Nepal Government Portal Allegedly Breached: 462,600 Citizens’ Data Reportedly Listed for Sale on Dark Web
A new dark web forum post claims to offer hundreds of thousands of Nepali citizens’ personal records, continuing a troubling pattern of breaches targeting the country’s digital infrastructure.
Kathmandu — September 2026
A threat actor operating under the alias “3r3bu5,” claiming affiliation with a group calling itself “Team Erebus,” has posted on a known cybercrime forum advertising what they describe as personally identifiable information (PII) belonging to approximately 462,600 Nepali citizens, allegedly sourced from a compromised government (.gov.np) portal. The listing, posted this week, includes claims of citizenship IDs and other identity documents, with the seller asking roughly $1,000 for the full dataset.
As of publication, the claim has not been independently verified by Nepal’s National Cyber Security Centre (NCSC) or third-party security researchers. Breach listings of this kind should be treated with caution: sellers on underground forums frequently exaggerate scope, recycle data from earlier incidents, or fabricate claims entirely to defraud other criminals.
What the Post Claims

According to the forum listing, the actor says they compromised a Nepali government portal and obtained a large tranche of PII, including scanned citizenship documents and other identifying information belonging to “mixed” citizens, reportedly including some public figures. The post includes a set of sample document images intended to lend credibility to the claim, along with taunting language aimed at Nepali authorities and an invitation for interested buyers to make contact privately.
This report does not reproduce, verify, or link to any of the leaked material, the seller’s contact details, or the forum itself — standard practice when covering breach claims, to avoid amplifying access to stolen data.
Part of a Broader Pattern
If confirmed, this would be at least the fourth major breach involving Nepali government-linked citizen data since early 2025:
- March 2025 — “Hello Sarkar” portal: A group calling itself “Ghudra,” claiming ties to the Russian-linked “Fancy Bear” (APT28), compromised the Prime Minister’s Office’s citizen service portal. The group listed the full database for sale at $1,000, with an additional “live shell access” option priced at $1,300. Leaked data reportedly included names, emails, usernames, phone numbers, passwords, device IDs, photos, and physical addresses.
- Late 2025 — Nepal Police website: A group identified as “Kazu” claimed responsibility for exfiltrating more than 2 million records, including citizenship certificates, passport scans, and biometric-linked data, which were then advertised on dark web marketplaces for roughly $7,000.
- 2025, cumulative impact: Security researchers estimate that across multiple incidents in 2025 alone, the personal records of more than 5 million Nepali citizens were exposed including citizenship numbers, academic records, phone numbers, and scanned identity documents largely attributed to weak database configurations, unpatched legacy systems, and insufficient encryption across government IT infrastructure.
- August 2026 — Government email exposure: After Nepal joined Have I Been Pwned, a global breach-tracking service, the NCSC identified 135 compromised “nepal.gov.np” government email accounts, part of an effort to get real-time visibility into where government data has been leaking.
Cybersecurity commentators have repeatedly flagged the same underlying issues: Nepal’s rapid digital transformation including online citizenship portals, national ID systems, and e-governance platforms under the Digital Nepal Framework has outpaced the legal and technical safeguards needed to protect the data those systems collect.
Why This Matters for Ordinary Citizens
Citizenship and national ID data is uniquely sensitive because, unlike a password, it cannot be reset. When exposed, it can be used for:
- Identity theft and fraud: opening fraudulent bank accounts, SIM cards, or loans in a victim’s name
- Phishing and impersonation scams: Nepal’s NCSC has already documented fraudulent emails impersonating senior police and PM’s Office officials
- SIM-swapping attacks: using leaked phone numbers and personal details to hijack mobile accounts
- Sextortion and targeted harassment: particularly where photos and addresses are included in leaked datasets
Security expert Ribash Neupane, commenting on an earlier Nepali government breach, noted that when attackers steal citizens’ digital assets at this scale, it puts everything at risk from financial systems to physical safety since the same data trades hands repeatedly for profit.
Government Response
The NCSC has taken some recent steps to improve visibility into breaches, including joining Have I Been Pwned and deploying dark-web monitoring tools such as CTM360, provided through the International Telecommunication Union, to track illicit trading of state data. However, transparency advocates, including Transparency International Nepal, have criticized the broader pattern of delayed disclosure and inconsistent compliance with the NCSC’s own 102-point security advisory issued in January 2025.
Nepal currently lacks a comprehensive legal framework setting clear technical and operational standards for identity data management, despite the existence of the National Identity Card and Registration Act, 2076.
What Affected Citizens Can Do
- Avoid clicking links or downloading attachments from unsolicited emails claiming to be from government agencies, police, or the PM’s Office
- Enable multi-factor authentication on any accounts linked to a phone number, email, or ID that may have been exposed
- Be cautious of unexpected calls or messages referencing personal details like citizenship numbers, as these can lend false legitimacy to scam attempts
- Monitor for signs of identity misuse, such as unfamiliar accounts or loan applications
This article covers an unverified breach claim posted to a dark web forum. It does not link to, reproduce, or independently confirm the leaked data referenced in the listing.