Have I Been Pwned adds Nepal as its 47th government partner

Have I Been Pwned (HIBP), the breach-notification service run by security researcher Troy Hunt, has added Nepal as the 47th government onboarded to its free government service. Nepal's National Cyber Security Centre (NCSC) now has access to monitor Nepalese government domains against the data HIBP holds, meaning the NCSC can check government email addresses for exposure in past and future data breaches. The free gov service exists specifically for this purpose: it gives national cyber teams visibility into compromised credentials and breached accounts across their own government domain space, so they can identify exposure and respond quickly when an account turns up in a new breach. HIBP frames Nepal's inclusion as part of a growing list of governments and national cybersecurity teams that use the service to understand their exposure, protect government departments and public resources, and reduce the risk from compromised credentials before attackers can exploit them. No specific breach or exposure incident involving Nepalese government accounts prompted the move, and no date for the onboarding or details of how the NCSC's access works technically are given.
Key facts
- Nepal is the 47th government onboarded to Have I Been Pwned's free government monitoring service.
- Nepal's National Cyber Security Centre (NCSC) can now monitor Nepalese government domains against HIBP's breach data.
- The access lets the NCSC identify exposure across government email addresses and respond when accounts appear in a new data breach.
- HIBP describes the free gov service's purpose as strengthening national cyber teams' threat monitoring and incident response through visibility into compromised credentials and breached accounts.
Why it matters
This is a routine expansion of an existing HIBP offering rather than a new capability: the free government service already covers 46 other governments, and Nepal simply becomes the 47th. Its value is preventive. A national cyber team that can see which of its own government email addresses show up in a breach can rotate credentials and investigate before attackers use them, rather than finding out after an incident.
Who it affects
The direct user is Nepal's National Cyber Security Centre, which gains monitoring access over Nepalese government domains. The people whose exposure is being tracked are holders of Nepalese government email accounts; the public benefits indirectly if compromised government credentials are caught and rotated before they can be used against government departments and public resources.
How to use it
HIBP's government service is free. Once a national cyber team like the NCSC is onboarded, it can check its government domains against HIBP's breach database to see which accounts have appeared in known breaches, supporting ongoing monitoring rather than a one-off lookup.
How solid is it
The account comes directly from Troy Hunt's own blog post announcing the onboarding, which is the primary source for HIBP program updates. The core fact, Nepal's addition as the 47th government, is stated plainly and is not in dispute.
Risks and caveats
The source does not name a specific breach or exposure incident that prompted Nepal's onboarding, does not give a date for when it happened, does not name any of the other 46 governments in the program, and does not describe the technical details of how the NCSC's monitoring access works or how often it is checked.