Published August 2026. Based on the National Cyber Security Centre’s reported findings and Have I Been Pwned’s own published announcement. Where reporting and the underlying evidence disagree, this article says so.
You may have seen the headline: 135 Nepal government email accounts found in a data breach, including addresses at the Prime Minister’s Office, Home Ministry, Finance Ministry and Foreign Ministry.
The number is real and officially sourced. But what it actually means is not what most people are assuming — and getting that wrong leads to the wrong response. Here is the accurate version, and what you should genuinely do about it.
What Actually Happened
The Part Almost Everyone Is Getting Wrong
This is the most important paragraph on this page.
✗ What it does NOT mean
It does not mean Nepal’s government mail servers were hacked. It does not mean an attacker broke into government systems, and it does not by itself mean state records were exposed.
✓ What it DOES mean
135 government email addresses turned up in breaches of other companies’ services — places where civil servants signed up using their work email, plus leaked credential lists and infostealer logs.
Have I Been Pwned holds third-party breach data. That is its entire design. HIBP’s own documentation states plainly that finding your organisation’s addresses in its database does not mean your organisation was breached. A government officer who registered at a social network, a design tool or a shopping site with their gov.np address, and that service was later breached, is exactly how an address lands in this count.
Two Numbers Worth Understanding
| Claim | Status |
|---|---|
| Nepal joined Have I Been Pwned; NCSC is the onboarded agency; 47th government | Confirmed by HIBP’s own published announcement — a first-party source. |
| 135 compromised government accounts | Officially attributed but single-sourced. It comes from NCSC’s own preliminary study, relayed through one media house. No second outlet did an independent count, and no methodology was published. |
| The scope of “135” | Reported for the nepal.gov.np domain specifically — the shared civil-service mail domain. Nepal has many other .gov.np subdomains, so the real total across all government domains is likely higher, not lower. |
| “Breaches will now be detected as soon as they happen” | Overstated. HIBP alerts when a breach corpus is ingested and processed — often months or years after the original compromise. It is not real-time attack detection on Nepali systems. |
| Whether the breaches are recent or old | Not published. No breakdown was given of which breaches the 135 came from. That distinction decides whether this is urgent or largely historic. |
What an Attacker Can Actually Do With This
There are two very different attack routes, and mixing them up leads people to defend against the wrong one.
Route 1: Take over the real account
If a leaked password still works on the government mailbox, the attacker logs in. Email then arrives from a genuinely legitimate address, passes every technical check, and may even continue a real conversation thread. This is the dangerous scenario, and password reuse is what enables it.
Route 2: Just pretend
Far more commonly, the attacker never touches the account at all. They create a lookalike address, spoof a display name, or set the reply-to elsewhere. The mailbox appearing in a breach list simply tells them which names and offices to impersonate convincingly.
Once either route works, the standard playbook follows: threats of legal action to create panic, requests for confidential documents, fake login pages harvesting your password, and requests for an OTP, password or personal details.
🤝 Got a suspicious email you are not sure about?
Send us the details before you click anything — Digital Solution will help you check whether it is genuine, and what to do if you already responded.
If You Receive an Email From a Government Address
✅ The four checks that actually work
- Do not open the link. Hover first and read the real destination. A government service will not host its login on a random domain.
- Do not download the attachment — particularly anything ending .zip, .exe, .scr, or an Office file that asks you to enable macros.
- Verify through a number you found yourself. Not the number in the email. Look up the office’s published number and call that.
- Never reuse a password. This is the one that stops the whole attack chain, not just this email.
If You Work for a Government Office
The 135 figure is not an abstraction for you — your address may be one of them.
- Change your government mailbox password today, to something you have never used anywhere else.
- Stop using your work address for personal signups. Every registration at a shopping site, social platform or free tool puts the address into someone else’s security posture.
- Enable two-factor authentication wherever the system supports it. A leaked password alone then gets an attacker nowhere.
- Check every other account that shared that password — the leaked credential is only worth what it still unlocks.
- Use a password manager. The instruction “use a different password everywhere” is impossible to follow by memory, which is precisely why people reuse.
- Report anything suspicious internally rather than quietly deleting it. If your account is being impersonated, colleagues need to know.
How to Check Your Own Email
The same tool NCSC used is free and public. Go to haveibeenpwned.com, enter your email address, and it will list the known breaches your address appears in.
The Genuinely Good News
It is worth saying clearly: joining HIBP is a sensible, low-cost, correct decision, and the fact that a number came out within days shows the service is being used rather than announced. Nepal is one of 47 governments doing this. The finding is a hygiene audit, and every organisation that runs one finds something.
The reasonable criticism is not that 135 accounts were found. It is that the number was released without saying which breaches they came from or how old they are — which is exactly the information that would tell citizens whether to be worried today.
What Could Not Be Verified
In the interest of not repeating things we could not stand behind:
- No official press release from NCSC, the Ministry of Communication and Information Technology, or the Nepal Police Cyber Bureau confirming the 135 figure could be found. The only official voice is the Director quoted in the press.
- No independent corroboration of the count, and no published methodology.
- No breakdown of which breaches or what period the addresses came from.
- Reports of a phishing wave conducted in the name of the PM’s Office and senior officials were described in coverage, but we found no incident report or sample corroborating it.
Frequently Asked Questions
Were Nepal’s government email servers hacked?
There is no evidence of that in this finding. The 135 addresses appeared in breaches of third-party services, which is what Have I Been Pwned collects. The risk arises if those leaked passwords were reused on government accounts.
What is Have I Been Pwned?
A free service that collects data from publicly known breaches and lets you check whether your email address appears in any of them. It offers governments free monitoring of their own domains; Nepal is the 47th to join.
Which agency joined it?
Nepal’s National Cyber Security Centre (NCSC), onboarded on 3 August 2026.
Is 135 the total number of affected government accounts?
It was reported for the nepal.gov.np domain. Nepal operates many other .gov.np domains, so the figure across all government domains is likely higher.
Can I trust an email from a gov.np address now?
Treat the sender address as one weak signal, not proof. An address can be genuine while the message is not — and a convincing fake needs no compromise at all. Verify by phone using a number you looked up yourself.
How do I check if my email was in a breach?
Enter your address at haveibeenpwned.com. Never enter a password anywhere claiming to check it.
I already clicked a suspicious link. What now?
Change that password immediately from a different device, change it anywhere else you reused it, enable two-factor authentication, and watch your accounts. See our guide on what to do after online fraud in Nepal.
Does this mean my personal data held by the government leaked?
Nothing in this finding shows that. It concerns officials’ email addresses appearing in other companies’ breaches.
Sources
- Troy Hunt, “Welcoming the Nepalese Government to Have I Been Pwned”, 3 August 2026 — first-party confirmation of the onboarding.
- The Kathmandu Post and Kantipur, 6 August 2026 — reporting of NCSC’s preliminary study and the 135 figure, quoting NCSC Director Raj Kumar Maharjan.
- Have I Been Pwned FAQs — on what appearance in the database does and does not indicate.
Related Reading
- What to do after online fraud in Nepal
- Online job scam warning signs
- Nepal’s umbrella technology and cybersecurity law
- Nepal’s digital identity systems explained
Disclaimer: Digital Solution Nepal is an independent educational and digital-service assistance website, not a government body. This article summarises published reporting and first-party announcements as of August 2026; details may develop. For an active security incident, contact the Nepal Police Cyber Bureau or your organisation’s IT authority.

