135 government email addresses compromised. Over 1,500 websites knocked offline by a single DDoS attack. SSL certificates expiring on critical citizen portals and nobody bothering to renew them for days. This isn't some hypothetical worst-case scenario. This is Nepal. Right now.
And the people responsible for keeping our digital infrastructure safe? A significant chunk of them are doing the bare minimum — or less. The negligence of government-appointed technical staff in Nepal has become a genuine threat to every citizen's privacy and security. Not a theoretical risk. A proven, documented, ongoing disaster.
Key Takeaways
- 135 official government email accounts under the nepal.gov.np domain were found compromised in data breaches after Nepal joined the Have I Been Pwned monitoring service.
- Government portals suffered 47 data leaks and 142 data breaches over the last five years, according to the Ministry of Electronics and Information Technology.
- A January 2023 DDoS attack took down roughly 1,500 government websites, and a March 2025 attack crippled over 400 more — both targeting the same vulnerable Government Integrated Data Centre.
- Critical sites like the National ID citizen portal have had expired SSL certificates left unrenewed for days, exposing users to man-in-the-middle attacks.
- Government agencies are increasingly using AI "vibe coding" to build public-facing applications without understanding encryption or security standards, and 62% of AI-generated code ships with critical vulnerabilities.
- Nepal's National Identity Card verification system, designed for 6,000 requests per hour, now struggles to process 600–700 per day due to zero infrastructure investment.
- Nepal scored just 44.99 out of 100 on the 2020 Global Cybersecurity Index, ranking 94th out of 182 countries.
Expired SSL Certificates on Government Portals: The Simplest Job Nobody Does
Let's start with something that should embarrass every IT officer drawing a government salary in Nepal. SSL certificate renewal.
This is not complex work. It's not cutting-edge security research. You get a notification weeks before expiration. You click some buttons. You maybe paste a key. Done. Automated tools can even handle it for you.
And yet, Nepal's citizen-facing portals — including citizenportal.donidcr.gov.np, the National ID registration system — have been caught running with expired SSL certificates. Users visiting these sites get hit with "Your connection is not private" browser warnings. Some push through anyway because they need government services. Others don't know what the warning even means.
Here's what an expired certificate actually does: it breaks HTTPS encryption. Any data you submit — your name, citizenship number, biometric details — can potentially be intercepted through man-in-the-middle attacks. For a government identity portal. Think about that for a second.
The really infuriating part? These certificates don't expire without warning. Every certificate authority sends multiple reminders. The technical staff knows. They just... don't act. Not for hours. For days.
Raj Kumar Maharjan, Director of the National Cyber Security Centre, has publicly acknowledged that legacy frameworks and outdated software remain widespread across government agencies. But acknowledging the problem and fixing it are two very different things.
1,500 Websites Down: When the Whole Infrastructure Collapses Under Load
In January 2023, a DDoS attack hit the Government Integrated Data Centre (GIDC) at Singha Durbar and knocked approximately 1,500 government websites offline. Immigration systems at Tribhuvan International Airport failed. Officers had to pull out paper records — at an international airport in 2023.
The National Information Technology Centre (NITC) claimed no data was compromised. But as Republica reported, that claim was met with deep skepticism because no comprehensive forensic study was ever conducted. You can't say nothing was stolen if you never actually checked.
Then it happened again. In March 2025, over 400 government websites went down in another attack targeting the exact same infrastructure. Same GIDC. Same single point of failure. Immigration systems crashed again, causing three-hour delays at the airport.
After this second attack, a hacker group called ShadowLeak claimed to possess a backup database from the Office of the Prime Minister containing roughly 100,000 rows of personal data. They listed it on darknet forums for about $1,000. Shell access to internal servers? $1,300. That's the price tag on Nepal's national security — less than a decent laptop.
As the Kathmandu Post reported, the root causes are painfully clear: outdated technology, shortsighted procurement, vendor dependency, and a chronic shortage of technical personnel who actually care about their jobs.
The Vibe Coding Epidemic: AI Slop on Government Servers
Here's a newer problem that's making everything worse. "Vibe coding" — where people use AI tools like ChatGPT or Copilot to generate entire applications without deeply understanding the code they're shipping.
This trend has hit Nepal's government sector hard. According to Online Khabar, everything from student projects to government systems is now being built with AI-generated code. And Maharjan himself warned about this directly: "AI tools have made website development fast and accessible, but users often do not know how secure the generated systems truly are."
The numbers back him up. Research from Ox Security found that 62% of AI-generated applications ship with critical security vulnerabilities. Georgia Tech researchers found that without specific security guardrails, large language models produce insecure code up to 90% of the time.
So what does this look like in practice? Government portals that feel like they were slapped together in an afternoon. Sites that crash under moderate traffic. Applications with SQL injection vulnerabilities — which, by the way, account for over 65% of reported breach cases in Nepal. Login forms without proper input validation. APIs with no rate limiting.
If you've visited certain government websites and thought "this looks like it was made by AI in 2023," you're probably right. The aesthetic is unmistakable: generic layouts, cookie-cutter components, zero attention to edge cases. And underneath that surface? Security holes you could drive a truck through.
The issue isn't that AI tools exist. It's that they're being used by people who lack the expertise to evaluate what the AI produces — and those people are responsible for systems handling citizens' most sensitive data. If you're interested in how AI tools should actually be evaluated before trusting them, we covered some of that thinking in our piece on whether you really need an AI subscription.
