A ransomware attack at Data Hub disrupted systems used by 72 Nepali brokerage firms and forced NEPSE to halt trading for a day, raising questions about cybersecurity and market resilience.

Nepal’s stock market faced an unprecedented cybersecurity disruption this week after a ransomware attack affected the data-centre infrastructure used by dozens of brokerage firms.
The incident forced the Nepal Stock Exchange (NEPSE) to suspend regular trading on September 21, leaving investors unable to trade for the day.
Trading resumed on September 22 after the technical problem at Data Hub Pvt Ltd was reported as resolved. However, regulators are still examining the incident and its wider implications for Nepal’s digital capital-market infrastructure.
The disruption originated at Data Hub, a data centre that hosts the servers used by 72 trading-member companies.
OnlineKhabar reported that Data Hub detected the ransomware incident on the morning of September 20. The company described the incident as a ransomware attack in communication with YCO Pvt Ltd, which manages the trading systems used by the affected brokers.
Ransomware is malicious software that can restrict access to computer systems or data. In some cases, attackers also attempt to steal information and demand payment in exchange for restoring access.
Data Hub isolated the affected infrastructure while it investigated the incident and assessed whether the attack had spread to connected systems.
The affected data centre hosts systems used by 72 brokerage companies.
YCO reported that the disruption involved multiple systems and services associated with the brokers’ operations, including their Trading Management Systems (TMS), systems connected with the Central Depository System and Clearing (CDSC), payment gateways and other interconnected services.
Because these systems are connected to broader market infrastructure, restoring them immediately could have created additional operational and cybersecurity risks.
The Stock Brokers Association of Nepal requested that NEPSE suspend trading after the affected systems remained unavailable.
NEPSE subsequently halted the September 21 trading session under Rule 21(1) of the Securities Listing and Trading Regulations, 2018.
The exchange said continuing trading while the data-centre problem remained unresolved could potentially damage its trading system.
The decision was therefore not simply a routine technical outage response. It was intended to prevent a problem affecting interconnected broker infrastructure from creating further risks for the wider exchange.
Available reporting does not establish that NEPSE’s core trading system was successfully compromised.
NEPSE spokesperson Murahari Parajuli said safeguards had been put in place to protect the exchange’s own trading system. The affected infrastructure was isolated as the incident was investigated.
However, because the data centre was connected to NEPSE and other market systems, officials considered the possibility of cybersecurity and operational risks serious enough to suspend trading.
That distinction is important: the confirmed incident involved Data Hub’s infrastructure, while the potential risk extended to interconnected market systems.
At the time of reporting, there was no confirmed public finding that investors’ personal or financial data had been stolen.
Data Hub said it was conducting forensic analysis to determine the full impact of the incident.
The company also reported that its latest backup had been taken before the attack and stored separately. Keeping backups isolated from the primary infrastructure is an important part of recovery planning because ransomware can otherwise affect connected backup systems as well.
The final assessment of whether any data was accessed, copied or compromised will depend on the ongoing forensic investigation.
The incident has exposed how dependent Nepal’s capital market is on interconnected digital infrastructure.
With 72 brokers using the affected data centre, a disruption at one critical facility was enough to prevent a large part of the brokerage sector from operating normally.
This raises questions about redundancy, disaster recovery, cybersecurity monitoring and alternative arrangements for continuing market operations when a critical service provider becomes unavailable.
The issue is particularly relevant as Nepal continues to modernise its capital market and introduce more technology-dependent services.
The Securities Board of Nepal (SEBON) has directed NEPSE to investigate the circumstances surrounding the trading suspension and submit a report with measures to prevent similar incidents.
SEBON has also deployed a five-member inspection team led by a deputy executive director.
The regulator has asked for the investigation to examine the technical problem and recommend improvements.
This means the full institutional response to the incident is still developing.
NEPSE resumed regular trading on September 22 after Data Hub reported that the technical problem had been resolved.
The market had therefore remained closed for one regular trading session.
Although trading has resumed, the resolution of the immediate technical problem does not necessarily close the cybersecurity question. Authorities still need to establish the precise cause, determine the extent of any compromise and evaluate whether existing backup and contingency arrangements are sufficient.
The incident highlights several areas that could receive greater attention.
Redundancy: Critical market services need alternatives so that a single infrastructure failure does not disrupt a large part of the market.
Cybersecurity monitoring: Continuous monitoring and rapid incident detection can reduce the time between an intrusion and containment.
Isolated backups: Backups should remain protected from the systems they are designed to restore.
Incident-response plans: Brokers, data-centre operators, NEPSE and regulators need clearly defined procedures for handling major cyber incidents.
Data protection: Investors need confidence that personal, financial and trading information is protected even when connected systems are attacked.
Business continuity: A stock exchange requires contingency arrangements that allow essential market functions to continue safely when individual infrastructure providers fail.
The NEPSE incident has ended the immediate trading disruption, but the investigation will determine whether it was an isolated technical event or evidence of broader weaknesses in Nepal’s capital-market infrastructure.
No related articles found yet.
Comments
0 comments
Loading comments...