Nepal News | Nepal’s First Online News Portal | #ransomware | #cybercrime


KATHMANDU: On September 20, a ransomware attack on Data Hub Pvt Ltd froze trading infrastructure for 72 of Nepal’s 90 brokerage firms, forcing the Nepal Stock Exchange (NEPSE) to suspend a full day of trading on September 21 to preserve market fairness and system security.

Although NEPSE’s core trading engine remained unbreached and trading resumed Tuesday with a modest index rebound, the incident exposed severe structural risks tied to outsourcing critical capital market infrastructure to a single vendor.

Furthermore, Nepal Rastra Bank figures from mid-August show market capitalization and index values were already cooling compared to the previous year, proving that systemic vulnerabilities and slowing growth run deeper than a single cyber incident.

This explainer will analyze recurring structural risks, including monopoly dynamics, infrastructure consolidation and regulatory challenges facing NEPSE.

What actually happened on Sunday and Monday?

Data Hub Pvt Ltd, the company hosting the Trading Management System for the large majority of Nepal’s active brokers, detected a ransomware intrusion on its systems at around 5:30 in the morning on Sunday, 20 September. It notified YCO Pvt Ltd, which manages the shared trading software used across the industry, describing the incident in writing as ransomware rather than an ordinary technical fault. By Monday morning the affected systems were still down, and YCO told the Stock Brokers’ Association that the intrusion had spread across several linked systems, including the depository and clearing side, payment gateways, and other connected services.

Rather than risk bringing anything back online while the scope of the breach was still unclear, the affected infrastructure was isolated as a precaution. With 72 of its member brokers effectively shut out of their own trading terminals, the Stock Brokers’ Association asked the Nepal Stock Exchange to suspend the entire day’s session, and the exchange agreed under its standard rules.

How badly was NEPSE itself affected, as opposed to individual brokers?

It helps to separate two things. NEPSE’s own core trading engine, the Online Trading System, is separate infrastructure that the exchange runs directly, and a NEPSE spokesperson said protective measures had been applied to that system specifically. The ransomware did not breach NEPSE’s own servers outright; it hit the data centre brokers use to connect into the exchange.

That distinction mattered less in practice than it sounds, because the data centre shares a network with NEPSE’s own trading infrastructure, and the exchange itself said the incident carried cybersecurity, operational, and data theft risk to its systems if trading continued while the breach was still live elsewhere on the network. That risk, more than a confirmed direct hit, is what justified halting the whole market rather than only the 72 affected brokers.

NEPSE also cited fairness: even though 18 of roughly 90 active brokers were unaffected, letting them trade while the majority sat locked out would have created an uneven playing field for investors using the affected firms.

Why does one company end up hosting servers for 72 brokers in the first place?

This traces back to how Nepal’s brokerage industry built its technology. Instead of dozens of individual firms each running a secure, resilient data centre of their own, most outsourced that job to a handful of specialised vendors, of which Data Hub is among the largest, hosting infrastructure for the clear majority of active brokers under one roof.

The logic is straightforward: a properly redundant data centre is expensive, and for smaller brokerage houses building one independently would not pencil out. Consolidating with a specialist vendor lets brokers focus on trading rather than infrastructure.

The cost of that convenience showed up starkly this week. When most of a national exchange’s brokers depend on one vendor, a single successful attack on that vendor can freeze the whole market, which is exactly what happened. Brokers have effectively been kept away from managing core infrastructure like data centres and trading systems, which stays concentrated among a small number of business groups instead.

How big is Nepal’s stock market right now, based on the latest official data?

Nepal Rastra Bank’s report on the first month of fiscal year 2026/27, published 18 September and covering data through mid-August 2026, puts total market capitalisation at Rs 4,550 billion, up slightly from Rs 4,463.55 billion in mid-July but still below the Rs 4,660 billion recorded a year earlier in mid-August 2025. The NEPSE index itself stood at 2,643.84 points in mid-August, a small recovery from 2,597.80 in mid-July but roughly 5 percent below the 2,788.37 level of a year ago, and market capitalisation as a share of GDP slipped to 68.9 percent from 75.1 percent over the same twelve months.

Nepal Rastra Bank office in Thapathali. Photo: Shambhu Regmi

The number of listed companies grew to 305 from 302 in mid-July, made up of 133 banks, financial institutions and insurers, 111 hydropower firms, 31 manufacturers, and smaller numbers of hotels, investment firms and trading companies. Banks and insurers still account for the largest slice of market value at 50.9 percent, with hydropower at 18.3 percent, up from 17.5 percent a month earlier.

