
Neither Individuals Are Sensitive Nor Institutions Responsible — A Grave Crisis in Data Security and Privacy
Summary
Reviewed.
- In Nepal, the leakage of citizens’ personal information by governmental and private organizations raises serious concerns about privacy and digital security.
- The data breach at Padmakantha Campus, which publicly shared academic details of 1,364 undergraduate students on social media, has reignited debates about data protection.
- According to the Cyber Bureau, complaints regarding electronic offenses and cyber fraud remain persistently high in recent times.
August 7, Kathmandu – The first-year undergraduate examinations under Tribhuvan University are currently underway. Last week, colleges were actively distributing admit cards.
However, while trying to distribute the admit cards conveniently to students, data security and privacy concerns were neglected.
Padmakantha Campus in Bagbazar publicly posted data including admit cards of 1,364 students on social media. Although the campus later removed the post following public outcry, students were still able to access academic details easily by scanning QR codes.
This data leak reflects a lack of seriousness by the Padmakantha administration on this critical issue. Campus chief Jayalakshmi Pradhan claimed the act was done with the ‘pure intention to facilitate students.’ Yet, some staff members showed little sensitivity, saying, ‘photos and names are already visible,’ trivializing the matter.
The Padmakantha administration also contended that other educational institutions are conducting similar practices. An employee remarked, ‘We are not alone; other colleges are doing this as well.’ This highlights a widespread lack of data sensitivity within educational leadership.
000
A few weeks ago, a serious incident shook Nepal’s digital security sector. Software developer Nirdesh Subedi found that an exact clone website of the government’s official ‘Nagarik App’ portal was being hosted on his domain.
Subedi’s site used an older interface of the Nagarik App. When users searched for ‘Nagarik App login,’ his domain appeared at the top of the search results, though Google Chrome flagged it with a security warning as a ‘dangerous’ link.
The Nagarik App contains extremely sensitive governmental and personal details such as citizenship, passport, PAN card, and educational certificates. The cloning of such a platform significantly heightens the risk of cybercrimes.
This incident raised questions about the government’s cybersecurity and data sensitivity shortcomings. Clone sites are often used to steal user login credentials through fraudulent means.
000
Cyber attacks on Nepal’s government digital systems are not new. Repeated risks have emerged due to failure to learn from past vulnerabilities and improve security management.
Government websites with weak security mechanisms become easy targets for hackers.
On February 13, 2025, 21 subdomains of the Koshi Province government suffered unauthorized access.
The group named ‘YNR’ accessed the Koshi government’s subdomains and publicly leaked data on the ‘Zone-H’ portal.
A month later, on March 26, 2025, the ‘Hello Sarkar’ website under the Prime Minister and Council of Ministers’ office was also compromised.
The hacker group ‘Ghuldra’ claimed to have published access data on the ‘Bridge Forum’ after the government refused to engage with them.
In the subsequent month, on April 23, 2025, the Nepal Police Headquarters’ website was rendered vulnerable, with the hacker group ‘Kaju’ obtaining approximately 2 million citizens’ citizenship details and selling them online for 7,000 USD.
000
Not only online but physical service providers like supermarkets and cafes are also collecting customer personal details without permission. Stores such as Bhatbhateni and Big Mart increasingly demand customer names and phone numbers during billing or membership registration.
However, providing such data rarely results in substantial discounts or benefits for customers.
Many cafes and restaurants require customers’ phone numbers under the pretext of providing Wi-Fi services. Rather than sharing the password directly, captive portals are used, which mandatorily collect mobile numbers.

The easy demand for phone numbers and personal details poses significant privacy risks for consumers.
Many venues do not clearly disclose that they are collecting data. Experts warn that software or technical vulnerabilities could cause data leaks and misuse.
Customers indirectly provide their data motivated by Wi-Fi access and minimal discounts but often receive no clear information about data use or protection.
000
Cybersecurity experts say such data misuse and protection failures directly affect individuals’ personal privacy. Unauthorized use of personal details causes unnecessary troubles and inconveniences for users.
For instance, the recently discussed ‘SG Update’ incident showed unauthorized messages urging nearly 4,000 mobile users to subscribe to a YouTube channel at 10:11 PM in Baishakh sent from a shortcode.
This unsolicited promotional message raised concerns, especially among users who had never shared their phone numbers publicly, leading to natural questions.
Following widespread questions, the YouTube channel operator Sagar Kshetri clarified the issue was caused by a technical error.
He explained on LinkedIn, ‘While sending updates to event participants, a system error caused unnecessary contacts to be synced—including some unauthorized contacts from an employee’s phone.’
Beyond individual cases, political campaigns frequently send promotional messages directly to voters’ mobiles without consent, especially during elections.
Cybersecurity specialist Naresh Lamgade expressed concern that data security weaknesses make voters’ phone numbers vulnerable to political campaigning without permission.
Lamgade, founder of cybersecurity firm Bagbee, stated, ‘Once a data breach occurs, everyone’s personal information is exposed, but people often fail to understand the consequences and value of this breach.’
‘In other countries, governments impose fines for data leaks, and affected citizens can file lawsuits for compensation. In Nepal, regulatory bodies and responsible institutions lack such rigor, and public awareness remains low.’

According to him, with increasing digital technologies and online platforms, the misuse of citizens’ personal data is evident in many sectors.
‘For example, after a data leak from a delivery company, a well-known person had to change their phone number due to a flood of calls and messages. This is just one example,’ he said.
Similarly, ride-share and delivery companies hold sensitive customer data such as addresses and phone numbers that require enhanced protection, Lamgade emphasized.
Information technology expert Dovan Rai identifies three primary reasons for Nepal’s weak data security: First, the absence of a cultural emphasis on privacy and personal space in Nepali society.
Second, lack of awareness about data misuse and its impacts in digital media. Third, institutional shortcomings in professionalism and accountability.

Dr. Rai explains that negligence and lack of awareness around data cause visible risks in various incidents.
In developed countries, citizens are highly aware of their data privacy. Governments impose penalties for data breaches, and affected individuals receive legal recourse and compensation.
Nepal lacks clear, stringent legal frameworks, allowing institutions with data access to evade substantial consequences.
Therefore, Dr. Rai stresses that strong legal policies by the state, institutional accountability, and individual vigilance are crucial to protect citizens’ personal privacy in the digital era.
000
The lack of sensitivity toward data has led to a rise in cybercrime cases. According to Cyber Bureau statistics, there were 20,526 cybercrime complaints filed in the recent fiscal year.
Of these, 13,230 involved electronic offenses and 7,296 were cyber fraud cases.
In fiscal year 2078/79, the number was 18,926, with 11,186 electronic offenses and 7,740 cyber fraud cases.
In fiscal year 2077/78, complaints peaked at 19,730, including 15,576 electronic offenses and 4,154 cyber fraud incidents. These figures highlight the escalating significance and sensitivity of cybersecurity issues.