Ransomware Threat Behind ‘Technical Glitch’: NEPSE Closed on Brokers’ Request, SEBON Launches Probe
On Sunday, NEPSE halted trading without opening the market. While the official reason was a ‘technical problem,’ reports emerged that the data center hosting servers of 72 brokers was hit by a ransomware attack. SEBON has formed a five-member investigation team.
Kathmandu. On Sunday, an unusual event unfolded in Nepal’s capital market—the market was closed without any trading taking place. The official reason cited was a ‘technical problem in the data center of brokers.’ However, the incident did not remain limited to that, and reports from various sources revealed that the data center had been hit by a ransomware attack.
Out of 92 companies authorized by the Nepal Stock Exchange (NEPSE) to work as stockbrokers, the servers of 72 brokers are hosted in a single data center. When a problem occurred in that data center, the trading systems—i.e., TMS—of a large number of brokerage companies were affected.
As most brokers were unable to operate their systems, NEPSE suspended all securities trading on Sunday at their request. Initially presented as a routine technical issue, it later emerged that the data center had suffered a ransomware attack.
In a ransomware attack, hackers take control of a system or its files, block access, and demand money to restore access. However, in this incident, no official technical details have been made public regarding whether data was stolen, whether the attackers demanded money, or how many systems were affected.
‘Cyber Attack’ Missing from SEBON’s Statement
The press release issued by the Securities Board of Nepal (SEBON) does not explicitly mention ransomware or a cyber attack. The board stated that trading was suspended after it received information about a ‘technical problem’ in the data center hosting the servers of 72 brokers.
This language raises further questions—if the problem was merely technical, why was it necessary to close the market for the entire day? And if it was a cyber attack, why was clear information not immediately provided to investors?
In a sensitive sector like the capital market, delayed or incomplete information risks spreading rumors, weakening investor confidence, and raising serious questions about system security.
Five-Member Investigation Team Formed
SEBON, stating it took the incident seriously, has formed a five-member inspection team led by its deputy executive director. The team has been tasked with immediately identifying the technical and other problems and determining the real reason behind the trading suspension.
Based on the investigation team’s report and recommendations, the board says necessary steps will be taken to make Nepal’s securities market healthier, safer, and more transparent.
Similarly, SEBON has directed NEPSE to conduct a detailed study and investigation of the incident and submit a report with necessary reforms to prevent such incidents from recurring by October 28, 2026 (2083 Ashwin 12).
72 Brokers in One Data Center—Isn’t That a Major Risk in Itself?
The incident has raised another serious question about the technological infrastructure of Nepal’s capital market. With the systems of 72 out of 92 brokers relying on a single data center, a single problem there can stall almost the entire market.
This raises questions about the effectiveness of ‘single point of failure,’ alternative data centers, real-time backup, disaster recovery, cyber security testing, and emergency trading continuity arrangements.
If the main system is affected and services cannot be immediately operated from an alternative system, the question of how secure Nepal’s online securities trading system really is becomes serious.
Who Will Bear Investors’ Losses?
When the market is closed, investors who needed to sell or buy shares have missed opportunities. This may have directly impacted investors wanting to trade due to loan repayments, margin management, short-term trading, or emergency cash needs.
It remains to be seen from the investigation whose weakness among brokers, data center operators, NEPSE, and regulators was responsible. But the question of who will take responsibility for the opportunity loss suffered by investors and the impact on market confidence has already arisen.
Now, the facts made public by SEBON’s five-member team, the report submitted by NEPSE, and the technical examination of the affected data center must clarify the truth of the incident. Whether the problem was merely ‘technical’ or a serious cyber attack on Nepal’s capital market—investors await a transparent answer.

