Kathmandu, September 22
On Monday, the Nepal Stock Exchange (NEPSE) was forced to suspend regular share trading for an entire day. NEPSE initially described the disruption as a “technical problem”. But information emerging after the incident points to a more serious cause — a ransomware attack on the data centre operated by Data Hub Pvt Ltd.
The attack disrupted the servers and trading management systems (TMS) of 72 brokerage companies, bringing the stock market to a standstill.
Trading resumed on Tuesday after the systems were restored using backup data from Data Hub’s disaster recovery centre in Butwal.
According to information provided by Data Hub, the attack was detected early Sunday morning, around 4am to 5:30am. However, the affected brokerage systems remained unable to operate throughout Monday.
Cybersecurity expert and BugV founder Naresh Lamgade said the incident should not be treated as an ordinary hacking attempt.
“This was not a normal hack. It appears to have been a systematic and planned ransomware attack,” Lamgade said.
What happened?
A letter sent by Data Hub to YCO Pvt Ltd also explicitly refers to the incident as a ransomware attack.
In a ransomware attack, attackers gain access to a computer system or server and encrypt files, making them inaccessible. In many cases, attackers then demand a ransom in exchange for a decryption key.
According to Lamgade, ransom notes are commonly left behind in such attacks, demanding payment through bank transfers or cryptocurrencies.
“It is possible that such a message exists within Data Hub but has not been made public,” he said.
However, a senior Data Hub official said the incident appeared to differ from the conventional pattern.
“Ransom messages are usually left in ransomware attacks. But that did not happen in our case. The data was encrypted and the systems were rendered unusable,” the official said.
The official said it was too early to determine whether any data had been stolen.
“We are investigating whether the data was compromised. Our team is currently working on it. We will also know who was behind the attack only after the investigation,” the official said.
How did the stock market resume?
The official said trading resumed on Tuesday after Data Hub restored the affected systems from its disaster recovery centre in Butwal.
“We formatted all the encrypted data and restored it from the backup in Butwal. Fortunately, there was no data loss. That is the biggest relief for now,” the official said.
The official also acknowledged that some fintech companies and other organisations were affected by the incident, although he declined to identify them or provide details about the extent of the damage.
“All the details will emerge after the investigation,” he said.
Why is the Data Hub attack significant?
Data Hub is one of Nepal’s major data centre service providers. According to information on its website, the company has been providing services since 2012 and hosts data for more than 1,000 companies.
Banks, insurance companies, mobile wallet providers and other major institutions use data centres to host their systems and data.
Nepal’s regulatory framework also restricts banks and payment service providers from storing certain data outside the country, making domestic data centres particularly important to the financial sector.
The scale of the disruption has therefore raised questions about the security of critical infrastructure hosted at a single facility.
Lamgade uses a simple analogy to explain the situation.
“Imagine a house being used as a data centre. One room houses NEPSE, another houses banks and another houses insurance companies,” he said.
“The attack may appear to have primarily affected the room where NEPSE was located, but the house itself was attacked.”
This is why investigators must determine whether systems belonging to other organisations were also compromised, he said.
Was the attack planned?
Another cybersecurity expert, who spoke to Onlinekhabar on condition of anonymity, said attacks of this scale are generally not carried out in a single day.
According to the expert, attackers often spend considerable time identifying critical systems, monitoring networks and looking for vulnerabilities before launching an attack.
“The fact that the attackers were able to affect NEPSE’s entire trading system so deeply could indicate that they had gained access to the system beforehand,” the expert said.
However, the expert stressed that only a forensic investigation can establish how long the attackers had access to the system.
“It is important to establish whether Data Hub itself managed the servers or whether that responsibility lay with NEPSE and the brokers,” the expert said.
“In some cases, a data centre only provides space, electricity and internet connectivity, while the client manages the systems. But regardless of the arrangement, the incident raises questions about the security of the infrastructure.”
He said data centre operators need to maintain strong security systems because attackers may make repeated attempts before successfully penetrating a network.
The importance of backups
The incident has also highlighted the importance of maintaining reliable backups. In this case, the backup at the Butwal disaster recovery centre allowed the stock market to resume operations. But the cybersecurity expert said more information is needed about exactly how the recovery was carried out.
“Data Hub needs to clarify whether the affected systems had to be completely formatted and restored, or whether the data was moved to another server before operations resumed,” he said.
It is also important to establish whether the attackers merely encrypted the data or whether they copied and removed it from the system, he added.
What is a ransomware attack?
Ransomware is a form of cyberattack in which criminals gain access to an organisation’s computer systems or servers and encrypt important files and data.
Once encrypted, the files cannot normally be opened or used. Attackers often leave a ransom note demanding payment in exchange for a decryption key.
More recent ransomware attacks frequently involve a second step known as “double extortion”. Attackers first steal sensitive data and then encrypt the victim’s systems. They threaten to publish the stolen information if the ransom is not paid.
This means that even organisations with functioning backups can face serious consequences if sensitive information has already been copied and removed from their systems.
Whether the Data Hub incident involved data theft as well as encryption remains under investigation.
Ransomware attacks have disrupted critical infrastructure worldwide
Ransomware has repeatedly targeted financial institutions, data centres and other critical infrastructure around the world.
In May 2021, the DarkSide ransomware group attacked Colonial Pipeline in the United States, forcing the company to shut down its pipeline operations. The disruption contributed to fuel shortages and price increases in parts of the eastern United States. Colonial Pipeline later paid a ransom of about $4.4 million.
In November 2023, the LockBit ransomware group attacked the US arm of China’s Industrial and Commercial Bank of China (ICBC). The incident disrupted trade settlement operations in the US Treasury market, forcing some transactions to be handled manually.
The 2019-20 ransomware attack on UK foreign exchange company Travelex also disrupted the company’s website, mobile application and operations at branches around the world for weeks.
Other financial institutions, including US insurer CNA Financial, have also been targeted by ransomware attacks.
The incidents demonstrate why ransomware attacks on financial institutions and the infrastructure supporting financial markets can have consequences beyond a single company.
India has also experienced similar disruptions. In 2024, a ransomware attack on C-Edge Technologies affected the operations of hundreds of small banks in the country.
Large data centre operators have also been targeted. Companies including Equinix and CyrusOne have previously reported ransomware-related incidents.
For Nepal, the attack on Data Hub has raised a more immediate question — how resilient are the systems underpinning critical financial infrastructure, and what safeguards are in place if the primary data centre is compromised?
Those questions are likely to become clearer as the forensic investigation into the incident progresses.
Click Here For The Original Source.
