Turkmenportal logo
Today 12:12
21232123
Share on social networktelegram iconOk iconVk iconTwitter (X) icon
135 hacked government email addresses found in Nepal

At least 135 official email addresses on the nepal.gov.np domain were compromised as a result of various data breaches. This was revealed after Nepal joined Have I Been Pwned, a global platform for monitoring credential leaks. The country became the 47th government agency in the world to integrate with this system.

According to the National Cyber Security Center, the victims include employees of the Prime Minister's Office, the Ministry of Interior, the Ministry of Finance, and the Ministry of Foreign Affairs. The center's director, Raj Kumar Maharjan, reported that the new platform allows for the prompt identification of the source of the leak, alerting officials, and forcing password changes.

To strengthen its security, the agency uses the CTM360 darknet monitoring system provided by the International Telecommunication Union and has also acquired a security event management (SIEM) system. Over the past four months, approximately 40 government systems have been tested for vulnerabilities.

According to Maharjan, over 90% of cyber incidents are not related to technical vulnerabilities, but to human error and social engineering. He noted a rise in phishing attacks using artificial intelligence: scammers send emails impersonating high-ranking officials and the police, threatening recipients with legal action.

Nepal's government systems have previously been the target of sophisticated cyberattacks, including the hacking of the Prime Minister's Office by the Sidewinder group. A major DDoS attack in January 2024 prompted the creation of the National Cyber Security Center, which was transferred to the Prime Minister's Office in May 2026. However, the agency's final organizational structure has not yet been approved.