The paid-up value of the roughly 9.59 billion listed shares stood at Rs 945.54 billion, with Rs 6.90 billion in new securities listed during the month. NEPSE remains majority state owned, with the Government of Nepal holding 58.66 percent, Nepal Rastra Bank 9.5 percent, the Employees Provident Fund 10 percent, and Rastriya Banijya Bank 11.23 percent.

How did trading go when NEPSE reopened on Tuesday?

Better than the mood going into it might have suggested. NEPSE resumed regular trading at 11 a.m. on Tuesday, 22 September, after NEPSE information officer Murahari Parajuli confirmed that Data Hub had resolved the technical issue at its data centre and YCO had signed off on bringing the affected brokers’ systems back online.

The index gained 7.06 points to close at 2,654.28, up from Friday’s close of 2,647.22, the last session before the market shut down. Turnover came in at Rs 7.053 billion, higher than the Rs 6.745 billion recorded in that previous session, with roughly 21.6 million shares of 356 listed securities changing hands. Of the individual stocks, 137 gained ground, 131 declined and 11 were unchanged. Mid Solu Hydropower posted the day’s biggest gain at nearly 15 percent, while Snow Rivers led the losers, down more than 8 percent. Hathway Investment Nepal, Himalayan Distillery and Ghalemdi Hydro saw the heaviest turnover.

As with the shutdown itself, NEPSE kept the whole market moving together on the way back in rather than letting brokers on unaffected systems resume early, preserving the same equal access logic it used to justify the original suspension. Whether the ransomware’s full spread through Data Hub’s wider network has actually been resolved, rather than merely contained enough to trade safely, is something SEBON’s ongoing investigation will need to establish with more certainty than has so far been made public.

Has something like this happened before at NEPSE?

Repeatedly, though not always described as ransomware specifically. Just two months earlier, on 23 July, the NEPSE website and the shared Trading Management System briefly showed the index collapsing by more than a thousand points, close to 37 percent, to 1,717 points, about fifteen minutes after the market had already closed for the day. That was attributed to a technical glitch rather than an attack, but it rattled investors much the same way, since a headline crash of that size spreading on social media can do real damage regardless of the cause.

More broadly, disruptions tied to trading infrastructure at brokers, at Data Hub, or at YCO have become a recurring feature of NEPSE’s operations rather than one-off events. Analysts quoted in coverage of past incidents describe a pattern in which responsibility gets shifted between NEPSE, brokers, the data centre operator and the software vendor each time something breaks, while investors and brokers absorb the disruption regardless.

Following this latest episode, NEPSE’s board reportedly agreed on Monday evening that trading would resume the next day whether or not the underlying Data Hub problem was fully resolved, a call that hints at growing institutional fatigue with treating a full market suspension as the automatic response every time.

What role has the Securities Board of Nepal played in all this?

SEBON has directed NEPSE to investigate the circumstances behind Monday’s suspension and submit a report by September 28, and has separately deployed a five-member inspection team led by a deputy executive director to examine the technical and procedural causes of the shutdown. The regulator wants recommendations on preventing a repeat and on making the market’s infrastructure more secure and transparent, though nothing has been made public yet.

Securities Board of Nepal. File photo

SEBON’s relationship with NEPSE has been an uneasy one well beyond this single incident. In an unrelated 2014 dispute, NEPSE removed brokers’ identifying numbers from its public floorsheet citing privacy concerns, a move investors read as covering for possible cartel behaviour among large investors and brokers, until SEBON intervened and had the numbers restored within weeks. SEBON has also flagged manipulation risks tied to certain order types on the exchange in the past, and at various points has openly criticised NEPSE for treating its position as the country’s only stock exchange as licence to ignore its regulator’s own rules.

That longer history is why this week’s probe carries weight beyond the immediate technical failure, with investors effectively asking SEBON to finally address a structural weakness that has been visible for years.

Beyond outright attacks, how else do critics say Nepal’s stock market gets “held hostage”?

Several recurring complaints have resurfaced together this week. One is NEPSE’s monopoly position as Nepal’s only stock exchange, which critics say removes the competitive pressure that might otherwise force faster fixes to chronic technical weaknesses. A former SEBON chairman once put it bluntly, describing NEPSE as exercising the full power of a monopolist by disregarding rules set by its own regulator.

A second complaint involves manipulation rather than technical failure. SEBON has in the past publicly listed dozens of stocks it considered overpriced or at risk of manipulation by self-styled market experts and influencers, and separately moved to strip an order type known as all-or-none from the trading system after concluding it was being used to push prices around artificially. Retail investors have long complained about limited market depth information, meaning they cannot see enough of the order book to judge whether price moves reflect genuine demand or coordinated activity by a small number of larger players.

