Full Report
The Securities Board of Nepal (SEBON) has launched a high-level probe into the suspension of share trading after a ransomware attack disrupted the Data Hub server, affecting 72 out of Nepal’s 92 registered stock brokerage firms. The cyber security breach forced an emergency halt to trading operations across the Nepal Stock Exchange (NEPSE), raising widespread concern among millions of capital market investors. In response to the disruption, SEBON has formed a five-member inspection committee led by an Executive Director to investigate the root technical causes, review security protocols, and recommend preventative measures for Nepal’s stock market infrastructure.
Analysis Summary
# Incident Report: Ransomware Disruption of Nepal Stock Exchange (NEPSE) Infrastructure
## Executive Summary
On September 22, 2026, a ransomware attack targeted Data Hub Pvt. Ltd., the primary data center provider for Nepal’s financial markets. The breach disrupted the Data Hub servers hosting 72 out of 92 registered stock brokerage firms, forcing an emergency suspension of share trading across the Nepal Stock Exchange (NEPSE). While operations were paralyzed, a successful pre-incident backup allowed for a recovery path, and the Securities Board of Nepal (SEBON) has initiated a high-level probe into the infrastructure's systemic vulnerabilities.
## Incident Details
- **Discovery Date:** Sunday, September 22, 2026 (Approx. 05:30 AM)
- **Incident Date:** September 22, 2026
- **Affected Organization:** Data Hub Pvt. Ltd. (Service Provider for 72 Brokerages)
- **Sector:** Financial Services / Capital Markets
- **Geography:** Kathmandu, Nepal
## Timeline of Events
### Initial Access
- **Date/Time:** Prior to 05:30 AM on Sunday.
- **Vector:** Under investigation (Report due September 28).
- **Details:** Attackers targeted the Data Hub server architecture hosting the Trade Management System (TMS).
### Lateral Movement
- **Details:** The attack successfully spread across the infrastructure hosting 72 different brokerage firms, indicating a breach at the service provider level rather than individual firm levels.
### Data Exfiltration/Impact
- **Impact:** Encryption/Disruption of TMS, CDSC & Clearing systems, and integrated payment gateways. No specific data exfiltration was confirmed in the initial report, but operational availability was zero.
### Detection & Response
- **04:00 AM:** Final safe, isolated system backup completed.
- **05:30 AM:** Ransomware intrusion detected by Data Hub Pvt. Ltd.
- **Immediate Action:** Affected systems disconnected from external networks to prevent further lateral movement.
- **Post-Detection:** SEBON formed a five-member inspection committee; NEPSE ordered to submit a forensic report by September 28.
## Attack Methodology
- **Initial Access:** Not disclosed (Under forensic review).
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Not disclosed.
- **Discovery:** Not disclosed.
- **Lateral Movement:** Compromise of shared data center infrastructure allowed simultaneous impact on 72 brokerage entities.
- **Collection:** Not disclosed.
- **Exfiltration:** Not disclosed.
- **Impact:** Ransomware deployment leading to service exhaustion and emergency halt of national trading.
## Impact Assessment
- **Financial:** Paralyzed a market with capitalization exceeding Rs 45 Kharba.
- **Data Breach:** Scope of sensitive investor data theft is currently under investigation.
- **Operational:** Total suspension of share trading; 72/92 brokers offline; clearing and payment gateways halted.
- **Reputational:** Widespread concern among 8 million capital market investors regarding the security of Nepal's financial infrastructure.
## Indicators of Compromise
- **Network indicators:** Internal connections to Data Hub server segments (Specific IPs/URLs currently under forensic embargo).
- **File indicators:** Ransomware encrypted files on TMS servers.
- **Behavioral indicators:** Unauthorized encryption activity detected at 05:30 AM; disruption of automated settlement workflows.
## Response Actions
- **Containment:** Emergency disconnection of impacted systems from external networks and the internet.
- **Eradication:** Forensic analysis initiated by a five-member technical inspection team to sanitize servers.
- **Recovery:** Restoration processes initiated using the isolated 04:00 AM backup.
## Lessons Learned
- **Redundancy:** Reliance on a single data center (Data Hub) for the majority of the market created a single point of failure.
- **Backup Strategy:** The 90-minute window between the last backup and detection saved the market from catastrophic data loss, highlighting the necessity of frequent, isolated "air-gapped" backups.
- **Third-Party Risk:** The incident underscores the need for stricter cybersecurity audits for vendors hosting critical national infrastructure.
## Recommendations
- **Infrastructure Diversification:** Implement geographic and provider redundancy for brokerage hosting to avoid mass outages.
- **Zero Trust Architecture:** Implement stricter network segmentation between different brokerage tenants within the same data center.
- **Real-time Monitoring:** Deploy advanced EDR (Endpoint Detection and Response) to identify ransomware behavior earlier than the 90-minute window observed here.
- **Regulatory Oversight:** SEBON should establish mandatory minimum-security baselines for all third-party IT providers in the financial sector.