The London College Top Banner Ad

Social Engineering: Nepal’s Invisible Digital Threat

Suspicious call and warning signals

Social Engineering: The Biggest Invisible Threat of the Digital Age and Practical Ways to Stay Safe (A Detailed Study)

When most Nepali readers hear the term “cybersecurity,” they imagine complex coding, hackers working in dark rooms, or software that breaks firewalls. But many real-world incidents have taught a bitter truth: even the world’s strongest “server” or “encryption” cannot protect you unless your mind is not “hacked.”

The art of hacking the human mind is known in technical terms as social engineering.

Social engineering is not a computer virus. It is a psychological skill. It is a method of stealing confidential information or gaining unauthorized access by exploiting human nature—such as fear, greed, trust, curiosity, or the desire to help.

According to one statistic, 98% of cyberattacks begin with a small human mistake. That is why a famous saying in cybersecurity is: “The weakest link in your security is not software, it is people (You are the weakest link).”

Looking at recent trends in Nepal, Nepal Police Cyber Bureau data shows that cybercrime complaints more than doubled in the last fiscal year (2080/81). A large share of these involve WhatsApp lottery scams, money demands after hacking Facebook accounts, or fake bank staff asking for OTP codes. These are all examples of social engineering.

What Is Social Engineering and How Does It Work? (The Mechanism)

In simple terms, if a hacker works for months trying to discover your password by attacking your computer, that is “technical hacking.” But if that same hacker calls you and says, “Sir, I am calling from the bank. Please give me your password to update your account,” and gets the password directly from your mouth, that is “social engineering.”

This attack usually follows four psychological stages (attack cycle):

  1. Investigation: The attacker collects information about the victim (from Facebook, LinkedIn, or public databases).

  2. Hook: The attacker tries to build trust, such as “I’m calling from Nepal Telecom” or “Your parcel has arrived.”

  3. Play: The victim is pushed through pressure or temptation, such as “If you don’t share details now, your account will be closed” (fear) or “You’ve won a 25 lakh lottery” (greed).

  4. Exit: After the goal is achieved, the attacker erases traces and disappears.

Types of Social Engineering and Real Examples Seen in Nepal

To understand social engineering properly, it is necessary to analyze its different types and the real-world scenarios happening in Nepal.

Phishing (Email Trap)

This is the oldest and most common method. In this approach, fake emails are sent pretending to be from trusted institutions (such as banks, Google, or PayPal).

Nepali context: Recently, fake emails have been found using the name of “Nepal Police Central Investigation Bureau (CIB).” The email claims: “You have been found visiting illegal websites, and a case is being filed against you. If you do not pay the fine immediately, you will be sent to jail.”

This is a serious form of social engineering that plays directly on fear. Many people fall into it because they do not know the basic fact that government agencies do not threaten people like this through email.

Vishing (Voice Phishing)

Fraud committed through phone calls is called vishing. With the use of deepfake technology, this has become even more dangerous.

Nepali context: A widespread scam involves WhatsApp calls from numbers like +92 or +1 claiming, “You won a 25 lakh lottery—send 50,000 as tax through eSewa.” This scam is based on greed.

Another style: “Sir, your eSewa ID is being blocked. Please tell me the 6-digit code (OTP) you received.” People share the code in haste or under urgency, and the account gets emptied.

Smishing (SMS Phishing)

This is phishing done through SMS.

Nepali context: People receive messages such as “NTC_OFFER: You received a bonus, click this link to claim it” or “Your banking transaction was declined, click here to fix it.” The moment you click the link, malware may download to your phone, or a fake login page may open.

Baiting (Temptation as Bait)

Just like placing bait on a fishing hook, this method uses the temptation of something “free” or “attractive.”

Example: An infected pen drive is left in an office parking area. An employee connects it to the office computer out of curiosity (“Whose is this?”), and the virus spreads.

Digital baiting: “Click here to win a free iPhone 15” or “Click here to download Pathaan movie.”

Pretexting (Fake Story and Acting)

In this method, the attacker creates an imaginary situation or role.

Nepali context (rental scam): Taking advantage of how difficult it can be to find a room in Kathmandu, scammers post “Urgent flat available” with attractive room photos on Facebook. When contacted, they say, “I’m not at home, others are trying to book it too. Send Rs. 5,000 advance and I’ll reserve it for you.”

After the money is sent, the “landlord’s” phone is switched off. Here, necessity is exploited.

Quid Pro Quo (Exchange)

This method follows the idea: “To get something, you must give something.” The attacker offers “technical support” or “help.”

Example: A caller says, “We are calling from Microsoft. A virus has been detected on your computer. I will fix it—please download AnyDesk.” They then gain full access to your computer and empty your bank account.

