Kathmandu, October 10, 2026
A popup message attributed to the hacker group Force Anon has appeared on the website of Modern Institute of Technology (MIT) Nepal, adding to a series of reported cyber incidents targeting Nepal’s government, educational institutions and other organizations.
The message addressed Kathmandu Model College (KMC) and MIT Nepal, questioning the security of their digital infrastructure and urging them to fix vulnerabilities and strengthen their systems. It stated that students and staff were not the target and that their personal data was not intended to be misused. The incident involved a popup message rather than a conventional website defacement.
The incident comes amid growing concerns over cybersecurity in Nepal, with Force Anon reportedly claiming responsibility for or drawing attention to attacks involving several institutions.
One of the reported targets was the Office of the Attorney General, where a warning message was reportedly left on the website. The message read: “Your Free Volunters wont save the digital Infrastrute of Nepal sorry.” The group used the statement to criticize the country’s efforts to protect its digital infrastructure.
The Government Cloud Server (G-Cloud) has also been reported as a target. According to Ratopati, groups identified as PSy404 and AnoNagoSt, described in the report as affiliated with the ForceAnon network, allegedly accessed a public API system and posted messages and images. The report raises concerns about the security of government-hosted services, although the full extent of any data access has not been independently established.
Reports have also linked the wider wave of incidents to the Nepal Police Hospital and alleged leaks involving Gandaki University student records, political party administrators and volunteers, and municipal citizen property and building information. Other incidents mentioned in reports include the Department of Transport Management (DoTM), the NWASH government platform, and data associated with GEMS School Nepal and Panauti Municipality. The specific circumstances and attribution differ across cases, and these incidents should not all be assumed to have been carried out by Force Anon.
The reported incidents have renewed questions about the protection of sensitive information held by public institutions. Exposure of student records, personal details or property data could create privacy and security risks for the people concerned. Experts generally recommend regular security audits, prompt patching, strong access controls and responsible disclosure of vulnerabilities to reduce such risks.
Background on AnoaGhost
AnoaGhost, also referred to by variations of the name AnonGhost, has been described in online sources as a pro-Islamic and pro-Palestinian hacktivist collective active since around 2013. The name has been associated with politically and religiously motivated cyber activity, including website defacements. However, the group’s history, exact identity and any direct connection to Force Anon should be verified independently.