Menu
Browse

Cyber Incident Victim: Department of Roads, Nepal

Date:

Aug 2015

Location:

Nepal

Summary

Hackers identifying as Avian and Nepal Cyber Army compromised the Kathmandu Valley Town Development Committee's official website, defacing it with a warning message directed at Nepali politicians. The group claimed unauthorized access to the Department of Transportation's servers and threatened to disclose bank details of prominent political leaders—including Puspa Kamal Dahal, Baburam Bhattrai, Hishila Yami, and Sujata Koirala—unless they ceased organizing strikes. The attackers leveraged their breach to pressure government figures while demonstrating broader network infiltration capabilities.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
2 actors Available to members Available to members

Description

On August 17, 2015, the official website of the Kathmandu Valley Town Development Committee (http://kvtdc.gov.np/) was compromised by hackers identifying themselves as Avian and Nepal Cyber Army. The attackers defaced the website, replacing its normal content with a public message directed at Nepalese political leaders. In their declaration, the hackers claimed unauthorized access to servers belonging to the Nepal Department of Transportation, though they provided no specific evidence or details regarding the extent of this alleged breach. The defacement served as the primary observable action, with no immediate reports of data exfiltration or system disruption beyond the website takeover. The incident represented a direct challenge to government digital infrastructure, occurring without prior public warnings of system vulnerabilities.

Cyber Incident Image

The hackers issued explicit threats against four prominent political figures: Puspa Kamal Dahal, Baburam Bhattrai, Hishila Yami, and Sujata Koirala. They demanded an immediate cessation of political strikes, warning that failure to comply would result in the public release of the politicians' bank account details. No timeframe was specified for meeting their demands, nor did the message clarify whether the threatened financial data had already been extracted from targeted systems. The attackers did not reference specific grievances beyond opposition to strike actions, leaving their broader motivations unstated. Public accessibility of the defaced website confirmed the compromise until restoration efforts occurred, though no technical details about detection methods or containment procedures were disclosed in available reports. No follow-up disclosures regarding bank records or Department of Transportation systems were subsequently verified through official channels.

Sources
Sources available to members
1 source