What Happened at NEPSE and Why It Was Initially Called a Glitch
On Monday, trading on the Nepal Stock Exchange (NEPSE) came to a halt. The initial explanation offered to investors was vague: a "technical glitch" had disrupted operations. In reality, the disruption was caused by a ransomware attack detected around 5:30 a.m. that day, targeting Data Hub, the infrastructure provider that hosts the trading management systems (TMS) for 72 brokerage companies connected to NEPSE.
Because Data Hub serves as a centralized backbone for so many brokers at once, a single successful attack on its servers was enough to freeze the entire market. Investors were left uncertain, brokers could not process trades, and the exchange itself had little choice but to suspend the session while the scope of the damage was assessed.
The decision to initially describe the incident as a "technical glitch" rather than a ransomware attack is not unusual. Organizations facing a cyberattack often default to softer language in early statements, partly because the full scope of an intrusion is not immediately clear, and partly to avoid alarming customers, partners, or regulators before an investigation is complete. But this pattern of underreporting or mislabeling incidents can delay the response of everyone downstream, including brokers, investors, and other institutions that might be exposed to the same vulnerability.
How Ransomware Encryption and Double Extortion Actually Work
Ransomware is a type of malicious software that encrypts files and data on infected systems. Once encryption takes hold, the affected files can no longer be opened or used normally. Attackers typically leave behind a ransom note demanding payment, usually in cryptocurrency, in exchange for a decryption key that would restore access.
What makes modern ransomware attacks more damaging than earlier versions is a tactic known as "double extortion." In this model, attackers do not simply lock up files. Before triggering encryption, they quietly copy sensitive data off the network. This gives them a second point of leverage: even if a victim organization has backups and can restore its systems without paying, the attackers can still threaten to leak or sell the stolen data publicly unless a ransom is paid. For an institution like a stock exchange's data hub, which handles sensitive brokerage and possibly investor information, that second threat can be just as damaging as the original disruption.
This evolution in tactics is part of a broader trend. Attackers are constantly refining how they pressure victims into paying, and some groups are now going even further by using automation to speed up and personalize their extortion demands. For a closer look at how far these tactics have progressed, see this piece on how ransomware gangs now use AI to pressure victims harder.
Warning Signs Organizations Downplay After a Cyberattack
The NEPSE incident is a useful case study in how the language used to describe a cyber incident can shape public understanding of its severity. Terms like "technical glitch," "system disruption," or "connectivity issue" are often technically true in a narrow sense: systems did fail, connectivity was lost. But they omit the cause, which in this case was a deliberate criminal attack rather than routine system maintenance or hardware failure.
This gap between what is disclosed and what actually happened matters because it affects how quickly affected parties can protect themselves. Brokers relying on Data Hub's TMS servers, for example, would want to know immediately whether their own client data might have been exposed, not just that trading was temporarily paused. Investors deciding whether to trust the exchange with sensitive financial information also benefit from accurate, timely disclosure rather than euphemism.
Practical Defenses: Backups, Network Security, and VPN Use
While individual investors cannot control how a stock exchange or its vendors secure their infrastructure, the NEPSE incident is a reminder of the layered defenses that reduce the damage from ransomware, whether for large institutions or smaller businesses.
Regularly tested, offline backups remain one of the most effective countermeasures, since they allow an organization to restore encrypted data without needing the attacker's decryption key. Network segmentation, which limits how far an intrusion can spread once it gains a foothold, can also prevent a single compromised server from taking down systems for dozens of connected companies, as appears to have happened with Data Hub's centralized model. For remote access and administrative connections, a properly configured VPN adds another layer of protection by encrypting traffic and restricting who can reach sensitive systems in the first place, reducing the exposed attack surface that ransomware operators look for.
What This Means For You
If you are an investor or broker connected to systems like NEPSE's, the biggest takeaway is not to take vague official statements at face value. Follow up on the details behind terms like "technical glitch" and ask whether personal or financial data may have been affected. For businesses of any size, this incident underscores that centralizing critical infrastructure with a single vendor, as Data Hub did for 72 brokers, creates a single point of failure that attackers can exploit for outsized impact.
Key Takeaways
- Ransomware attacks are increasingly framed publicly as generic "technical issues," so it pays to ask direct questions after any service disruption.
- Double extortion means paying a ransom for a decryption key does not guarantee stolen data won't still be leaked.
- Backups, network segmentation, and VPN-secured remote access are practical, proven defenses against ransomware spreading through shared infrastructure.
- As extortion tactics grow more sophisticated, including the use of AI to pressure victims, staying informed about attacker methods helps organizations and individuals respond faster and more effectively.




