
Nepal’s government cloud portal (portal.gcloud.gov.np/enlight-cloud/api/) has experienced a hacking incident. Hackers announced the breach through the Telegram channel “Force Anon,” posting a message and image on the website. Visitors to the link encountered an image of a young woman alongside the text “Hacked by PSY404.” The page also displayed the phrase “Typical Idiot Security Ice-Cream – SPEEDY-03-PYS404 – Mirav – Grac3 – AnoaGhost.”
This incident highlights the system’s vulnerabilities, though it remains unclear if any data was compromised. Experts recommend a forensic audit and immediate actions to enhance security and prevent future breaches. The hackers criticized the government’s security measures on public forums, labeling them as “Idiot Security.” AnoaGhost, the leader of the international hacktivist group AnonGhost, is known for targeting various web portals, including both government and private organizations.
AnoaGhost has also been linked to cyberattacks against the UK’s National Health Service and is suspected of being part of the United Islamic Cyber Force. It is still uncertain whether the breach affected the domain name or the server.
The government cloud portal, managed by the Integrated Data Management Center, was previously under the Department of Information Technology. This portal allows state agencies to host servers based on their needs. Efforts to get a response from IDMC Director General Manish Bhattarai have been unsuccessful.
