Nepal’s stock market remained closed on September 21 after a ransomware attack at DataHub disrupted systems used by 72 brokers, raising concerns over market resilience and investor data security.

The Nepal Stock Exchange (NEPSE) suspended the day’s trading session after the Stock Brokers Association of Nepal requested a halt because affected brokerage systems were not functioning normally. NEPSE said continuing operations under the circumstances could create additional risks to its own trading infrastructure.
The incident has raised broader questions about the resilience of Nepal’s increasingly digital capital-market infrastructure and the protection of investors’ data.
According to brokers cited by The Kathmandu Post, the data centre operated by DataHub Pvt Ltd was hit at around 4am on Sunday, September 20.
DataHub hosts servers used by 72 NEPSE trading members. More than 24 hours after the incident was detected, the full extent of the disruption was still being assessed.
YCO Pvt Ltd, which manages the trading systems used by the affected brokers, said information received from DataHub indicated that multiple systems and services had been affected.
These reportedly included trading management systems, CDSC-related services, payment gateways and other interconnected systems. The affected systems were isolated as a precaution.
NEPSE's public notice described the situation as an unresolved technical problem at DataHub rather than providing a detailed public account of the cyber incident. Other reporting, including the Kathmandu Post's investigation, identified the disruption as a ransomware attack.
The decision was primarily a risk-control measure.
The affected brokers were unable to operate their systems normally, while their infrastructure was connected to the broader NEPSE network. YCO warned that continuing trading while the affected systems were isolated and the scope of the incident was still being assessed could expose the exchange to additional cybersecurity and operational risks.
The Stock Brokers Association therefore asked NEPSE to suspend the session.
NEPSE subsequently halted Monday's regular trading under Rule 21(1) of the Securities Listing and Trading Regulations, 2018. Independent reports of the exchange's notice also confirm that the underlying technical problem had remained unresolved.
The reported disruption went beyond the basic ability to place share orders.
According to YCO's communication cited by the Kathmandu Post, the ransomware incident affected several interconnected services, including:
Trading Management Systems (TMS)
Systems connected with CDSC-related operations
Payment gateways
Other interconnected services
Because these systems support different stages of securities trading and settlement, isolating compromised infrastructure was considered necessary while the incident was being investigated.
The precise extent of any data compromise had not been established when the Kathmandu Post report was published.
The shutdown has also shifted attention from market continuity to cybersecurity.
Investors and market analysts are seeking clarity on whether any personal, financial or trading information was accessed during the attack.
At the time of reporting, authorities and service providers were still assessing the scope of the incident. Therefore, there is not yet a confirmed public finding that investor data were stolen.
The distinction is important: a ransomware attack can disrupt systems without necessarily proving that particular categories of data were exfiltrated.
The incident has exposed another structural concern: the concentration of brokerage infrastructure within a common data-centre environment.
With 72 brokers relying on the affected facility, a disruption at one critical infrastructure provider was capable of preventing a large portion of the brokerage sector from functioning normally.
Investor and market analyst Subas Chandra Dhungana told the Kathmandu Post that Nepal needs stronger contingency arrangements for situations in which critical market infrastructure becomes unavailable.
The episode therefore raises questions about backup infrastructure, disaster recovery, network segmentation, cybersecurity testing and alternative trading arrangements.
At the time of the Kathmandu Post's September 21 report, NEPSE had not confirmed whether normal trading would resume on Tuesday.
The immediate priority was to assess and contain the data-centre incident before restoring affected services.
Other reports also confirmed that the exchange's decision was linked to the unresolved DataHub problem and the request from the Stock Brokers Association.
Nepal has been moving toward a more technology-driven capital market, with plans for digital trading, expanded financial instruments and stronger market infrastructure.
That transition also increases the importance of cybersecurity and operational resilience.
Monday's shutdown demonstrates how a problem outside the physical premises of NEPSE can still interrupt the wider market when brokerage, payment and securities systems are interconnected.
The immediate cause of Monday's closure was the disruption at DataHub. The longer-term issue is whether Nepal's capital-market infrastructure has sufficient redundancy and cybersecurity safeguards to keep trading and settlement functioning when a major technology provider is compromised.
Comments
0 comments
Loading comments...