Cyber Attack Rocks NEPSE Broker Systems: Investigation Committee Probes Critical Vulnerabilities
The Nepali capital market was shaken by a significant cyber attack on Monday, prompting immediate action from regulatory bodies. Following the incident, the Securities Board of Nepal (SEBON) swiftly formed an investigation committee, while the Nepal Police has also initiated its own probe into the matter. This dual-pronged investigation aims to uncover the full extent of the damage, determine if investor data was compromised, ascertain whether the attackers merely disrupted systems or altered/destroyed information, and ultimately identify those responsible for the sophisticated breach. The incident has raised serious concerns about the cybersecurity posture of the nation's financial infrastructure and its potential implications for investor confidence.
The legal ramifications of such an attack are substantial. If investigations reveal unauthorized access to computer or information systems, the Electronic Transactions Act, 2063, specifically Section 45, could be invoked. This section prescribes imprisonment, fines, or both for unauthorized access. Furthermore, if evidence emerges that the attackers destroyed, altered, or rendered unusable any computer system, information, data, or programs—a common characteristic of ransomware attacks—Section 46 would apply. Investigators will particularly scrutinize this aspect, given the nature of modern cyber threats. The unauthorized disclosure of electronically stored records or information, if proven, could also lead to charges under Section 48, pertaining to privacy violations.
Beyond the realm of cybercrime, the incident could also trigger investigations into securities-related offenses. Should the probe uncover that individuals gained unauthorized access to confidential share trading information and subsequently used it for personal gain or through proxy accounts, the matter would extend beyond a mere cyber incident. Such actions could fall under the purview of insider trading regulations as per the Securities Act, 2063. Moreover, if the attackers are found to have manipulated share prices or trading volumes, influenced investors with false or misleading information, or engaged in fraudulent transactions, other provisions of the Securities Act could be brought into play. This highlights a critical distinction: the act of breaching a computer system and the act of leveraging that breach for illegal financial gain in the stock market are separate offenses, both potentially applicable in this single incident.
To thoroughly address the incident and recommend robust preventative measures, the investigation committee must meticulously answer ten critical questions:
- Entry Point Analysis: What was the exact method of entry for the attackers into the data hub's system? Was it through weak passwords, user error, infected devices, third-party service providers, software vulnerabilities, or another vector? Identifying the root cause is paramount for effective security enhancements.
- Scope of Access: Which systems did the attackers manage to access? Was the compromise limited to a single data hub server, or did it extend to trading management systems, central depository services, payment gateways, and other critical infrastructure?
- Data Integrity Check: Has investor data been stolen, altered, or destroyed? This is the most sensitive question, requiring independent digital forensics to verify the integrity of customer names, accounts, trading history, orders, funds, securities ownership, and other personal details.
- Trading Interference: Did the attackers interfere with any share transactions or trading orders? If trading orders were altered, halted, or created through unauthorized system access, this transcends a mere cybersecurity incident and becomes a grave matter concerning the integrity of the entire securities market.
- Financial Motivation: Is there evidence that the attackers sought financial gain? Was a ransom demanded, and if so, how and where was it requested? Was pressure applied to transfer funds via digital currency or other means?
- Structural Vulnerability: How did a situation arise where 72 out of 90 brokers were dependent on a single data infrastructure? This presents a significant structural risk where a problem in one location can impact a large segment of the market. The committee must investigate not only the technical but also the regulatory reasons behind this setup.
- Disaster Recovery Efficacy: Why did data backup and alternative systems fail to become operational immediately? How effective were the provisions for an alternative data center, a separate network, and emergency operational procedures for critical financial infrastructure? Was the emergency plan merely on paper or regularly tested in practice?
- Security Audit History: How frequently were security audits and risk assessments conducted for the data center and broker systems? Were vulnerabilities identified previously, and if so, why were they not rectified?
- Incident Response Coordination: How quickly was information exchanged among relevant stakeholders—the data hub, brokers, NEPSE, CDSC, SEBON, Nepal Rastra Bank, police, and other cybersecurity agencies—after the incident was detected? Was there a clear incident management protocol in place?
- Future Prevention Strategy: What concrete measures will be adopted to prevent similar attacks in the future? This is perhaps the most crucial question. While identifying and punishing culprits is necessary, it alone won't solve the systemic issue. A robust plan must include reducing reliance on a single data center, establishing alternative systems, conducting regular cyber exercises, implementing independent security audits, and building a market structure capable of operating even during emergencies.
The incident affecting 72 brokers is not merely a coincidence but potentially a symptom of structural weaknesses within Nepal's capital market. The findings of this investigation will be critical in shaping future cybersecurity policies, enhancing market resilience, and restoring investor confidence. It is imperative that the committee's recommendations lead to tangible improvements, ensuring the long-term stability and security of the Nepali stock exchange. Separately, the Nepal Stock Exchange had announced that the market would remain closed on Ashwin 5, Monday.

Rohan Poudel
Rohan is a Full Stack Developer and the technical architect behind Nepali Share Market. With expertise in React, Node.js, and Machine Learning, he specializes in building scalable financial platforms and automated trading algorithms for the NEPSE ecosystem.
View Full Profile