The Nepal Stock Exchange (NEPSE) halted all regular securities trading on Monday after a severe cyber security breach disrupted operations across 72 brokerage firms.
The disruption stems from a targeted ransomware attack on DataHub Pvt Ltd, a primary data center hosting critical infrastructure for a vast majority of Nepal’s stockbrokers. The incident, which began early Sunday morning at around 4:00 AM, compromised several core platforms, including the Trade Management System (TMS), CDSC-related processing systems, and linked payment gateways.
YCO Pvt Ltd, the technology provider managing system integration for the brokers, alerted the Stock Brokers’ Association of Nepal that the ransomware had affected interconnected networks. To mitigate risks to data integrity and prevent potential intrusion into NEPSE’s core engine, system administrators isolated the compromised servers.
Following an urgent request from the Stock Brokers’ Association, NEPSE officially suspended trading under Rule 21(1) of the Securities Listing and Trading Regulations, 2075. Exchange officials stated that operating the market under vulnerable connectivity conditions posed significant systemic risks to the entire capital market.
Forensic assessments and system recovery efforts by cybersecurity teams are currently underway, though authorities have not yet disclosed the identity of the ransomware vector or whether ransom demands were made. The incident has sparked broader concern among investors and market analysts regarding single-point-of-failure vulnerabilities in Nepal’s financial technology infrastructure.