As the global digital infrastructure accelerates, we are facing an unprecedented surge in cybercrime. In 2025 alone, Cambodian citizens alone lost an estimated $45 million to online scams, with only about $20 million successfully recovered by authorities. This led the Cambodian government to draft a new law on “Anti-Technology Fraud” which is designed to provide a comprehensive legal framework to prevent, intercept, and suppress cyber-enabled crimes. Despite efforts to combat such crimes, we cannot ignore its prevalence in present-day society. Whether we like it or not, we could someday fall victim to such schemes. Below are some suggested steps that victims can legally take if they encounter such unfortunate events.
In the digital world, evidence is important. Suspects can delete messages, deactivate accounts, or “unsend” documents in seconds. Speed and silence are your best tools. It is best not to alert the perpetrator that you are onto them, as this often leads to the immediate destruction of proof.
What to collect:
Tip: When taking screenshots on a phone, ensure the battery percentage, time, and signal strength are visible. This helps verify the chronological order and authenticity of the captures.
If you have transferred funds or noticed unauthorized activity, minutes matter. Digital assets and cash transfers are often moved through multiple accounts quickly to make them untraceable.
What you should do:
In Cambodia, a “complaint” is the legal trigger for a formal investigation.
Where to Report:
Realistic Expectations: Investigations into cybercrime, especially those involving foreign IP addresses or offshore accounts, are slow. Do not expect an immediate refund; the goal here is to build a legal paper trail that may assist in larger-scale crackdowns.
A civil lawsuit is typically pursued in parallel with, or after, a criminal case. It is most effective when:
If a business suffers a cybercrime (hacking, ransomware, data breach), it must assess both criminal exposure and civil/contractual liability.
1. Review Contractual Obligations
If customer or employee data was compromised due to a cyberattack, the business must review confidentiality clauses, data protection obligations, security warranties, limitation of liability clauses. If the company promised to protect data but failed to implement reasonable cybersecurity measures, it may be considered a breach of contract.
If company directors or employees were involved (for example, insider data theft), they may also face criminal responsibility. In addition, if the company failed to prevent obvious security risks, authorities may investigate negligence depending on circumstances.
2. Implement Stronger Cybersecurity Practices
To reduce cybercrime risks, businesses should install firewalls and intrusion detection systems, use encryption, apply regular security updates, use multi-factor authentication, and perform cybersecurity audits.
Training employees in identifying suspicious emails, protecting passwords, reporting security incidents immediately, can also be an important preventative action. Employee negligence can create corporate liability.
3. Seek Legal Advice Early
Taking swift legal action can also limit liability for companies and prevent further loss for individuals.
At Din & Co. we are here to assist if you require assistance or advice regarding cyber crime issues.
Contact Our Expert Team
Co-Principal