Trading at NEPSE came roaring back after a ransomware attack forced a rare shutdown. With systems restored, turnover hit NRs 7.05 billion as regulators pressed for answers on the breach.
Screens lit up again at the Nepal Stock Exchange on Tuesday. Just a day earlier, a ransomware attack had frozen the market and left 72 brokerage firms unable to trade. The shutdown came fast. A cyberattack hit Data Hub Pvt. Ltd.'s data center, and NEPSE stopped all trading to keep things fair. This kind of halt is almost unheard of for the exchange.
The trouble started early Sunday. Data Hub warned YCO Pvt. Ltd.-the company behind the Trading Management System (TMS) used by most brokers-that its systems had been hit. Out of 92 licensed brokerage firms, 72 depend on this TMS. NEPSE decided to close the whole market. Letting only some brokers trade would have caused confusion and opened the door to manipulation. According to Kathmandu Post, the ransomware didn't just hit the TMS. It also affected CDSC systems, payment gateways, and other connected services. The attack showed how much risk comes from relying on a single digital hub.
By Tuesday, technical teams had brought the systems back online. NEPSE said trading through the TMS was back to normal. The market jumped. The NEPSE index rose 7.06 points to 2,654.28. Turnover climbed to NRs 7.05 billion, up from Rs 6.74 billion the previous session. Investors traded 215.9 million shares across 356 securities. Out of those, 137 companies gained, while 131 fell. The recovery used backup data from the disaster recovery centre in Butwal. Forensic checks and technical audits are still underway to make sure the systems are safe, according to local media.
Mid-Solu Hydropower led the gains, up 14.99% to NRs 606 per share. First Microfinance rose 7.75% to Rs 820. On the losing side, Snow Rivers dropped 8.23% to Rs 970, and Narayani Development Bank fell 6.96% to NRs 749. Hathway Investment saw the most trading, with Rs 444 million in shares changing hands. Himalayan Distillery and Ghalemdi Hydropower followed.
Il caso NEPSE dimostra come la resilienza delle infrastrutture digitali finanziarie sia oggi una priorità assoluta per la sicurezza nazionale e la tutela degli investitori. L'adozione di standard minimi di sicurezza informatica, come raccomandato dall'Agenzia per la Cybersicurezza Nazionale, è fondamentale per prevenire interruzioni sistemiche nei mercati.
Indagine sulle cause e risposta delle autorità
As trading resumed, the Securities Board of Nepal (SEBON) moved quickly. NEPSE was told to investigate what caused the shutdown and report back by September 28. SEBON set up a five-member inspection team, led by a deputy executive director, to look into both technical and procedural failures. The regulator wants to know what went wrong, how to fix it, and how to make the market stronger against future cyberattacks.
NEPSE and Data Hub say the systems are now stable, but the full impact of the ransomware is still being checked. It's not yet clear which systems were accessed or if any sensitive data was leaked. These questions are urgent, echoing concerns raised in a recent analysis about the risks exposed by such attacks on financial infrastructure.
Nuove regole fiscali e impatto sul mercato
The reopening came as new, lower capital gains tax rates on share trades took effect. The government had raised rates earlier in the fiscal year, but now cut them to 3.75% and 5%. The new rates started Tuesday and helped boost trading. Seven of the 13 sector indices rose, with the Other sector up 1.36%.
This incident shows how fragile digital infrastructure can be in modern financial markets. When one data center can freeze almost the whole trading system, strong cybersecurity and backup plans are a must. The market's quick rebound shows investors can regain confidence fast. Now, regulators face a real test: can Nepal's securities sector learn from this breach and build real resilience, or will the next attack shut down trading all over again?