Kathmandu, Nepal — A ransomware attack on infrastructure operated by Data Hub Pvt. Ltd. disrupted trading systems used by 72 securities brokerage companies and led the Nepal Stock Exchange (NEPSE) to suspend regular share trading on September 21, 2026.
Data Hub said the ransomware incident affecting infrastructure hosting brokers’ Trading Management System, or TMS, was detected at around 5:30 a.m. on September 20. The company informed YCO Pvt. Ltd., which manages the trading systems used by the affected brokers, about the incident.
NEPSE initially described the disruption publicly as a technical problem at Data Hub. It said the problem had remained unresolved since the morning of September 20 and that continuing regular trading while the issue persisted could pose a risk to its trading system. The Stock Brokers Association of Nepal also requested that the session be suspended.
NEPSE consequently halted regular trading on September 21 under Rule 21(1) of the Securities Listing and Trading Regulations, 2018.
Ransomware affected interconnected services
According to information provided by Data Hub and relayed by YCO, the ransomware incident affected several interconnected services, including TMS infrastructure, systems related to CDS and clearing operations, payment gateways and other connected services.
Data Hub kept affected systems offline while technical teams assessed whether the malicious software could have affected or spread to other connected networks.
The company said a complete backup taken at around 4 a.m. on September 20 — roughly an hour and a half before the attack was detected — had been secured separately and remained isolated from the affected infrastructure.
Forensic analysis and security checks were carried out before the affected infrastructure was restored.
Ransomware is malicious software designed to prevent users or organisations from accessing systems or data, commonly by encrypting files. Attackers may demand payment for restoring access, and some ransomware operations also involve stealing data before encryption.
No confirmed evidence of investor data theft
The full scope of access gained by the attackers has not been publicly established.
As of subsequent reporting on September 23, it remained unclear whether data had been stolen or altered during the attack or precisely how the attackers gained access to the Data Hub systems. Data Hub said further information would depend on forensic examination and security checks.
NEPSE spokesperson Murahari Parajuli told New Business Age that NEPSE's own trading system had not been compromised. The incident nevertheless created enough risk to connected market systems for trading to be suspended while the affected infrastructure was isolated.
A separate claim that Data Hub hosts records or systems belonging to 17 to 18 government agencies has appeared in media reporting, but no authoritative confirmation identifying those agencies or establishing that their systems were affected by this ransomware incident was found during verification. That claim should therefore not be presented as confirmed.
Trading restored the following day
Regular NEPSE trading resumed on September 22 after the technical problem affecting the Data Hub infrastructure was reported as resolved.
NEPSE Information Officer Murahari Parajuli said trading could resume after the exchange received confirmation that the issue involving the data centre serving the 72 trading members had been addressed.
New Business Age reported that Data Hub's managing director, Deepak Shrestha, said data stored at the company's separate Butwal facility allowed the affected systems to be recovered. He also said the attack originated outside Nepal and that the attackers had demanded payment in bitcoin, although the amount was not disclosed.
Regulator orders investigation
The disruption has prompted regulatory scrutiny of the resilience and security of Nepal's capital-market technology infrastructure.
The Securities Board of Nepal (SEBON) directed NEPSE to investigate the incident and submit a report containing corrective recommendations. It also deployed a five-member inspection team led by a deputy executive director to examine the technical problem, its impact and risks to the trading system.
The incident has also renewed scrutiny of the concentration of critical brokerage infrastructure at a single service provider. Data Hub hosts the TMS server infrastructure used by 72 brokerage companies, meaning a disruption at the facility affected a large part of the market simultaneously.



Join the conversation
Comments are reviewed before publication. Your email stays private.