Staff Reporter
THE Namibia Cyber Security Incident Response Team (NAM-CSIRT) has confirmed that some of the data stolen during the recent cyberattack on the Namibia Airports Company (NAC) has been published online, as investigations continue to determine the full extent of the breach and whether sensitive information has been compromised.
In an update issued by NAM-CSIRT, which operates under the Communications Regulatory Authority of Namibia, preliminary assessments indicate that the leaked data may include airport permit system records, parking management information, engineering and project documentation, financial records, and internal reports.
According to NAC, the cyberattack was first detected on 6 March 2026, when approximately 500GB of data was exfiltrated, with threats by the perpetrators to release the information online.
NAM-CSIRT further revealed that the group behind the attack is the INC Ransomware Group. The incident marks the second known attack linked to the group in Namibia, following a previous breach involving the Otjiwarongo Municipality last year.
The incident is among a series of high-profile cyberattacks involving data theft and ransom demands that have affected Namibia’s public and private sectors, including a 2025 breach at Paratus Namibia that disrupted voice and cloud services, reportedly linked to a group known as Akira, and a 2024 ransomware attack on Telecom Namibia by Hunters International, where more than 626GB of data was stolen and later leaked after ransom demands were not met.
Authorities said verification processes are ongoing to establish the scope of the breach, including whether personal or sensitive data has been affected. Response and containment measures remain in place, with NAM-CSIRT working alongside NAC, external cybersecurity experts, and other stakeholders to conduct forensic investigations and strengthen security systems.
NAM-CSIRT has urged organisations to enhance cybersecurity practices, including regularly updating systems, implementing multi-factor authentication, and improving user awareness to mitigate risks.
Executive for Communication and Consumer Relations at CRAN, Mufaro Nesongano, cautioned against the circulation of unverified or compromised data, warning that it could expose individuals and organisations to further risk. He emphasised the need for responsible handling of information as investigations continue.
Further updates are expected as more verified information becomes available.
Photo: CRAN


