The number of cybercrimes in Uzbekistan has increased 13-fold.
The Central Bank of Uzbekistan is transitioning to risk-based cybersecurity oversight amid rising cybercrime and losses exceeding 3.8 trillion soums.

The number of cybercrimes in Uzbekistan has increased 13-fold over the past five years, reaching over 62,000 cases compared to 4,800. In response, the country's Central Bank is preparing to implement risk-based oversight of bank cybersecurity. These data were presented at the session "Trust at the Speed of AI: Cyber Resilience & Fraud Defense for Payment Rails" at the Silk Road Finance and Technology Forum, which took place in Tashkent on August 25.
The session's moderator, Artyom Saidov, head of cybersecurity at KPMG Uzbekistan, noted that the share of digital payment users in the country has grown from 39% in 2021 to 72% in 2025, and raised the question of whether cybersecurity can keep up with this pace.
According to information presented at the session, citing the Ministry of Internal Affairs, the total damage from cybercrime over the five-year period exceeded 3.8 trillion soums, with more than half of this amount occurring in 2025.
Mirzabek Bobojanov, head of the CERT-CBU Cybersecurity Center at the Central Bank of Uzbekistan, reported that since the beginning of 2026, banks and payment institutions have blocked approximately 18 million suspicious transactions. This was made possible by requiring banks to have their own anti-fraud systems based on artificial intelligence.
He cited an example of fraud using social engineering: attackers arranged a video call to a bank client, posing as a Central Bank employee, using deepfake technology to replace their face. The client, after verifying their identity through the Central Bank's official website and seeing a matching photo, transferred a large sum to the fraudsters. According to Bobojanov, anti-fraud systems protect clients but are not 100% guaranteed due to the population's level of financial literacy.
Zokhir Mirzayev, Director of Information Security at Asakabank, emphasized that the sharp increase in the number of new payment system users means that many are encountering digital financial services for the first time and lack basic knowledge of data protection. He also noted that a significant portion of the data protection burden falls disproportionately on commercial banks, as most small and medium-sized businesses (SMBs)—their clients—lack their own information security departments.
Umid Khakimov, CEO of Ipak Yuli Bank, reported that the bank serves over 5 million clients, has issued over 5 million cards (including Visa and local cards), and maintains approximately 900 ATMs and over 20,000 POS terminals. He stated that the use of artificial intelligence allows the bank to significantly reduce costs in the face of increasing competition and customer price sensitivity, but that implementing such solutions without a prior risk assessment is unacceptable. He noted that the bank first builds a security infrastructure and then moves on to efficiency and cost optimization.
Bobodzhanov announced that the regulator is shifting from a compliance-oriented approach to risk-based supervision. As part of the digitalization project, a banking sector cybersecurity strategy and a risk assessment methodology based on the maturity level of organizations have been developed. Next year, the launch of a new regulatory system with four levels of requirements is planned, depending on the scale and digital maturity of banks and payment organizations: systemically important banks have stricter requirements than organizations with smaller client volumes.
He also announced the launch of a platform for exchanging information on cyber incidents between commercial banks, which went live approximately two months before the forum. Bobodzhanov noted that initially, banks were reluctant to share information, but this is gradually changing.
Nikolay Belshteyn, Senior Director of Consulting and Analytics at Visa CEMEA, stated that this dynamic is not unique to Central Asia but is global: attackers are attacking not so much corporate infrastructure as trust between people. Creating a phishing email or deepfake today requires minutes and minimal investment. He noted that many banks and regulators continue to build defenses based on yesterday's rather than today's threats. To respond more quickly, banks need management support through investments in cybersecurity and artificial intelligence. He cited the example of Visa, which processes billions of payments and is forced to make decisions on the legitimacy of transactions in milliseconds.
Responding to the question of what single measure could support trust in the payment system in the coming year, all panelists independently cited cooperation and real-time information sharing on incidents. Belshtein noted that, based on his observations in other regions, an attack on one bank often foreshadows an attack on another within a few hours or days, so timely data sharing allows market participants to prepare in advance for a similar threat.

