135 Nepal Government Emails Found in Breach Data: What It Really Means

135 Nepal government gov.np email addresses found in third party data breaches

Published August 2026. Based on the National Cyber Security Centre’s reported findings and Have I Been Pwned’s own published announcement. Where reporting and the underlying evidence disagree, this article says so.

You may have seen the headline: 135 Nepal government email accounts found in a data breach, including addresses at the Prime Minister’s Office, Home Ministry, Finance Ministry and Foreign Ministry.

The number is real and officially sourced. But what it actually means is not what most people are assuming — and getting that wrong leads to the wrong response. Here is the accurate version, and what you should genuinely do about it.

What Actually Happened

3 August 2026Troy Hunt, who operates Have I Been Pwned (HIBP), publishes “Welcoming the Nepalese Government to Have I Been Pwned.” Nepal’s National Cyber Security Centre (NCSC) is onboarded — the 47th government to join HIBP’s free service for government domains.
Immediately afterNCSC runs its first domain-wide search on the government mail domain and carries out a preliminary study.
6 August 2026Kantipur and The Kathmandu Post report the result: 135 addresses on the nepal.gov.np domain appear in breach data. NCSC Director Raj Kumar Maharjan is quoted. Ministries named include the Office of the Prime Minister and Council of Ministers, Home, Finance and Foreign Affairs.
These are one story, not two. The 135 figure is a direct product of joining HIBP — it is what the first search returned. Anyone presenting the HIBP onboarding and the 135 accounts as two separate events has conflated a single sequence.

The Part Almost Everyone Is Getting Wrong

This is the most important paragraph on this page.

✗ What it does NOT mean

It does not mean Nepal’s government mail servers were hacked. It does not mean an attacker broke into government systems, and it does not by itself mean state records were exposed.

✓ What it DOES mean

135 government email addresses turned up in breaches of other companies’ services — places where civil servants signed up using their work email, plus leaked credential lists and infostealer logs.

Have I Been Pwned holds third-party breach data. That is its entire design. HIBP’s own documentation states plainly that finding your organisation’s addresses in its database does not mean your organisation was breached. A government officer who registered at a social network, a design tool or a shopping site with their gov.np address, and that service was later breached, is exactly how an address lands in this count.

So why is this still serious? Because a breached third-party record usually includes a password — and if that officer reused the same password on their government mailbox, an attacker does not need to hack anything. They can simply log in. That is called credential stuffing, and it is the single most common route to a real account takeover. The danger is not the breach itself. The danger is password reuse.

Two Numbers Worth Understanding

ClaimStatus
Nepal joined Have I Been Pwned; NCSC is the onboarded agency; 47th governmentConfirmed by HIBP’s own published announcement — a first-party source.
135 compromised government accountsOfficially attributed but single-sourced. It comes from NCSC’s own preliminary study, relayed through one media house. No second outlet did an independent count, and no methodology was published.
The scope of “135”Reported for the nepal.gov.np domain specifically — the shared civil-service mail domain. Nepal has many other .gov.np subdomains, so the real total across all government domains is likely higher, not lower.
“Breaches will now be detected as soon as they happen”Overstated. HIBP alerts when a breach corpus is ingested and processed — often months or years after the original compromise. It is not real-time attack detection on Nepali systems.
Whether the breaches are recent or oldNot published. No breakdown was given of which breaches the 135 came from. That distinction decides whether this is urgent or largely historic.

What an Attacker Can Actually Do With This

There are two very different attack routes, and mixing them up leads people to defend against the wrong one.

Route 1: Take over the real account

If a leaked password still works on the government mailbox, the attacker logs in. Email then arrives from a genuinely legitimate address, passes every technical check, and may even continue a real conversation thread. This is the dangerous scenario, and password reuse is what enables it.

Route 2: Just pretend

Far more commonly, the attacker never touches the account at all. They create a lookalike address, spoof a display name, or set the reply-to elsewhere. The mailbox appearing in a breach list simply tells them which names and offices to impersonate convincingly.

The practical consequence is the same for you. Whether the message came from a hijacked real account or a convincing fake, you cannot tell from the sender address alone. Which is why the rule below matters more than any technical detail.

Once either route works, the standard playbook follows: threats of legal action to create panic, requests for confidential documents, fake login pages harvesting your password, and requests for an OTP, password or personal details.

🤝 Got a suspicious email you are not sure about?

Send us the details before you click anything — Digital Solution will help you check whether it is genuine, and what to do if you already responded.

📲 WhatsApp: +977 9705433699  Our Services →

If You Receive an Email From a Government Address

✅ The four checks that actually work

  • Do not open the link. Hover first and read the real destination. A government service will not host its login on a random domain.
  • Do not download the attachment — particularly anything ending .zip, .exe, .scr, or an Office file that asks you to enable macros.
  • Verify through a number you found yourself. Not the number in the email. Look up the office’s published number and call that.
  • Never reuse a password. This is the one that stops the whole attack chain, not just this email.
Two additions worth making. First: urgency is the tell. Genuine government correspondence rarely demands that you act within hours or lose something. Threats of immediate legal action, account closure or arrest are social-engineering levers, not administrative practice. Second: no government office will ask for your OTP. Not the bank, not the police, not a ministry. That request alone ends the conversation.

