
TIMOR-LESTE Scorecard
Vietnam is a big, very online, and strategically important state in SEA’s cyber threat landscape. Its Cybersecurity Law, NCSC, and upcoming Data Law provide a robust if highly state-centric framework for controlling data and regulating cyberspace. At the same time, the country faces relentless cyber threats: hundreds of thousands of incidents per year, serious ransomware activity, and headline-grabbing breaches including Vietnam Social Security and the National Credit Information Center.
Geopolitically, Vietnam’s role as a South China Sea frontline state and manufacturing powerhouse makes it a prime target for espionage and infrastructure-focused operations, while its citizens are heavily exposed to regional scam networks and trafficking-for-cybercrime.
​
Overall Position: Small, lower-maturity digital state with modest exposure but now flagged as an emerging scam center hotspot, sitting right at the “early Cambodia/Myanmar” stage of the crisis.
​
Cyber Maturity 4/10 Draft laws and reforms exist, but institutions and capability are still early-stage.
​​
Threat Activity 6/10 Historically low–moderate, now spiking as scam centers and cyber fraud appear.
​​​
Digital Exposure 5/10 Roughly 40% internet penetration, high mobile SIM penetration, growing slowly.
​​​
Law Enforcement Capability 4/10 Some active investigations and international support, but capacity is thin.
​​​​
Geopolitical Risk 5/10 state, but now in UNODC spotlight and on the path to ASEAN membership.
​​​
Scam/Fraud/Trafficking 7/10 Clear evidence of scam center activity and trafficking-style setups in Oecusse.
CYBER MATURITY ASSESSMENT
Timor-Leste has a draft cybercrime law, an unofficial English translation circulating, and is working with the Council of Europe to align with the Budapest Convention on cybercrime.
It also passed Decree-Law 12/2024 for e-commerce and e-signatures, but civil society warns that planned cyber laws risk over-broad powers and weak privacy protections.
​
-
Draft Cybercrime Bill sets out offences and procedures for digital evidence and international cooperation.
-
Budapest Convention accession process underway with GLACY+ support.
-
Decree-Law 12/2024 creates a general regime for e-commerce & e-signatures, including penalties for spam and abuse.
-
Civil society (CIVICUS, Asia Centre, etc.) raise concerns: draft cyber law may be used to curb dissent, “misuse of social media,” and criticism of leaders.
4/10
DIGITAL EXPOSURE
Timor-Leste’s digital exposure is moderate: internet penetration is around 40.4%, with about 575k users and high mobile SIM penetration (~124% vs population) by late 2025.
​
-
575k internet users at end of 2025, 40.4% penetration; around 687k social media identities (around 48%).
-
Earlier estimates (DataReportal / Lowy) suggested ~44% connectivity in 2024, but newer surveys hint real usage might be slightly higher than reported.
-
around 1.75M mobile connections in early 2025 (124% of population), showing mobile-first connectivity.
5/10
GEOPOLITICAL & ECONOMIC DRIVERS
Geopolitically, Timor-Leste is a small state, but it’s now a UNODC-flagged scam hotspot near Australia and on track to join ASEAN in 2025, which will deepen digital and economic integration and scrutiny.
​
-
UNODC warns that scam centres moving out of Mekong/Philippines are now appearing in Timor-Leste, with patterns similar to early Mekong cases.
-
Oecusse Digital Centre free-trade zone (opened Dec 2024) is already implicated in scam operations, making it a sensitive geo-economic node.
-
Timor-Leste is preparing to join ASEAN, which will tie it into regional cyber cooperation, but also the regional cybercrime and scam ecosystem.
-
No South China Sea claims or civil war, so kinetic/geopolitical risk is lower than PH/VN/MM, but crime-driven strategic risk is rising.
5/10
CURRENT THREAT ACTIVITY
Historically, Timor-Leste was a low-visibility cyber target, but that’s changing as scam centres and linked fraud operations are detected and as local cyber fraud cases begin to surface.
​
-
UNODC reports triad-linked scam operations setting up in Timor-Leste, particularly in the Oecusse Special Administrative Region.
-
Police raid in August at a hotel in Oecusse-Ambeno detained 30+ foreign nationals (Indonesia, Malaysia, China) for illegal employment linked to scam operations.
-
Public Prosecutor is actively investigating a recent cyber fraud incident in Dili, highlighting emerging local cybercrime.
6/10
LAW ENFORCEMENT & CYBERCRIME CONTROL
Law enforcement is starting to engage with cybercrime, investigating fraud cases and working with international partners, but operational capacity, tooling, and experience are still limited.
​
-
Public Prosecutor’s Office actively pursuing cyber fraud cases in Dili.
-
Cooperation with Council of Europe GLACY+ aims to upgrade investigative and evidentiary capacity for cybercrime.
-
Draft law includes provisions for expeditious preservation and disclosure of computer data for international cooperation.
-
No evidence yet of large, specialized cyber units with the scale seen in PH/TH/MY; system is small and still learning.
4/10
SCAM / HUMAN TRAFFICKING / FRAUD
Timor-Leste is now clearly part of the fraud-factory story: UNODC says triad-linked scam centres have appeared in Oecusse, mirroring early stages of the Cambodia/Myanmar crisis, though at smaller scale (for now).
​
-
UNODC alert: East Timor has become the “latest hotspot” for scam-centre operations, with setups similar to those in Mekong countries and the Philippines.
-
August raid in Oecusse: >30 foreign nationals detained in a hotel, suspected of involvement in scam operations under the Oecusse Digital Centre regime.
-
Global reporting frames this as the expansion wave of the scam industry as operations are disrupted in Cambodia/Myanmar/Laos and move to “vulnerable” states like Timor-Leste.
7/10