Honey Trap (Romance Scam)

In Nepal, there is also a growing trend of romance scams on Facebook or Instagram, where scammers pretend to be foreigners (often as doctors or pilots). Later, they say, “I’m coming to Nepal, but customs stopped me at the airport. I need 5 lakhs to release the dollars.”

Why Do People Fall for It? (The Psychology of Victimhood)

Many people believe, “I’m smart, I won’t fall for it.” But social engineers understand psychology very well. They attack six major human weaknesses (based on Cialdini’s Principles of Persuasion):

  1. Fear: When someone hears “police case” or “bank account closure,” logical thinking shuts down.

  2. Urgency: “If you don’t share the code within 5 minutes, the money won’t return.” It removes the time needed to think.

  3. Greed: “25 lakhs without doing anything.” Humans naturally desire easy money.

  4. Curiosity: A link sent on Messenger saying, “Who is that person in this video who looks like you?” makes people click out of curiosity.

  5. Authority: When a “boss” or “manager” speaks, junior staff may panic and share confidential data.

  6. Helpfulness: “I had an accident, please send 5,000.” Nepalis are often helpful, and that is exploited.

Deepfake and AI: The Future of Social Engineering

Artificial Intelligence (AI) has taken this threat to a new level.

Voice cloning: AI can imitate your father’s or son’s voice from just a 3-second audio clip. Imagine receiving a call where your son is crying and says, “Dad, I lost my wallet, I’m stuck—please send 5,000 to my friend’s number.” The voice sounds exactly like your son. Would you suspect it?

In Nepal, groups have started becoming active in threatening people using “digital arrest” tactics through this technology.

Practical Prevention and Safety Measures (The Human Firewall)

We must understand that no antivirus can fully stop social engineering. You must become your own human firewall. Based on what has proven effective through two decades of experience, here are practical steps:

Stop, Look, Think

If any email, SMS, or phone call tries to force you into a quick decision, stop for 5 seconds. Ask yourself:

  • “Does a bank ever call and ask for a password?”

  • “Why would a stranger give me money?”

Follow a “Zero Trust” Policy

Caller ID spoofing: Even if your screen shows “Nepal Police” or “XYZ Bank,” do not trust it. Technically, it is possible to display someone else’s name or number.

Call the institution’s official number yourself and confirm.

Do not answer WhatsApp/Viber calls from unknown numbers, or cut the call if it seems suspicious.

Use Multi-Factor Authentication (MFA/2FA)

Passwords alone are never enough. Turn on 2FA for Facebook, Google, Instagram, and banking apps. Even if someone knows your password, they cannot log in without the code sent to your phone or an authentication app (Google Authenticator).

But be careful: never share your OTP or code with anyone.

Inspect Links (URL Inspection)

There is a difference between nepalbank.com and nepaibank.com. Scammers create fake sites using typosquatting—like replacing “l” with “i” or using similar spellings.

Before clicking any link, hover the mouse and check the real address. Also, do not assume that a site with https:// (lock icon) is always safe. Scammers can use SSL locks too.

Stop Over-Sharing

Information you post on social media becomes a weapon for scammers.

If you post “Birthday trip to Pokhara,” a scammer may call your office and claim, “I’m hotel staff calling from Pokhara, their credit card isn’t working…” and create a fake emergency.

Do not publicly share your date of birth, address, school name, or family details. These details are often used to crack “security questions.”

Institutional Security (For Organizations)

If you run an organization:

  • Make security awareness training mandatory for staff.

  • Test staff with simulated phishing emails.

  • Apply a “verification call” policy for money transfers (confirm once by phone before acting).

What to Do If an Incident Happens? (Incident Response in Nepal)

If you or your family becomes a victim, do not panic. The immediate steps are:

  1. Cut Contact: Stop talking to the scammer.

  2. Block Accounts: Call the bank or digital wallet (eSewa/Khalti/Imepay) immediately and ask them to freeze the account.

  3. Collect Evidence: Save chat screenshots, phone numbers, transaction IDs, and profile links. Do not delete them.

  4. File a Legal Complaint:

    • Go to the nearest police station, or

    • Contact Nepal Police Cyber Bureau (Bhotahity, Kathmandu)

    • Email for complaints: cyberbureau@nepalpolice.gov.np

    • If urgent, you can call 100

Conclusion: An Expert’s Suggestion

In twenty years of experience, I have seen thousands of such cases. No matter how smart technology becomes, thieves always look for new ways to break locks. But in social engineering, they do not break the lock—they ask you for the key.

My final suggestion is simple: nobody on the internet is selfless. Always view free offers, threats without reason, and excessive friendliness from strangers with suspicion.

Being suspicious is not rude. It is smartness in the digital age.

The safety of you, your family, and your organization is in your hands (and your mind).

(Note: This article is fully based on research and facts. The technologies mentioned here are explained only for educational and awareness purposes. Misuse of these methods for illegal activities is punishable by law.)

Digital Literacy
Comments