47 Data Leaks, 142 Breaches, Zero Accountability
The Ministry of Electronics and Information Technology confirmed that government portals experienced 47 data leaks and 142 data breaches over the past five years. Let those numbers settle in for a moment.
When Nepal joined Have I Been Pwned as the 47th government entity worldwide, the initial scan immediately flagged 135 compromised email addresses under the nepal.gov.np domain. These weren't random low-level accounts. They belonged to civil servants at the Office of the Prime Minister, Ministry of Home Affairs, Ministry of Finance, and Ministry of Foreign Affairs.
Cybersecurity expert Mona Nyachhyon put it bluntly: "When official email addresses are compromised, it grants unauthorised actors a doorway into internal networks. This compromises government secrecy, exposes sensitive communication, and provides attackers with legitimate channels to launch sophisticated social engineering campaigns."
And that's exactly what happened. Phishing emails impersonating the Additional Inspector General of Nepal Police and the Prime Minister's Office have been circulating, threatening citizens with prosecution to extract personal data.
Between 2019 and 2023, cybercrime complaints filed with the Nepal Police's Cyber Bureau tripled — from 2,301 to 6,297 annually. Nepal has fewer than 500 certified cybersecurity professionals in the entire country, according to ITSERT-NP estimates. Meanwhile, 67% of organizations lack even basic cybersecurity practices.
A System Designed to Fail
The National Identity Card verification system tells you everything you need to know about how Nepal's government approaches technology. The system was designed in 2018 to handle 6,000 real-time verification requests per hour. Today, it struggles to process 600 to 700 requests per day. Not per hour. Per day.
Information systems architect Vivek Rana explained it clearly: "High-traffic public and private sector systems were aggressively tethered to the central NID server without any corresponding investment in expanding the system's processing bandwidth, data storage capacity, or server hardware. When thousands of simultaneous verification requests hit the central server during peak business hours, the infrastructure simply collapses."
One senior government IT officer, speaking anonymously, revealed that 80 million rupees worth of server hardware was procured for regional land revenue offices — and then not a single rupee was allocated for maintenance over the next eight to ten years. The hardware is now completely nonfunctional.
Why? Because technical personnel can't convince non-technical ministry secretaries that invisible things like software maintenance actually matter. And officials are reportedly afraid to request upgrade funds because it might trigger corruption investigations. So the servers just... rot.
For those curious about how Nepal's broader internet infrastructure stacks up, our analysis of internet connectivity in Nepal covers some related structural issues.
What Needs to Change
I'm not going to pretend there's one magic fix. But a few things are non-negotiable:
Automate SSL certificate renewal. This is a solved problem. Use Let's Encrypt. Use certbot with a cron job. There is no excuse for expired certificates on production government sites in 2025.
Stop deploying AI-generated code without security audits. If your team can't review the code for vulnerabilities, they shouldn't be shipping it. Period.
Invest in infrastructure lifecycle, not just procurement. Buying servers means nothing if you abandon them. Allocate maintenance budgets. Enforce SLAs with vendors.
Hire and retain competent security professionals. Pay them properly. Give them authority. Stop letting non-technical bureaucrats make technical decisions.
Conduct real, independent security audits. Not checkbox exercises. Actual penetration testing by qualified teams, done regularly.
Establish accountability. When 135 government emails get breached, someone should answer for it. When SSL certificates expire on critical portals, there should be consequences.
The Bottom Line
Nepal's digital ambitions are running years ahead of its technical competence and institutional willingness to maintain what it builds. The country scored 44.99 out of 100 on the Global Cybersecurity Index. Cybercrime complaints have tripled. Government email accounts are being sold on the dark web.
And through it all, the technical staff responsible for these systems coast along, collecting salaries while SSL certificates expire, servers crash under trivial loads, and AI-generated slop code handles citizens' most personal data without a single proper audit.
This isn't just a technology problem. It's an accountability problem. Every expired certificate, every unpatched server, every vibe-coded portal pushed to production — it represents someone who was supposed to do their job and didn't. Citizens deserve better. And until there's real pressure to change, nothing will.
If you've had experiences with Nepal's government digital services breaking down, or if you work in this space and see these problems firsthand, I'd genuinely like to hear from you in the comments.
Sources
- Kathmandu Post — "Widespread server crashes point to Nepal's digital state failure"
- Kathmandu Post — "Nepal uncovers 135 compromised government email accounts after joining global breach tracker"
- MyRepublica — "Nepal's Digital Frontier: How Safe Are We from Cyber Attacks?"
- Business 360 Nepal — "Nepal's Digital Collapse: The Government's Cyber Crisis and Path to Recovery"
- Online Khabar — "How 'vibe coding' is taking off in Nepal"
- Ox Security — "Vibe Coding Security: Why 62% of AI-Generated Applications Ship with Critical Vulnerabilities"
- eKantipur/Facebook — "Is our data safe?" — Government portals: 47 data leaks and 142 breaches in five years
- Troy Hunt — "Welcoming the Nepalese Government to Have I Been Pwned"
- ITU — "Global Cybersecurity Index 2024"
- Georgia Tech Research — "Bad Vibes: AI-Generated Code is Vulnerable, Researchers Warn"