mofaga.gov.np Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
mofaga.gov.np was listed by the funksec ransomware group on December 30, 2024 after internal files were exfiltrated in a ransomware attack. The number of people affected is undisclosed; anyone who has interacted with the site should check for signs of compromise and change passwords or monitor accounts as needed.
On December 30, 2024, the website mofaga.gov.np, operated by Nepal’s Ministry of Federal Affairs and General Administration, was listed by the ransomware group funksec. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and many operational details of the incident have not been disclosed. The listing itself is a claim by the group and has not been independently confirmed in the available record.
Because the organisation handles core functions of federal coordination and local governance across Nepal, any compromise of its internal systems carries potential consequences for administrative continuity and the confidentiality of government records. What is known so far is limited to the reported listing and the stated nature of the data taken.
Inside the incident
According to the available facts, mofaga.gov.np was listed by funksec on December 30, 2024. The group’s claim describes a ransomware attack in which internal files were exfiltrated. No further public detail has been provided on the precise timing of the intrusion, the initial access method, the volume of data removed, or whether systems were encrypted in addition to the data theft. The number of individuals whose information may have been involved is recorded as unknown. Beyond the leak-site listing and the characterisation of the material as internal files, the technical and chronological specifics of the incident remain undisclosed.
The group behind it: funksec
Funksec is a ransomware operation that has appeared in public threat reporting in recent periods. Like many contemporary ransomware groups, it typically combines data theft with encryption threats and publishes victim names on dedicated leak sites to pressure organisations into paying. The group has been observed listing entities across multiple sectors and geographies, often claiming to have stolen internal documents and databases. Its public communications frequently emphasise the volume or sensitivity of exfiltrated material while offering limited verifiable proof until later stages of a campaign. In this case, the listing of mofaga.gov.np constitutes the group’s claim; no independent confirmation of the full scope of access or the authenticity of any sample files has been supplied in the facts available here. Funksec’s broader pattern of activity includes opportunistic targeting and the use of standard ransomware tooling, though specific tooling or affiliates involved in any single incident are rarely detailed publicly at the moment of listing.
About mofaga.gov.np
The domain mofaga.gov.np belongs to the Ministry of Federal Affairs and General Administration of Nepal. This ministry oversees federal affairs, local governance structures, and a range of administrative functions intended to support decentralisation, local development, and public administration across the country’s provinces and municipalities. Organisations of this type routinely manage policy documents, inter-governmental correspondence, personnel records, budgetary and planning materials, and data related to local government coordination. A breach affecting such a body is consequential because it can expose sensitive internal deliberations, disrupt administrative workflows that citizens and local authorities rely upon, and create longer-term risks if confidential governance information is misused or further disseminated.
What data was at risk
The facts state that internal files were exfiltrated in the ransomware attack. No more granular inventory of file types, databases, or personal data categories has been disclosed. Government ministries responsible for federal and local administration typically hold a mixture of operational documents, staff information, correspondence with provincial and municipal bodies, planning and budget materials, and records supporting public-service delivery. Whether any of those categories were present among the files taken in this incident is unconfirmed. The exact contents therefore remain unknown, and no claim about specific personal identifiers, financial records, or citizen data can be treated as established fact on the basis of the information provided.
The real-world impact
For individuals whose details may appear in the ministry’s internal files, the primary risks include potential exposure of personal or professional information that could be used for social engineering, identity-related fraud, or unwanted contact. Because the scale of any personal data involvement is unknown, the precise number of people facing these risks cannot be stated. For the ministry itself, the consequences may include temporary disruption of administrative processes, the need to validate the integrity of remaining systems, and the longer-term challenge of determining whether sensitive policy or personnel material has been circulated. Public trust in digital government services can also be affected when a central administrative body appears on a ransomware leak site, even when the full extent of the compromise is still unclear. None of these outcomes is automatic; they depend on what was actually taken and how it is subsequently handled.
Were you affected?
If you have had dealings with Nepal’s Ministry of Federal Affairs and General Administration—whether as staff, a local government counterpart, a contractor, or a citizen submitting information—consider monitoring official communications from the ministry for any guidance it may issue. Review account credentials associated with government portals, enable multi-factor authentication where available, and remain alert to unexpected requests for personal or financial details that could exploit knowledge of the incident. Because the number of people affected is unknown and the precise data types remain limited to the description “internal files,” it is not possible to confirm individual exposure from public sources alone. Readers can run a free exposure scan of their email address to check whether that address has already appeared in other known breach datasets, which provides one practical starting point for personal vigilance while further details about this specific incident, if any, emerge.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
gstpam.org Listed by babuk2 Ransomware Grouppbos.gov.pk Listed by babuk2 Ransomware Grouprtdc.gov.mn Listed by babuk2 Ransomware Groupskopje.gov.mk Listed by babuk2 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the mofaga.gov.np Listed by funksec Ransomware Group →
Publicly posted by funksec — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.