In an unusually direct attribution, NAM-CSIRT named the group after RansomHouse posted a message demanding contact to prevent the leak of confidential data and project documents. The group addressed the "Namibian Defence Force" but the domain in its listing belongs to the MODVA, the government department overseeing the military.
NAM-CSIRT said in a statement: "Analysis of the affected systems established that the incident is associated with the RansomHouse ransomware group, a cybercriminal syndicate known internationally for deploying ransomware and engaging in so-called double extortion tactics where threat actors encrypt systems while simultaneously threatening to disclose alleged stolen information."
The statement added that NAM-CSIRT remains actively engaged in coordinating technical support, investigation, remediation measures, and post-incident reviews under the National Cyber Security Incident Management guidelines.
Emilia Nghikembua, chief executive of the Communications Regulatory Authority of Namibia and head of NAM-CSIRT, said the team would support MODVA throughout the investigation and recovery. She urged organizations to report cyberattacks promptly. "The collective security of Namibia's digital ecosystem depends on timely reporting, proactive information sharing, and continuous investment in cybersecurity preparedness," she said.
NAM-CSIRT did not answer questions about the recovery timeline, whether a ransom had been demanded, or whether any payment was under consideration. It has not disclosed which systems or data were affected, whether information was stolen, or whether any files were encrypted.
RansomHouse, active since 2021, is not among the most prolific extortion groups but has outlasted many rivals. According to Halcyon's Ransomware Research Center, the group has listed a steady number of victims each year since it began operating, although it remains less active than dominant operations such as The Gentlemen and Qilin.