-
A series of data leaks and security failures has exposed weaknesses in how Nepal protects citizens’ personal information.
-
A Kathmandu campus publicly exposed personal data of 1,364 students by posting admit cards on social media, treating the breach lightly.
-
Government websites, including the Nepal Police Headquarter, have suffered repeated breaches, with hackers offering citizenship data of two million citizens for $7,000.

Nepal’s move to digital services has definitely made life easier for a lot of people. Now, citizens can access government records, apply for things online, and handle daily tasks right from their phones.
But recent incidents suggest the country is still struggling to keep up in the area of cybersecurity. Among the latest incidents is a data leak at Padma Kanya Campus in Kathmandu.
Padma Kanya Campus reportedly posted admit cards belonging to more than a thousand students on social media. The post vanished after media reports, but the damage was already done.
Students who scanned QR codes gained access to symbol numbers, registration numbers, and academic records of their peers. Campus officials shrugged it off as a convenience move.
A staff member even defended the practice, claiming other colleges do the same thing. “We are not the only ones. You just happened to find Padma Kanya,” they told Onlinekhabar.
This incident reveals a troubling reality. Nepal’s educational institutions lack a basic understanding of data privacy.
A Pattern of Digital Negligence Among Nepal Government Sites
The campus breach is not an isolated case. A few weeks earlier, software developer Nirdesh Subedi cloned the government’s official Nagarik App web portal. He hosted an older version on his personal domain.
His website appeared among the top search results on Bing for “Nagarik App login.” Google Chrome flagged the app as malicious. However, the damage had already happened.
The Nagarik App holds a lot of sensitive information – citizenship certificates, passports, PAN cards, education-related certificates, etc. Cloning the app without authorization puts users at risk of phishing attacks through which attackers could steal their login credentials.
Government Systems Under Siege
Government websites have become easy targets. On February 13, 2O25, hackers accessed 21 subdomains under the Koshi Provincial Government. A group called YNR claimed responsibility and posted evidence on the Zone-H portal.
The attacks kept coming. On March 26, 2O25, the government’s Hello Sarkar website fell to hackers. A group called Ghudra posted the data on Breach Forums following claims that the government was not responding to any of their communication attempts.
The most serious breach occurred on April 23, 2O25, when there was a security breach in the website of the Nepal Police Headquarters. A hacking group that goes by the name Kaju reportedly stole Nepali citizenship records of around two million people. They advertised the data for sale online for $7,000.
There have been continued security breaches because people have not learned lessons from previous attacks.
The Growing Cybercrime Wave in Nepal
Nepal Police’s Cyber Bureau statistics paint a worrying picture. During the last fiscal year, authorities registered 20,526 cybercrime complaints. Of these, 13,230 involved electronic offenses, while 7,296 were cyber fraud cases.
The previous fiscal year saw 18,926 complaints, with 11,186 electronic offense cases and 7,740 cyber fraud complaints. These cases have been on the rise.
The credential theft threat is even more pronounced in neighboring India, where IT firms face a surge in such attempts. Seqrite’s India Cyber Threat Report 2026 recorded 265.52 million detections across over 8 million endpoints, with stolen credentials increasingly traded on dark web markets.
In the 2O81/82 fiscal year alone, over 18,000 individuals fell victim to online fraud. They both got hit hard: 9,787 men and 7,921 women fell victim to cyber fraud. Most of these scams started on Facebook, and after that, it was TikTok, WhatsApp, Instagram, and even digital wallets like eSewa and Khalti.
Private Sector Collecting Data Without Accountability
The problem extends beyond government systems. Supermarket chains like Big Mart and Bhatbhateni routinely ask for customers’ names and phone numbers. Many customers receive little benefit in exchange for sharing sensitive information.
Cafés and restaurants force customers to enter mobile numbers before granting Wi-Fi access. Instead of simply providing passwords, they use captive portals that collect personal data.
Most businesses do not clearly inform customers that they are storing their information. Cybersecurity experts warn that weak data protection measures jeopardizes citizens’ privacy.
The Legal Gap
Nepal’s rules around data protection are, honestly, pretty flimsy. Privacy Act, 2O75 (2O18) and Individual Privacy Regulation, 2O77 (2O2O) provide the definitions of personal data and sensitive data. However, they do not ensure basic rights to access, erase, or correct data.
The government tried to tighten things up with the revised Draft Information Technology and Cyber Security Bill, 2O24, but lawmakers haven’t gotten around to passing it. If they ever do, breaking privacy rules could actually land you a fine of up to NPR 500,000 or three years in jail. Still, that’s all “if.”
Naresh Lamgade, a cybersecurity expert, points out that a lot of other countries don’t joke with data privacy. Their companies pay big fines after data leaks, and regular people can even sue for compensation. “In Nepal, however, regulators show little concern, and public awareness remains very low”.
Dobhan Rai, who is an information technology expert, stated three main reasons behind Nepal’s weak data protection. The first one is the lack of a privacy culture. Secondly, low public awareness about data misuse. And the third reason is poor institutional accountability.
So What Needs to Change?
Experts keep saying the same things: to protect the privacy of citizens, there should be stricter laws in place. Organizations need to be accountable for how they handle people’s data and digital safety. Also, people need to be aware of the importance of keeping their personal information private and secure.
Nepal has to set strict data protection laws. In addition, there should be fines for organizations who fault these rules and those responsible for data breaches should be held accountable.
Right now, most citizens don’t even know why their personal information matters, never mind the risks if it gets out. The government should learn from past slip-ups and make changes so there won’t be a repeat of those incidents.
If this cycle of negligence keeps going, each new breach puts more people at risk of fraud, identity theft, harassment, etc. Without real action, Nepal’s digital future isn’t just uncertain, it’s wide open to trouble.