Last updated: 20 August 2026. All findings below come from TechPana’s Dark Files investigation published 3 Bhadra 2083 (19 August 2026), researched by Hikmat Acharya. Digital Solution has not independently accessed or verified the underlying dataset — we are reporting and explaining their published findings.
🗂️ सम्बन्धित: Nepal’s government email breach, explained
Quick answer: The Nepal bank data leak reported by TechPana involves more than 9,000 sensitive login records tied to 18 of Nepal’s 20 commercial banks circulating on the dark web — staff, system administrators and customers. Around 600 of those accounts relate to banks’ internal systems. This is not the same as saying the banks were hacked: the report attributes the leaks to password reuse and staff carelessness, not to a breach of core banking systems. Your money is not automatically at risk, but your exposure to convincing, well-informed phishing just went up. The practical response is in the checklist below.
Key takeaways
- 18 of 20 commercial banks appear in the dataset; 16 had employee and system-admin records, the other two only customer records.
- 1,676 credential records were analysed in detail, resolving to 569 unique accounts — the same accounts leaking repeatedly.
- Nabil, Rastriya Banijya and Nepal Bank together account for about 46 percent of the analysed data.
- 25.4 percent of the leaked passwords were rated very weak — names and addresses with 123 or 678 tacked on. Average length was 12.3 characters.
- Most leaked logins point to Microsoft 365 / Azure AD and office webmail, then HR systems, core banking and e-banking portals — plus 11 records tied to Nepal Rastra Bank’s financial reporting portal.
- System administrator accounts leaked at four banks. One Sanima admin account appeared five separate times.
What was actually found
TechPana’s Dark Files series went looking for Nepali banking credentials being traded on the dark web. The headline number from the first instalment: over 9,000 sensitive login records connected to staff, system administrators and customers of Nepal’s commercial banks, of which roughly 600 accounts are tied to banks’ internal systems rather than customer-facing ones.
Of the country’s twenty commercial banks, sixteen had employee or system-administrator data in the set. The banks named in the report are Nepal Bank, Rastriya Banijya Bank, Krishi Bikas Bank (ADBL), Standard Chartered Nepal, Prime Commercial, Sanima, Himalayan, Nabil, Kumari, NMB, Global IME, Laxmi Sunrise, Prabhu, Citizens Bank International, NIC Asia and Nepal Investment Mega.
Records per bank, as tallied by TechPana
| Bank | Credential records |
|---|---|
| Nabil Bank | 128 |
| Rastriya Banijya Bank | 60 |
| Nepal Bank Limited | 56 |
| Sanima Bank | 52 |
| NMB Bank | 50 |
| Himalayan Bank | 44 |
| Kumari Bank | 43 |
| Citizens Bank International | 31 |
| Prabhu Bank | 31 |
| NIC Asia Bank | 30 |
| Krishi Bikas Bank (ADBL) | 20 |
| Standard Chartered Nepal | 20 |
| Global IME, Prime Commercial, Nepal Investment Mega, Laxmi Sunrise | 1 each |
These are counts of leaked credential records in the analysed sample, not counts of affected customers, and not a ranking of which bank is “least safe”. A bank with more staff and more third-party integrations will naturally surface more records.
Which systems the leaked logins open
The credentials are not all equal. Ranked by how often they appeared, per the report:
| System the login belongs to | Why it matters |
|---|---|
| Microsoft 365 / Azure AD and office webmail (most common) | Email is the reset route for almost everything else, and the launchpad for internal phishing |
| HR systems | Staff personal data, salary and identity documents |
| Core banking | The ledger itself — the most sensitive tier |
| E-banking portals | Customer-facing transaction systems |
| Nepal Rastra Bank financial reporting portal (11 records) | Regulatory reporting submitted in a bank’s name |
Notice the order. The most-leaked category is ordinary office email — the account most staff think of as harmless.
The nuance that most reposts will drop
“Bank passwords on the dark web” reads like the banks were broken into. The report itself says something different and more mundane — the leaks are attributed to employee and administrator carelessness, above all password reuse.
This is how the overwhelming majority of corporate credentials reach dark web markets anywhere in the world:
- Infostealer malware on a personal device. Someone installs a cracked app, a fake installer or a dubious browser extension at home; the malware scrapes every password saved in the browser — including the work ones — and ships them to a market.
- A third-party site gets breached. A staff member signed up somewhere with their office email and the same password they use at work. That site is hacked; the pair now works on the bank’s webmail too.
- Phishing. A convincing login page harvests the credential directly.
The report documents exactly this reuse pattern: bank staff using their official email address and the same password to log in to unrelated third-party platforms. That is why the same accounts appear again and again — 1,676 records collapsing down to 569 real accounts.
So the honest framing is: this is a discipline failure, not necessarily a systems failure. That is not reassuring. Discipline failures are how most real intrusions start.
Why the system admin accounts matter far more
Buried in the numbers is the finding that deserves the most attention. Four banks — Sanima, Kumari, NIC Asia and Prime Commercial — each had a system administrator or IT staff account in the leak.
An ordinary staff email is bad. An administrator account is a different category altogether, because that level of access typically includes core banking systems, network management, the ability to create new users, and the ability to reset other employees’ passwords. One leaked admin credential can, in principle, become access to everything the admin can reach.
The report notes that in Sanima’s case a single admin account surfaced five separate times, and that the account carried access to two third-party project platforms as well as three of the bank’s own systems.
There is one more detail worth flagging: Krishi Bikas Bank uses a .gov.np domain. Twenty of its email accounts were found, leaked a combined 119 times — government-domain credentials in a public market. Nepal has been here before, as our coverage of the government email breach showed.
