Ransomware at a Nepali data centre halts share trading for a day
A ransomware attack on Data Hub, which hosts systems for 72 of Nepal's 90 stockbrokers, forced NEPSE to suspend trading on 21 September.
A ransomware attack on Data Hub, a Kathmandu data-centre company, knocked out the trading systems of 72 Nepali stockbrokers on Sunday 20 September 2026, the Kathmandu Post and Onlinekhabar reported. The Nepal Stock Exchange suspended all trading on Monday 21 September. Data Hub restored the systems from backups at its disaster-recovery site in Butwal, and trading resumed on Tuesday.
- 1,000+companies whose data Data Hub hosts
- 18brokers not affected, hosted elsewhere
- 1 dayof trading lost before systems were restored
- Rs 4.5 tnor more in investor assets in the market, per the Post
- 28 Sepdeadline for NEPSE's report to the regulator
What happened
Data Hub said the attack was detected early on Sunday, between about 4 am and 5:30 am. Data Hub has operated since 2012 and hosts data for more than 1,000 companies, according to Onlinekhabar. Among them were the servers of 72 brokerage firms. The Kathmandu Post reported that 90 broker firms are currently operating, so the other 18, hosted elsewhere, were not affected. Nepal Stock Exchange, known as NEPSE, at first described the problem as technical. A letter from Data Hub to the trading software company later called it ransomware.
YCo, the company that manages the brokers' trading systems, told brokers that the incident affected the trading management system, the central depository and clearing systems, payment gateways and other connected services. It isolated the affected systems and warned that continuing to trade through the network link to NEPSE could add risk. The problem was still unresolved on Monday morning. After a written request from the Stock Brokers Association, NEPSE halted trading for the whole day. The 18 unaffected brokers asked to continue, but NEPSE refused.
On Monday evening, the NEPSE board agreed not to suspend trading again on Tuesday, even if the Data Hub problem continued. Systems were restored and trading resumed on Tuesday. The Securities Board of Nepal, the market regulator, sent a five-member inspection team and asked NEPSE to study the incident and submit a report with recommendations by 28 September. The Kathmandu Post put investor assets at stake in the market at 4.5 trillion rupees or more.
The engineering behind it
Ransomware is malicious software that encrypts files so their owner can no longer use them. Onlinekhabar explained that attackers usually leave a note demanding payment for the decryption key. In double extortion, they also steal data first and threaten to publish it. A senior Data Hub official said no ransom note was left, while cybersecurity expert Naresh Lamgade, founder of BugV, said a note may exist without being made public. Who carried out the attack was not known, and neither was whether any data was copied.
Recovery depended on preparation made long before the attack. Data Hub formatted the encrypted machines and restored them from backups kept at its disaster-recovery centre in Butwal, in a different city from the main site. The official said no data was lost. In general, a backup only protects against ransomware if the attacker cannot reach and encrypt it too, which is why backups are often kept offline or on separate networks. A second site in another city also protects against fire, flood or power failure.
Experts quoted by Onlinekhabar raised further questions. Lamgade called it a systematic, planned attack and said other customers' systems in the same data centre should also be checked. Another expert said attacks of this size usually follow a period of quiet exploration, so the attackers may have had access well before Sunday. A forensic investigation would need to establish how long they were inside, how they got in, and whether Data Hub or the brokers were responsible for managing the affected servers.
Onlinekhabar placed the attack among well-known cases abroad. In May 2021 a ransomware attack on Colonial Pipeline in the United States led to a ransom of about 4.4 million dollars. In November 2023 an attack on the US arm of the Chinese bank ICBC disrupted settlement of trades in the US Treasury market. In 2024 an attack on C-Edge Technologies in India affected hundreds of small banks. In each case, one service provider sat underneath many other organisations.
What it means in Nepal
The attack showed how one shared facility can become a single point of failure. One data centre hosted the trading systems of most of the country's brokers, so one incident stopped the whole market for a day. The Kathmandu Post reported that this was not NEPSE's first technical problem in 2026. In February and again in July, the index displayed false drops of more than 30 percent because of data errors. Market expert Niraj Giri, a former regulator, said the repeated problems come from a lack of long-term planning.
Onlinekhabar noted that Nepal's rules restrict banks and payment providers from storing certain data abroad, so banks, insurers and digital wallet companies rely on domestic data centres. That makes the security of a few local facilities important for much of the financial system. Former broker association president Narendra Raj Sijapati told the Post that a small number of business groups control key market infrastructure, and that responsibility gets passed around when something fails.
For engineering students, the case is a local example of ideas that are often taught with foreign examples. Separate backups, a second site in another city and isolating affected systems quickly are what allowed trading to restart within a day. Questions about who manages which server, how attackers got in and how long they stayed are the everyday work of incident response, and Nepali institutions will need engineers who can answer them.
What to study if this interests you
Database Management System, ENCT 301, in the fifth semester of BCT, covers transactions, backup and recovery, the ideas that let Data Hub restore the brokers' systems without data loss. The course has a full guide on this site. Computer Networks, ENCT 304, in the same semester, explains how systems in different places are linked, and how a network can be divided so that one infected part does not reach the rest.
Distributed and Cloud Computing, ENCT 411, in the seventh semester, covers replication across sites and avoiding single points of failure. Network and Cyber Security, ENCT 463, in the eighth semester, covers malware, access control and incident response, the skills used to investigate an attack like this one. Students can test these ideas on a small scale by backing up a project database, deleting it on purpose and timing how long a full restore takes.
Words in this story
- Ransomware
- Malicious software that locks or encrypts a victim's files and demands payment to unlock them.
- Disaster recovery site
- A second facility, usually in another place, that holds copies of systems and data so work can restart after a failure.
- Single point of failure
- One part of a system whose failure stops the whole system from working.
- Incident response
- The organised steps taken to contain, investigate and recover from a security attack.
Where this comes from
- The Kathmandu Post, 22 Sep 2026
- Onlinekhabar English, 22 Sep 2026
Written in our own words; no sentence is copied from these reports. Researched with AI assistance on 11 October 2026; no member of faculty has reviewed it yet. If you spot a mistake, call 01-5091616 and we will correct it and say so.




