Ransomware Attack on Data Hub: Pre-attack Backup Safe, TMS Service Disrupted
Data Hub Pvt. Ltd. has reported a ransomware attack on the infrastructure hosting broker companies' TMS. The backup up to 4 AM on Ashwin 4 is secure, but the system will not be brought back online until forensic analysis and security measures are implemented, leading to the suspension of Monday's trading.
Data Hub Pvt. Ltd. has confirmed a ransomware (cyber) attack on the infrastructure hosting broker companies' TMS. According to the company, the backup up to 4 AM on Ashwin 4, before the attack, has been secured and kept separately.
More than 30 hours have passed since the cyber attack, and as the problem remains unresolved, Monday's trading has been halted. Data Hub stated that a technical problem arose from 5:30 AM on Ashwin 4 and efforts are underway to resolve it.
Since the ransomware could spread to other connected networks and systems, the affected systems have not been brought back online so far. According to Data Hub, as TMS is connected to NEPSE's infrastructure and other related systems, it will take some time to conduct a forensic analysis and implement necessary corrective and security measures before bringing the system back online.
According to Yako, based on information received from Data Hub, the ransomware incident has affected the following systems and services:
- TMS
- CDSC-related systems
- Payment gateways
- Other interconnected services