If You Work for a Government Office

The 135 figure is not an abstraction for you — your address may be one of them.

  1. Change your government mailbox password today, to something you have never used anywhere else.
  2. Stop using your work address for personal signups. Every registration at a shopping site, social platform or free tool puts the address into someone else’s security posture.
  3. Enable two-factor authentication wherever the system supports it. A leaked password alone then gets an attacker nowhere.
  4. Check every other account that shared that password — the leaked credential is only worth what it still unlocks.
  5. Use a password manager. The instruction “use a different password everywhere” is impossible to follow by memory, which is precisely why people reuse.
  6. Report anything suspicious internally rather than quietly deleting it. If your account is being impersonated, colleagues need to know.

How to Check Your Own Email

The same tool NCSC used is free and public. Go to haveibeenpwned.com, enter your email address, and it will list the known breaches your address appears in.

What to do with the result: if your address appears, do not panic — most Nepali email addresses of any age appear somewhere. What matters is the follow-up. Change the password for every listed service where you still use that password, and anywhere else you reused it. The listing tells you which of your old passwords is now public.
Only use the official site. Stories like this reliably produce copycat “breach checker” pages that harvest whatever you type. Never enter a password into any site claiming to check whether it was leaked, and treat any “check if your account was hacked” link arriving by email or social media as hostile.

The Genuinely Good News

It is worth saying clearly: joining HIBP is a sensible, low-cost, correct decision, and the fact that a number came out within days shows the service is being used rather than announced. Nepal is one of 47 governments doing this. The finding is a hygiene audit, and every organisation that runs one finds something.

The reasonable criticism is not that 135 accounts were found. It is that the number was released without saying which breaches they came from or how old they are — which is exactly the information that would tell citizens whether to be worried today.

What Could Not Be Verified

In the interest of not repeating things we could not stand behind:

  • No official press release from NCSC, the Ministry of Communication and Information Technology, or the Nepal Police Cyber Bureau confirming the 135 figure could be found. The only official voice is the Director quoted in the press.
  • No independent corroboration of the count, and no published methodology.
  • No breakdown of which breaches or what period the addresses came from.
  • Reports of a phishing wave conducted in the name of the PM’s Office and senior officials were described in coverage, but we found no incident report or sample corroborating it.

Frequently Asked Questions

Were Nepal’s government email servers hacked?

There is no evidence of that in this finding. The 135 addresses appeared in breaches of third-party services, which is what Have I Been Pwned collects. The risk arises if those leaked passwords were reused on government accounts.

What is Have I Been Pwned?

A free service that collects data from publicly known breaches and lets you check whether your email address appears in any of them. It offers governments free monitoring of their own domains; Nepal is the 47th to join.

Which agency joined it?

Nepal’s National Cyber Security Centre (NCSC), onboarded on 3 August 2026.

Is 135 the total number of affected government accounts?

It was reported for the nepal.gov.np domain. Nepal operates many other .gov.np domains, so the figure across all government domains is likely higher.

Can I trust an email from a gov.np address now?

Treat the sender address as one weak signal, not proof. An address can be genuine while the message is not — and a convincing fake needs no compromise at all. Verify by phone using a number you looked up yourself.

How do I check if my email was in a breach?

Enter your address at haveibeenpwned.com. Never enter a password anywhere claiming to check it.

I already clicked a suspicious link. What now?

Change that password immediately from a different device, change it anywhere else you reused it, enable two-factor authentication, and watch your accounts. See our guide on what to do after online fraud in Nepal.

Does this mean my personal data held by the government leaked?

Nothing in this finding shows that. It concerns officials’ email addresses appearing in other companies’ breaches.

Sources

  • Troy Hunt, “Welcoming the Nepalese Government to Have I Been Pwned”, 3 August 2026 — first-party confirmation of the onboarding.
  • The Kathmandu Post and Kantipur, 6 August 2026 — reporting of NCSC’s preliminary study and the 135 figure, quoting NCSC Director Raj Kumar Maharjan.
  • Have I Been Pwned FAQs — on what appearance in the database does and does not indicate.

Related Reading

Disclaimer: Digital Solution Nepal is an independent educational and digital-service assistance website, not a government body. This article summarises published reporting and first-party announcements as of August 2026; details may develop. For an active security incident, contact the Nepal Police Cyber Bureau or your organisation’s IT authority.

Rabin Paudel
Written by

Rabin Paudel

Rabin Paudel is the Founder of Digital Solution, a Content Creator, and an AI Trainer. He shares practical and easy-to-understand content on Artificial Intelligence, Digital Literacy, Online Services, FinTech, and Technology. His mission is to make technology simple, accessible, and useful for everyone.

View all posts by Rabin Paudel →

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top
Quick Access

Quick Go

Jump straight to the most important sections of Digital Solution.

Digital Solution Blog

Technology, AI, Digital Services, Government Updates and Practical Guides for Nepal

Latest Updates

View all