RansomHouse cybercriminals breach Namibia's defence ministry network

Government confirms unauthorised activity linked to extortion group after listing on leak site

By LineZotpaper
Published
Read Time2 min
Namibia's computer security incident response team (NAM-CSIRT) has confirmed unauthorised activity in the network of the Ministry of Defence and Veterans Affairs (MODVA) and linked it to the RansomHouse cybercrime group, which listed the ministry as a victim on its leak site on September 16.

In an unusually direct attribution, NAM-CSIRT named the group after RansomHouse posted a message demanding contact to prevent the leak of confidential data and project documents. The group addressed the "Namibian Defence Force" but the domain in its listing belongs to the MODVA, the government department overseeing the military.

NAM-CSIRT said in a statement: "Analysis of the affected systems established that the incident is associated with the RansomHouse ransomware group, a cybercriminal syndicate known internationally for deploying ransomware and engaging in so-called double extortion tactics where threat actors encrypt systems while simultaneously threatening to disclose alleged stolen information."

The statement added that NAM-CSIRT remains actively engaged in coordinating technical support, investigation, remediation measures, and post-incident reviews under the National Cyber Security Incident Management guidelines.

Emilia Nghikembua, chief executive of the Communications Regulatory Authority of Namibia and head of NAM-CSIRT, said the team would support MODVA throughout the investigation and recovery. She urged organizations to report cyberattacks promptly. "The collective security of Namibia's digital ecosystem depends on timely reporting, proactive information sharing, and continuous investment in cybersecurity preparedness," she said.

NAM-CSIRT did not answer questions about the recovery timeline, whether a ransom had been demanded, or whether any payment was under consideration. It has not disclosed which systems or data were affected, whether information was stolen, or whether any files were encrypted.

RansomHouse, active since 2021, is not among the most prolific extortion groups but has outlasted many rivals. According to Halcyon's Ransomware Research Center, the group has listed a steady number of victims each year since it began operating, although it remains less active than dominant operations such as The Gentlemen and Qilin.

§

Analysis

Why This Matters

  • The breach of a national defence ministry network poses direct risks to national security, potentially exposing sensitive military and veterans' data.
  • It highlights the growing threat of cyber extortion against government institutions, even in smaller nations, and underscores the need for robust cybersecurity preparedness.
  • The incident may prompt other Namibian organisations to reassess their defences and reporting procedures, as urged by NAM-CSIRT.

Background

RansomHouse is a cybercrime syndicate known for double extortion: encrypting victims' systems while simultaneously stealing data and threatening to leak it if a ransom is not paid. Active since 2021, the group has maintained a steady but moderate victim count compared to larger ransomware operations. This attack marks a rare direct targeting of a country's defence establishment, an unusually aggressive move.

Key Perspectives

NAM-CSIRT and the Namibian government: The official response focuses on investigation, remediation, and encouraging timely reporting. The team has not disclosed the extent of the breach or whether sensitive data was taken, maintaining operational security. RansomHouse: The group has posted a demand on its leak site, framing the MODVA as a company with $434 million in annual revenue, and threatens to leak confidential data without engagement. Security experts: Observers note that extortion attacks increasingly rely on data theft alone, sometimes skipping encryption. The outcome may depend on whether the attackers possess genuinely sensitive material and whether the government decides to negotiate.

What to Watch

  • Whether NAM-CSIRT or MODVA disclose if a ransom was demanded and whether any payment is under consideration.
  • Any release of stolen data on RansomHouse's leak site, which would indicate failed negotiations and could escalate the incident.
  • The recovery timeline and whether the affected systems and data have been fully restored.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.