Nepal uncovers 135 compromised government email accounts after joining global breach tracker
Summarized and contextualized by DistantNews.
At a glance
- Nepal has identified 135 compromised government email accounts after joining a global breach tracking portal.
- The compromised accounts, under the 'nepal.gov.np' domain, expose sensitive state records and fuel phishing scams.
- The National Cyber Security Centre is using advanced tools to track leaks and notify affected departments in real-time.
Nepal has uncovered at least 135 compromised official government email addresses within the 'nepal.gov.np' domain, exposing sensitive state information and leading to a surge in high-profile phishing scams nationwide. This revelation came after Nepal officially integrated with Have I Been Pwned, a global portal that monitors domain security and tracks credential leaks.
The National Cyber Security Centre reported that Nepal is now the 47th government entity globally to join the system, allowing state authorities to precisely track when and where official credentials are leaked. Initial findings confirmed that the compromised accounts belong to civil servants in critical institutions, including the Office of the Prime Minister and Council of Ministers, the Ministry of Home Affairs, the Ministry of Finance, and the Ministry of Foreign Affairs.
When official email addresses are compromised, it grants unauthorised actors a doorway into internal networks. This compromises government secrecy, exposes sensitive communication, and provides attackers with legitimate channels to launch sophisticated social engineering campaigns.
Cybersecurity expert Mona Nyachhyon warned that these leaks pose a direct threat to state confidentiality, creating pathways into internal networks for unauthorized actors. This compromises government secrecy, exposes sensitive communications, and enables sophisticated social engineering campaigns. Raj Kumar Maharjan, Director of the National Cyber Security Centre, stated that the agency is actively notifying affected departments and securing vulnerable accounts.
Maharjan explained that the portal provides precise details on leaked email addresses and their sources, enabling real-time alerts to officials, immediate password resets, and damage prevention. The center has enhanced its security measures by employing advanced tools like CTM360, a dark web monitoring tool, and a Security Information and Event Management system. Analysts conduct deep-dive investigations using global threat intelligence to cross-reference suspicious activity against known malicious IP addresses. Despite these efforts, legacy frameworks and outdated software across government agencies remain a significant vulnerability.
Previously, it was exceptionally difficult to obtain concrete data on where and how Nepalโs government records were being stolen. Through this portal, our centre now receives precise details regarding which email address was leaked and from which source. This allows us to alert relevant officials in real time, enforce immediate password resets, and prevent further damage.
Originally published by Kathmandu Post. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.