Science & Technology
Nepal uncovers 135 compromised government email accounts after joining global breach tracker
Officials say the leaked credentials highlight long-standing weaknesses in government digital security, with immediate efforts underway to secure affected accounts.Sajana Baral
At least 135 official government email addresses under the primary ‘nepal.gov.np’ domain have been compromised in various data breaches, exposing sensitive state records and triggering a wave of high-profile phishing scams across the country.
The breach was revealed after Nepal officially joined Have I Been Pwned, a global web portal that monitors domain security and tracks credential leaks. According to the National Cyber Security Centre, Nepal became the 47th government entity worldwide to integrate with the monitoring system, enabling state authorities to track exactly when and where official credentials are exposed.
Initial findings from the portal confirmed that compromised email accounts belonged to civil servants stationed across vital institutions, including the Office of the Prime Minister and Council of Ministers, the Ministry of Home Affairs, the Ministry of Finance, and the Ministry of Foreign Affairs.
Prominent cybersecurity expert Mona Nyachhyon warned that such leaks pose a direct threat to state confidentiality. “When official email addresses are compromised, it grants unauthorised actors a doorway into internal networks,” Nyachhyon said. “This compromises government secrecy, exposes sensitive communication, and provides attackers with legitimate channels to launch sophisticated social engineering campaigns.”
The Director of the National Cyber Security Centre, Raj Kumar Maharjan, stated that the agency is moving swiftly to notify affected departments and secure vulnerable accounts. “Previously, it was exceptionally difficult to obtain concrete data on where and how Nepal’s government records were being stolen,” Maharjan said. “Through this portal, our centre now receives precise details regarding which email address was leaked and from which source. This allows us to alert relevant officials in real time, enforce immediate password resets, and prevent further damage.”
To strengthen its defensive perimeter, the centre has expanded its use of advanced technical tools. It currently utilises CTM360, a dark web monitoring tool provided by the International Telecommunication Union, to track illicit data exchanges involving state assets. Additionally, the centre purchased a Security Information and Event Management system to collect and analyse activity logs across government network nodes, expanding on previous open-source platforms like Wazuh and Security Onion.
When system anomalies are detected, Cyber Security Centre analysts conduct deep-dive investigations using global threat intelligence tools that cross-reference suspicious activity against known malicious IP addresses worldwide. The centre has also intensified Vulnerability Assessment and Penetration Testing (VAPT), auditing nearly 40 government systems over the past four months.
According to Maharjan, legacy frameworks and outdated software remain widespread across local and national agencies, greatly increasing vulnerability. He pointed out that the rapid adoption of artificial intelligence has introduced new security blind spots, particularly when agencies use AI tools or ‘vibe coding’ to build portals without understanding the underlying encryption.
“AI tools have made website development fast and accessible, but users often do not know how secure the generated systems truly are,” said Maharjan. “People build applications quickly using AI, but a lack of technical knowledge regarding encryption and security standards elevates the risk of cyber attacks. Furthermore, over 90 percent of cyber incidents stem from human behaviour and social engineering rather than purely technical flaws.”
Exploiting human psychology, attackers have increasingly used AI to generate convincing phishing emails that leverage fear and authority. Scammers have repeatedly impersonated high-ranking government and security officials to intimidate citizens.
In a recent case, fraudsters forged emails under the name and title of Additional Inspector General of Nepal Police Manoj Kumar KC. The fraudulent messages claimed that the recipient’s IP address had been caught accessing restricted or illegal content. Recipients were threatened with immediate prosecution by the Central Investigation Bureau and warned of impending court orders if they did not reply instantly.
Similar fake circulars have been circulated using the identity of the Prime Minister’s Office and Deputy Inspector Generals of Police.
“We have detected phishing emails sent directly in the names of the Prime Minister’s Office and top police personnel,” said Maharjan. “I have even received phishing emails addressed to me personally. Their primary objective is to instil panic and trick individuals into handing over confidential personal data.”
Cyber threats targeting Nepal’s public sector have escalated steadily over recent years. A past study by Bhairav Technology revealed that state systems were targeted by Advanced Persistent Threat (APT). Notably, the Sidewinder APT group compromised emails within the Prime Minister’s Office to siphon sensitive regional data. During the tenure of former Prime Minister Pushpa Kamal Dahal, attackers manipulated an official document bearing the Prime Minister’s signature, circulating auto-run malicious files disguised as trip itineraries to infect government computers.
Systemic vulnerabilities came to a head on 1 January 2024, when a massive Distributed Denial of Service (DDoS) attack crippled essential public service websites and web applications for weeks. In response, the Cabinet decided to establish the National Cyber Security Centre on 23 January 2024, officially operationalising it later that spring.
While DDoS attacks and website defacements persist, centre officials maintain that current protocols allow technical teams to mitigate disruptions and restore compromised platforms rapidly. To build resilience, the centre regularly conducts cyber drills and capacity-building exercises across ministries.
Administratively, the government expanded the scope of the Prime Minister’s Office through amendments to the Government of Nepal Business Allocation Rules published in the Nepal Gazette on 13 May 2026. The reform transferred the Cyber Security Centre, the Data Management Centre, and the Department of Information Technology from the Ministry of Communication and Information Technology to the Prime Minister’s Office.
Despite these restructuring efforts, operational hurdles remain. Although the government’s 100-day agenda approved by the Cabinet on 27 March 2026 mandated the establishment of an Information Technology and E-Governance Office within three months, organisation and management surveys remain incomplete. As a result, the cyber centre’s ultimate organisational structure and reporting hierarchy remain unsettled, even as technical teams work to draft comprehensive incident response guidelines to counter emerging threats.




22.04°C Kathmandu













