In having to interact with Nepali government websites I've noticed things like endpoints not even doing basic input sanitization, letting your run arbitrary queries on biometric data. Asking around the tech industry on how to report this it seems like this is a common occurrence. Someone even found a vulnerability that was apparently purposefully unpatched to most likely aid in corruption.
Personally I'd recommend Fable or Kimi K3. Have you tried them yet? They're better at your job than you could ever be, even in theory.
It's a pattern that is used for new welcomes.
Being “welcomed” to HIBP sounds a lot like being “welcomed” to the Bronx by a mugging.
I admit I do not follow HIBP and was unaware of this kind of outreach they do.
If they find during an investigation that you're avictim of a crime they WILL tell you where they found the data and what was exactly in it.
Troy? He'll basically resell you your own stolen data, because that's the only way to know if the password leaked was 20 years or 1 month old, and to what services exactly. If you're leaked in infostealer dump, you'd learn from the police what was associated with your email in this dump, so you know to snort if it was only empty password store from your Firefox, or financial data exposing you to ruin.
Troy? Oh, he can tell you that too, but for a price. He'll sell you your personal data back.
(I've looked far and wide and there doesn't seem to be ANY way to list as much as the domains of the email/password dumps without paying for access to the API)
03 August 2026
Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and respond quickly when those accounts appear in a new data breach.
This is precisely what the HIBP government service was built for: helping national cyber teams strengthen threat monitoring and incident response capabilities by providing visibility into compromised credentials and breached accounts across their government domain space.
Nepal joins a growing list of governments and national cybersecurity teams using HIBP to better understand their exposure, protect government departments and public resources, and reduce the risk posed by compromised credentials before attackers can take advantage.