KATHMANDU- A ransomware attack has been confirmed at the data centre of Data Hub Pvt. Ltd., which hosts Nepal’s stock trading management system, or TMS.
Data Hub officially informed TMS developer YCO Private Limited of the cyberattack in a letter. YCO subsequently notified the Stock Brokers Association of Nepal.
Data Hub said the ransomware attack on the infrastructure operating the TMS was detected at around 5:30 a.m. on Sunday.
The company said it had completed a full system backup at 4 a.m. the same day, shortly before the attack. The backup remains fully secure and isolated.
However, the affected systems have been taken offline because of the risk that the ransomware could spread through interconnected networks. Data Hub said restoring the systems would take some time while forensic analysis and security measures are completed.
Based on information provided by Data Hub, YCO told the brokers’ association that the incident had affected the TMS, systems linked to CDSC, various payment gateways and other interconnected services.
YCO warned that the attack could pose risks to the cybersecurity, regular operation and data integrity of the wider trading ecosystem because the data centre has direct network connectivity with the Nepal Stock Exchange, or NEPSE.
The company said all affected systems had been isolated for security reasons and a full assessment of the damage was underway.
YCO urged the brokers’ association to treat the matter seriously and take immediate action, warning that operating a regular market session under such sensitive circumstances could create further risks.
The letters sent by Data Hub to YCO and by YCO to the association identify the incident as a ransomware attack.
Ransomware is a form of cyberattack involving digital extortion. Cybercriminals use malicious software to encrypt important data, documents and files stored on the computers, mobile devices or servers of individuals, companies or government bodies.
Victims are unable to access their systems or files after an attack and typically receive a threatening message demanding payment in exchange for restoring their data.
Cybercriminals often demand payment through cryptocurrency to conceal their identities and warn that the data will be permanently destroyed or made public if the ransom is not paid.
In the case involving the Nepal Stock Exchange, authorities have not disclosed which ransomware group was behind the attack or how much ransom was demanded.








Comments
Share your opinion or feedback. Please keep comments respectful and constructive.