Notify NepalLoading...



Tribhuvan University’s first-year undergraduate examinations are currently underway. Last week, colleges across the country were busy distributing admit cards to students. However, while institutions focused on making admit card distribution more convenient, they largely overlooked data security and privacy.
Padma Kanya Campus in Bagbazar publicly exposed the personal data of 1,364 students by posting their admit cards on social media. The post was removed after media reports highlighted the issue. By then, however, students who had scanned the QR code had already gained access to other students’ symbol numbers, registration numbers, and academic records.
Despite the seriousness of the breach, the campus administration appeared to treat it lightly. Campus Chief Jayalakshmi Pradhan said the intention was simply to make the process easier for students. Some staff members even dismissed the concern, commenting that “it’s just a photo and a name.”
The administration further claimed that Padma Kanya was not alone in adopting this practice, arguing that other educational institutions also distribute admit cards in the same manner. “We are not the only ones. I won’t name them, but other colleges are doing the same. You just happened to find Padma Kanya,” one administrative staff member told Onlinekhabar.
The incident reflects the limited understanding of data privacy and sensitivity among leaders of Nepal’s educational institutions.
A few weeks earlier, another major incident raised concerns about Nepal’s digital security. Software developer Nirdesh Subedi was found to have cloned the Nepal government’s official Nagarik App web portal and hosted it on his personal domain.
He used an older version of the Nagarik App interface on his personal website. When users searched for “Nagarik App login,” Subedi’s website appeared among the top search results on Bing. Google Chrome, however, flagged the site as dangerous and warned users before allowing access.
The Nagarik App contains highly sensitive personal and government records, including citizenship certificates, passports, PAN cards, and educational certificates. Unauthorised cloning of such a platform significantly increases the risk of data theft. The incident prompted widespread criticism of the government’s cybersecurity practices and its handling of sensitive data.
Experts warned that cloned websites are commonly used in phishing attacks to trick users into revealing login credentials, making such incidents a serious cybersecurity threat. Cyberattacks targeting Nepal’s government digital systems are not new. Security weaknesses have repeatedly been exploited because lessons from previous incidents have not been adequately implemented.
Government websites have increasingly become easy targets due to weak security infrastructure. On February 13, 2025, hackers gained unauthorised access to 21 subdomains under the Koshi Provincial Government. A hacking group known as YNR claimed responsibility by publishing evidence of the breach on the Zone-H portal.
Exactly one month later, on March 26, 2025, the government’s Hello Sarkar website, operated under the Office of the Prime Minister and Council of Ministers, was also compromised. A group calling itself Ghudra claimed it released data through the “Breach Forums” platform after alleging that the government had ignored its attempts to establish contact.
The attacks continued.
On April 23, 2025, the Nepal Police Headquarters website also suffered a security breach. A hacking group known as Kaju reportedly obtained citizenship records of around two million Nepali citizens and offered the data online for US$7,000. The recent cloning of the Nagarik App’s web version is viewed as another example in this continuing pattern of cybersecurity failures.
Concerns over data misuse are not limited to online platforms. Physical businesses, including supermarkets and cafés, are also collecting customers’ personal information without adequate transparency. Major supermarket chains such as Bhatbhateni and Big Mart routinely ask customers for their names and phone numbers when processing bills or offering membership programs. Many customers complain that they receive little or no meaningful benefit in exchange for providing sensitive personal information.
Similarly, many cafés and restaurants require customers to submit their phone numbers before granting access to Wi-Fi. Instead of simply providing a password, many establishments use captive portals that force customers to enter their mobile numbers before accessing the internet.
Collecting personal information in exchange for basic services raises significant privacy concerns. Most businesses do not clearly inform customers that they are collecting and storing their data. If these businesses suffer software vulnerabilities or data breaches, the personal information they have collected could easily be exposed or misused.
Moreover, few businesses explain how they secure the personal data they collect in exchange for free Wi-Fi or minimal discounts. Cybersecurity experts warn that weak data protection practices directly threaten citizens’ privacy. Using personal information without consent often causes unnecessary inconvenience and harm.
A recent example involved the widely discussed “SG Update” incident.
Last Baisakh, at 10:11 p.m., around 4,000 mobile users received unsolicited promotional messages from the “SG Update” shortcode asking them to subscribe to a YouTube channel. Recipients criticised the late-night advertisements on social media, questioning how their personal phone numbers had been obtained despite never sharing them with the sender.
Following widespread criticism, YouTuber Sagar Chhetri, who operates the channel, issued an explanation, attributing the incident to a technical error. “While sending updates to participants of our event, a technical issue caused unnecessary contacts to be added to the system,” Chhetri wrote on LinkedIn. “One employee’s personal phone contacts were accidentally synchronised, resulting in messages being sent to people who had never given permission.”
Similar concerns arise during election periods, when political parties and candidates frequently send bulk campaign text messages to voters without obtaining prior consent. Cybersecurity expert Naresh Lamgade says weak data protection practices make it easy for voters’ phone numbers to end up in the hands of campaign organisations.
Lamgade, founder of cybersecurity firm Bugv, said, “Once a database is breached, everyone’s data can leak. People often don’t realise the value of their own data, so they don’t pay attention. In many countries, companies face heavy fines after data breaches, and affected citizens can sue for compensation. In Nepal, however, regulators and responsible institutions show little concern, and public awareness remains very low.”
According to him, misuse of personal data is becoming increasingly common across many industries. “We once heard from a celebrity whose contact information was leaked from a delivery company’s database. The person received so many unwanted calls and messages that they eventually had to change their SIM card. That’s just one example.”
Ride-sharing and delivery companies, he added, possess highly sensitive information such as customers’ home addresses and phone numbers, making stronger data protection essential. Information technology expert Dobhan Rai identifies three main reasons behind Nepal’s weak data protection practices.
First, Nepali society has not yet developed a strong culture of respecting privacy and personal space. Second, public awareness remains low regarding how digital data—including sensitive personal information—can be misused and what consequences such misuse can have. Third, many institutions lack professional accountability and a culture of responsibility.
According to Rai, numerous incidents clearly demonstrate the risks created by this combination of negligence and poor awareness. She noted that in developed countries, citizens are highly conscious of their data privacy rights, while governments enforce strict data protection laws that impose substantial fines on organisations responsible for data breaches. Victims also have legal avenues to seek compensation.
Nepal, by contrast, lacks clear and robust legal regulations governing data protection, allowing organisations that possess citizens’ personal data to escape accountability. Rai argues that safeguarding citizens’ privacy in the digital age requires strong legal frameworks, institutional accountability, and greater public awareness.
The growing lack of data security has also contributed to a rise in cybercrime. According to statistics provided by Nepal Police’s Cyber Bureau to Onlinekhabar, 20,526 cybercrime complaints were registered during the last fiscal year. Of these, 13,230 involved electronic offences, while 7,296 were related to cyber fraud.
In fiscal year 2081/82 (2024/25), authorities received 18,926 complaints, including 11,186 electronic offence cases and 7,740 cyber fraud complaints. In fiscal year 2080/81 (2023/24), the total number of complaints stood at 19,730, comprising 15,576 electronic offences and 4,154 cyber fraud cases.
Although the yearly figures fluctuate, both the statistics and recent incidents indicate that cybersecurity and data protection are becoming increasingly critical issues in Nepal.
The post Weak data protection exposes Nepal to growing cybersecurity risks appeared first on OnlineKhabar English News.
21 Shrawan, 2083