Layered on top of both is the infrastructure dependency this week’s attack exposed, with brokers relying on a small number of privately run data centres and one shared software vendor, concentrating both cybersecurity risk and bargaining power over the exchange’s daily operations in very few hands.

Have other stock exchanges around the world suffered similar shutdowns?

Yes, fairly regularly. The comparison cited most often in Nepali commentary this week is the Tokyo Stock Exchange, which halted trading for an entire day on 1 October 2020 after a hardware failure affected more than 3,500 listed companies, one of the starkest examples of how a single technical fault can freeze an entire national market regardless of how developed its financial system is.

Tokyo Stock Exchange

Other cases span more than a decade. India’s Bombay Stock Exchange halted trading for three hours in July 2014 due to a network outage, the National Stock Exchange of India suffered a three-hour halt in July 2017 when price quotations stopped updating, and again for nearly four hours in February 2021 after a telecom link failure took down its risk management system, an incident serious enough that regulators later took enforcement action against three senior exchange executives.

The New York Stock Exchange briefly suspended trading in stocks including Amazon and Alphabet in April 2018 after a technical glitch, and Germany’s Deutsche Boerse suffered a three-hour outage in 2020 tied to third-party software. None of these involved ransomware specifically, most were hardware or software failures rather than malicious attacks, but together they undercut any claim that this kind of vulnerability is unique to Nepal’s young capital market, even if the scale of disruption here, given how concentrated brokerage infrastructure is, may be proportionally larger than in bigger, more diversified markets.

What does a ransomware attack actually do, in plain terms, and why is it different from a normal glitch?

Ransomware is malicious software that infiltrates a system and encrypts the data on it, making files and systems unusable until either a ransom is paid or the victim restores everything from clean backups without paying. That is meaningfully different from an ordinary glitch, such as a server crashing under load or software producing bad data by accident, because a glitch is usually unintentional and fixable once engineers find the fault, while ransomware involves a hostile actor deliberately keeping systems locked until payment.

In this case, Data Hub said it isolated affected systems specifically because the ransomware had potentially spread to other connected networks, a standard containment step that also explains why systems could not simply be switched back on the moment the problem surfaced, since doing so risked spreading the infection further. Data Hub reported that its backups from up to ninety minutes before detection remained intact, a relatively good outcome by ransomware standards given that corrupting backup copies to increase pressure on the victim is a common tactic in these attacks.

Whether Data Hub or YCO paid any ransom, or resolved the incident purely through backups and rebuilding, has not been publicly confirmed.

How did investors and market participants react to the shutdown?

With frustration, and for some, a familiar sense of resignation. Repeated disruptions, whether from server outages or outright attacks, effectively lock up people’s money each time they happen, since shares cannot be bought or sold while the market is shut regardless of what an investor might urgently need to do with that cash. Market analysts pushed the criticism toward accountability.

Investors and analysts argued that authorities need to treat these disruptions with real seriousness and build genuine contingency plans for when critical infrastructure fails, rather than reacting case by case as each incident occurs. Commentators reflect on the recurring Tuesday’s numbers showed a quick rebound, but central bank data confirms the stock market was already losing momentum well before hackers hit the system this pattern is itself one reason Nepal’s capital market has struggled to mature meaningfully even after more than three and a half decades of operation.

Brokers, for their part, largely framed themselves as victims of a system design they do not control. They have reflected a broader industry argument that responsibility for the shutdown lies with how the market’s technology has been structured over the years, not with brokers’ own conduct.

What longer term changes, if any, are being discussed as a result of this incident?

At this stage, the response has mostly been investigation and public criticism rather than confirmed policy change. SEBON’s probe, due to report by 28 September, is the most concrete institutional step so far. Commentators writing since the attack have consistently called for moving away from reliance on a single data centre operator and a single shared trading software vendor for the bulk of the country’s brokerage infrastructure, arguing that some form of mandated redundancy, meaning brokers or vendors would need backup systems hosted separately from their primary setup, is the only real way to prevent a repeat.

There have also been renewed calls, echoing older complaints about NEPSE’s monopoly status, for stronger regulatory teeth to force faster modernisation of the exchange’s technology and clearer accountability when third-party vendors like Data Hub suffer failures that ripple across the whole market.

Whether any of this becomes enforceable policy, rather than another round of statements that fades once the immediate anger passes, will depend heavily on what SEBON’s investigation concludes and whether it is followed through with actual rules. For now, the most tangible outcome is reputational.

Coming so soon after July’s index glitch, a long history of similar disruptions, and a mid-August economic snapshot already showing a market cooling from a year ago, this attack has added fresh weight to arguments that Nepal’s capital market infrastructure needs structural reform rather than incident-by-incident firefighting.



Click Here For The Original Source.

——————————————————–

..........

.

.