Staff Reporter
THE Namibia Airports Company (NAC) has confirmed that data stolen during a recent cybersecurity breach has been released on the dark web, following a ransomware attack by the INC Ransomware Group.
In a statement issued, NAC said preliminary assessments indicate that the leaked data may include airport permit system files, parking management databases, engineering and project documents, financial records, and certain internal reports.
The company added that it is currently verifying the full extent of the breach to determine whether sensitive or personal information has been compromised.
According to NAC, the cyberattack was first detected on 6 March 2026, when it was discovered that approximately 500GB of data had been exfiltrated, with threats by the ransomware group to release the information online.
The Namibia Cyber Security Incident Response Team (NAM-CSIRT) said that the INC Ransomware Group uses “double-extortion” tactics, which involve both stealing data and encrypting systems to pressure victims into compliance. The incident marks the second known attack by the group in Namibia, following a previous breach involving the Otjiwarongo Municipality last year.
NAC said immediate containment measures were implemented following the incident, while additional safeguards have since been introduced to strengthen its cybersecurity systems.
The company further reassured stakeholders that airport operations, as well as safety and security, remain unaffected by the breach.
NAC emphasised that it is treating the matter with urgency and remains committed to transparency, adding that further updates will be provided as investigations into the scope and impact of the data exposure continue.
Picture for illustrative purposes only. Photo: Contributed


