It finally feels like the digital transformation Nepal has long envisioned is beginning to take shape. Nepali citizens can now download their National Identity Card (National ID Card) directly from their mobile phones without having to visit government offices.
For many people, losing an important government document often meant going through a lengthy and frustrating process to obtain a replacement. With the new system, however, citizens can access and download their National ID cards online whenever needed.
While the service is undoubtedly convenient, it also appears to have introduced a significant security concern. If left unaddressed, the loophole could expose sensitive personal documents to scammers and potentially increase the risk of cyber fraud and identity misuse.
How to Download Your National ID Card
To download a National ID card, users need to open Google on their mobile device and search for “NID Nepal.”
Among the search results, an option titled “Download Your ENID” appears. Clicking on it opens a form that requires several personal details.
Users must first enter their full name in Nepali, followed by their full name in English.
They are then required to provide their date of birth according to the Bikram Sambat calendar, including year, month, and day.
The next field asks for the citizenship issuance date, which can be found on the back side of a Nepali citizenship certificate.
Finally, users must complete a CAPTCHA verification by entering the exact characters displayed on the screen.
If the CAPTCHA box fails to load and continues spinning indefinitely, users may try accessing the service through browsers such as Chrome or Safari instead of Google Search’s built-in browser. Some users have also reported fewer issues when attempting the process later in the evening.
After completing the CAPTCHA and clicking the Search button, individuals who have already completed biometric enrollment for the National ID system can view their card details.
The card can then be downloaded by selecting the “Download Card” option followed by the download confirmation button.
How to Open the Downloaded PDF
Once the download process begins, users receive a notice explaining that the National ID card will be downloaded as a PDF file protected by an eight-character password.
The password format consists of the first four letters of the user’s name in uppercase letters followed by their birth year.
For example, if a person’s name begins with “Roshan” and their birth year is 2050 B.S., the password would be:
ROSH2050
After downloading, the PDF can be accessed from the phone’s file manager or opened directly through the browser’s download section.
Entering the password allows the user to view the National ID card.
The Security Concern Identified by Khoj Samachar
While the new system offers convenience, Khoj Samachar’s review of the National ID download process has identified a significant security concern that has received little public attention so far.
Based on the current procedure, downloading a National ID card appears to require only three pieces of information:
1. Full name
2. Date of birth
3. Citizenship issuance date
Once these details are entered correctly, users can reportedly view and download the National ID card without any additional verification layer.
At first glance, the process may seem extremely user-friendly.
However, the same simplicity that makes the service convenient could also create opportunities for abuse if personal information falls into the wrong hands.
If someone obtains these three details, they may potentially be able to access another person’s National ID document.
Why Could This Become a Risk?
Consider the example of public figures.
Many people’s names are already widely known. Their dates of birth can often be found through a simple online search.
Searching for a public figure’s date of birth on Google frequently provides immediate results.
This is not limited to one individual. Birth dates of many public personalities, including politicians, celebrities, and government officials, are often publicly available online.
If someone already knows a person’s name and date of birth, the remaining piece of information needed is the citizenship issuance date.
Should that information become exposed through any source, accessing the individual’s National ID card could become significantly easier.
Notably, the current process does not appear to require:
- OTP verification
- Mobile number verification
- Email verification
- Any secondary authentication layer
“My Date of Birth Isn’t on Google” — Think Again
Some people may believe they are safe because their personal information is not publicly searchable online.
However, citizenship documents are routinely shared in numerous situations.
They may be submitted for SIM card registration, bank account opening, cooperative memberships, manpower agencies, educational applications, visa processing, photocopy services, and various administrative procedures.
In some cases, individuals even upload citizenship documents to social media platforms for different purposes.
If a person’s name, date of birth, and citizenship issuance date leak from any one of these sources, unauthorized access to their National ID card could become a possibility.
How Could Scammers Misuse a National ID Card?
Possession of another person’s government-issued identification document can create serious risks in the digital age.
Fraudsters may attempt to use such information to create fake social media profiles on platforms such as Facebook, Instagram, or X (formerly Twitter).
In certain situations, they may even try to obtain account verification using identity documents.
Beyond social media misuse, stolen identity documents could potentially be used for:
- KYC verification on online platforms
- Opening digital wallet accounts
- Creating accounts on various services
- Launching phishing campaigns
- Collecting additional personal information
- Building profiles for future cybercrime activities
In simple terms, when a government-issued document falls into the wrong hands, the consequences can extend far beyond privacy concerns.
Victims may find themselves dealing with fraudulent activities carried out in their name.
What Should the Government Do?
Given the sensitivity of identity-related data, additional safeguards may be necessary to strengthen the system.
1. Introduce Mandatory OTP Verification
Before allowing users to view or download a National ID card, the system could introduce an additional verification layer.
A one-time password (OTP) could be sent to the registered mobile number, WhatsApp account, or email address associated with the individual.
Only after successfully entering the OTP should access be granted.
Because many Nepalis work abroad and may not have access to their Nepali mobile number, email-based verification should also be included as an alternative.
2. Restrict Downloads to the Nagarik App
If implementing OTP verification immediately is not feasible, another option would be to make National ID downloads available only through the Nagarik App.
The Nagarik App already requires user authentication before granting access to services, making unauthorized access significantly more difficult.
Limiting National ID downloads to a verified government application could add an additional layer of protection even without OTP verification.
Conclusion
The ability to download a National ID card from home is a major step forward for digital public services in Nepal.
However, convenience should never come at the cost of security.
When dealing with highly sensitive identity documents, even a small weakness can create significant risks for citizens.
As Nepal continues its digital transformation journey, protecting personal data must remain a top priority.
Based on its review of the current system, Khoj Samachar urges the government and concerned authorities to carefully assess this potential vulnerability and implement appropriate safeguards if necessary.
Strengthening verification measures and addressing any loopholes at an early stage could help prevent future misuse of citizens’ personal information and reinforce public trust in Nepal’s growing digital infrastructure.
Complete Guide to Downloading Your National ID Card (Video)
Watch the video below for a detailed walkthrough on how to download your National ID card, use the PDF password, and understand the security concerns surrounding the current system.