clear and accessible pathway to report crimes and seek justice, backed by the full technical and legal authority of the state.

Accessing Justice: The National Legal Aid Services Organization (NLASO)

The provision of state-supported legal assistance is managed by the National Legal Aid Services Organization (NLASO), a statutory body established to ensure that financial constraints do not prevent citizens from accessing justice [3]. For cybercrime victims, NLASO provides a critical pathway to legal representation, especially for those from marginalized or low-income backgrounds. The organization operates through District Legal Aid Committees and has a presence in the Supreme Court, offering services that include legal advice, mediation, and the appointment of panel lawyers to represent eligible individuals in court.

Eligibility for legal aid through NLASO is primarily determined by socio-economic criteria, specifically annual income limits, to ensure that the service reaches those who are most in need. As of the current regulations, individuals are eligible for legal aid in the Supreme Court if their annual income is below 150,000 BDT. For cases in District Courts, the annual income limit is set at 100,000 BDT. In addition to these income-based criteria, NLASO also prioritizes certain vulnerable groups, such as women, children, and persons with disabilities, who may face additional barriers to accessing the legal system. The organization also provides assistance to victims of human trafficking and those affected by domestic violence, recognizing the intersection between these issues and cyber-enabled crimes like online exploitation.

The application process for legal aid is designed to be straightforward, but it requires the submission of specific documentation to verify eligibility. Applicants must provide a certificate of income, typically issued by a local government official, along with the details of their case and any existing police reports. Once an application is approved, NLASO assigns a lawyer from its panel of experienced practitioners who will represent the victim throughout the legal proceedings, from the initial filing of the case to the final judgment. The state covers all legal fees, including the cost of filing documents and the lawyer's professional fees, ensuring that the victim does not bear any financial burden. This comprehensive support system is a testament to the government's commitment to the principle of "justice for all," ensuring that the digital divide does not translate into a justice divide.

Procedural Requirements: Reporting and Evidence

The success of any legal action in the realm of cybercrime is heavily dependent on the quality and integrity of the evidence presented. For victims seeking legal aid, the burden of documentation is a critical procedural requirement. The mandatory first step in any cybercrime case is the formal reporting of the offense to the police [4]. This is typically done by filing a General Diary (GD) or a First Information Report (FIR) at the nearest police station or directly with a specialized cybercrime unit. The GD or FIR serves as the official record of the incident and is an indispensable document for the legal aid application process.

Effective evidence preservation involves more than just taking screenshots. Victims are advised to retain original electronic files and preserve metadata, which includes information such as the time of the offense, the IP address of the perpetrator, and the specific device used. Metadata is often the "smoking gun" in cybercrime cases, providing the technical links necessary to identify a suspect. For example, the header information in an email can reveal the path the message took across the internet, while the EXIF data in an image can show the location and time it was captured. Victims should avoid altering or moving these files, as any change to the file properties can compromise their evidentiary value.

Screenshots should be comprehensive, showing the full URL, date, time, and the identity of the sender if possible. It is often helpful to use specialized screen capture tools that can record the entire webpage or thread, rather than just a single frame. In cases of financial fraud, bank statements, transaction logs, and any communication with the financial institution are essential. Victims should also keep a detailed log of all related events, including the dates and times of any subsequent incidents or attempts at contact by the perpetrator. Maintaining a clear chain of custody for all digital evidence is crucial; this means documenting who had access to the evidence and when. Any manipulation or loss of data can lead to the evidence being deemed inadmissible in court, potentially collapsing an otherwise strong case. The precision with which a victim documents the offense directly correlates with the viability of their legal claim and the effectiveness of the legal representation provided through state aid.

Step-by-Step Guide to Legal Aid Application

StepActionDescription
1Immediate ReportingFile a GD or FIR at the nearest police station or cybercrime unit [4].
2Evidence CollectionGather screenshots, metadata, and financial records related to the crime.
3Initial ConsultationSeek a preliminary consultation with a legal professional to understand your rights.
4NLASO ApplicationSubmit a formal application to NLASO with proof of income and police reports [3].
5Case AssignmentIf eligible, a panel lawyer will be assigned to represent you in the Cyber Tribunal.

Regular follow-up with the assigned legal representative and the NLASO office is essential to monitor the progress of the case. The procedural path is designed to be accessible, but it requires active participation from the victim to ensure that all necessary information is provided to the authorities and the legal team.

Practical Challenges and Mitigation Strategies

Victims of cybercrime often face unique challenges that can complicate their pursuit of justice. One of the primary issues is the ephemeral nature of digital evidence. Data can be deleted or altered in seconds, and service providers may only retain logs for a limited period. To mitigate this risk, victims must act with extreme timeliness, reporting the crime and preserving evidence as soon as it is discovered. Any delay can significantly diminish the chances of identifying the perpetrator or proving the offense in court.

Another challenge is the technical complexity of the legal proceedings. Many victims may not fully understand the technical aspects of their case or the specific requirements of the Cyber Security Act 2026. Engaging with legal professionals who have a background in digital jurisprudence is therefore highly recommended. While NLASO provides representation, seeking an initial private consultation can help victims better prepare their case and understand the potential outcomes. Furthermore, victims should be aware of the psychological toll of cybercrime, particularly in cases of online harassment or defamation. The legal system is increasingly recognizing these impacts, and specialized support may be available through various non-governmental organizations in conjunction with legal proceedings.

Conclusion

The provision of legal aid for cybercrime victims in Bangladesh is a fundamental pillar of the digital justice system. As the nation continues its journey towards a more connected future, the importance of accessible and effective legal recourse for digital offenses cannot be overstated. By understanding the statutory framework of the Cyber Security Act 2026, adhering to procedural requirements, and leveraging the support of the National Legal Aid Services Organization (NLASO), victims can effectively navigate the path to justice. The operational status of Cyber Tribunals in all eight divisions signals a commitment to protecting the rights of individuals in the digital realm. With the support of the state and the guidance of legal professionals, victims of cybercrime are empowered to seek redress and hold perpetrators accountable, ensuring that the digital space remains a safe and equitable environment for all.


Disclaimer: The information provided in this article is for general informational purposes only and does not constitute individualised legal advice. The legal framework and procedures related to cybercrime are subject to change, and victims are encouraged to consult with qualified legal professionals regarding their specific circumstances.

Book a Consultation: For professional guidance on navigating cybercrime laws and securing legal aid in Bangladesh, you may book a consultation with Tahmidur Rahman Remura Wahid (TRW).

References

[1] Prothom Alo, "Cyber Security Act 2026: Stricter penalties for AI-generated disinformation," 2026. https://en.prothomalo.com/bangladesh/wbq9kji6z7

[2] The Daily Star, "Cyber Tribunals set up in all 8 divisions," 2026. https://www.thedailystar.net/law-our-rights/law-news/news/cyber-tribunals-set-govt-8-divisions-2073209

[3] National Legal Aid Services Organization (NLASO), "Official Portal of NLASO," 2026. https://www.nlaso.gov.bd/

[4] Adv. Mintu Mondal, "How to file a cyber crime case in Bangladesh," 2026. https://advmintumondal.com/how-to-file-cyber-crime-case-bangladesh/

Let’s discuss
the detail.

For a focused conversation with TRW, book a consultation or contact the firm directly.Book consultation →info@trw.org