What this means for you as a customer
Be clear about the actual risk, because both panic and complacency are wrong here.
What this does not mean: nobody can move money out of your account with a leaked staff webmail password. Transfers still require your own credentials, your device and your OTP or MPIN.
What it does mean: customer records are in the dataset too, and information that looks like it came from inside a bank makes social engineering dramatically more effective. The dangerous call is not “give me your PIN”. It is the one that already knows your name, your branch, your account type and a recent transaction — and then asks you to confirm an OTP to “block a suspicious transfer”.
That is the threat this leak actually raises, and it is the one you can defend against for free.
Seven things to do this week
- Change your e-banking and mobile banking password — and make it one you use nowhere else. If you reused it anywhere, change it there too.
- Turn on every alert your bank offers. SMS and push notifications for debits mean an unauthorised transaction is something you learn in seconds, not at month end. If you run a shop, the same logic applies to QR payment voice notifications.
- Check your email against a breach database. haveibeenpwned.com is the standard free tool; it tells you which breaches your address appears in so you know which passwords to retire.
- Use a password manager. The only realistic way to have a different strong password everywhere is to stop trying to remember them. This is the single highest-value change on this list.
- Never approve an OTP you did not trigger. An OTP arriving out of nowhere is not an error — it means somebody is trying your credentials right now. Do not read it out. Change your password instead.
- Lower your transaction limits to what you actually need. Limits are adjustable, and a lower ceiling caps the damage of a bad day. Our guide to mobile banking transaction limits covers what NRB permits.
- Read your statement monthly. Small unexplained debits are usually the first sign, not a large one.
If you run a business, the same mistake is in your office
It is easy to read this as a banking story. It is not. The behaviour that produced it — one password, reused across the work email and a dozen random signups — is standard practice in most Nepali offices, including ones far less defended than a commercial bank.
Four things worth doing this month:
- Company email accounts must not share passwords with anything else. Make it a written rule, then verify it rather than assume it.
- Turn on two-factor authentication on your business email and any admin console. A leaked password without the second factor is usually a dead end.
- Revoke access the day someone leaves. Dormant accounts with live credentials are how old staff turn into current risks.
- Separate admin accounts from daily-use accounts. Nobody should be reading email from an account that can reset everyone else’s password.
If money does go missing
Speed matters more than anything else. Do these in order:
- Call your bank’s helpline immediately and ask them to freeze the account or card. Note the time and the reference number.
- Follow up in writing at your branch the same day, with screenshots, transaction IDs and timestamps.
- File a complaint with Nepal Police’s Cyber Bureau with the same evidence.
- Escalate to Nepal Rastra Bank if the bank does not resolve it within its stated timeline.
- Keep everything. Every screenshot, every reference number, every name you spoke to. Disputes are decided on documentation.
🔐 अफिसको email र password सुरक्षित छ कि छैन?
कम्पनीको email मा 2FA राख्न, password manager सेटअप गर्न वा कर्मचारीलाई cyber hygiene तालिम दिन — Digital Solution को team सँग कुरा गर्नुहोस्।
Frequently asked questions
Were Nepali banks hacked?
The investigation does not claim that. It reports credentials found circulating on the dark web and attributes them to password reuse and staff carelessness rather than to a breach of core banking systems. Leaked credentials are a serious warning sign, but they are not by themselves evidence that a bank’s systems were penetrated.
Is my money at risk because of this leak?
Not directly. A leaked staff webmail password cannot move money out of your account — that needs your own credentials, device and OTP. The realistic risk is far better-informed phishing and impersonation calls.
Which banks were named in the report?
Sixteen banks had staff or admin records: Nepal Bank, Rastriya Banijya, Krishi Bikas (ADBL), Standard Chartered, Prime Commercial, Sanima, Himalayan, Nabil, Kumari, NMB, Global IME, Laxmi Sunrise, Prabhu, Citizens, NIC Asia and Nepal Investment Mega. Two further banks appeared with customer data only.
How do I check if my own email has been leaked?
Use haveibeenpwned.com, the standard free breach-checking service. Enter your email address and it will list the known breaches containing it. Then change the password anywhere you reused it.
How did these passwords get out?
Overwhelmingly through reuse and infostealer malware — a work password saved in a browser on a personal device, or the same password used on a third-party site that was later breached. Around a quarter of the leaked passwords were rated very weak.
What should I do if I get a call from someone claiming to be my bank?
Hang up and call the number printed on your card or on the bank’s official website. Never share an OTP, MPIN or password, and never approve a login request you did not initiate — no genuine bank employee will ever ask for those.
Does a strong password alone protect me?
No. A unique password plus two-factor authentication is the combination that works. A strong password reused in ten places is only as safe as the weakest of those ten sites.
The bottom line
The most useful number in this Nepal bank data leak report is not 9,000. It is 25.4 percent — the share of leaked banking passwords that were weak enough to guess. That figure describes a habit, not an attack, and habits are fixable. Give your bank login a password you use nowhere else, turn on alerts and two-factor authentication, and stop trusting phone calls that already seem to know you. Then send this to whoever manages your office email, because the same habit is almost certainly sitting there too.
Digital Solution disclaimer: Digital Solution Pvt. Ltd. is an independent private company and is not affiliated with, endorsed by or acting on behalf of TechPana, Nepal Rastra Bank or any bank named in this article. All findings are attributed to TechPana’s Dark Files investigation of 19 August 2026; we have not independently accessed the underlying dataset and make no claim about any bank’s current security posture. Banks named here have not, at the time of writing, been shown to have suffered a breach of their core systems. Verify anything security-related directly with your own bank.

