Select your Top Menu from wp menus
  • Instagram
  • TikTok
RansomHouse ransomware attack confirmed in Defence Ministry network

RansomHouse ransomware attack confirmed in Defence Ministry network

Staff Reporter

THE Namibia Cyber Security Incident Response Team (NAM-CSIRT) has confirmed unauthorised activity within the network environment of the Ministry of Defence and Veterans Affairs (MODVA), linking the incident to the RansomHouse ransomware group.

The confirmation, issued by NAM-CSIRT follows the earlier listing of the ministry by RansomHouse on its dark web leak site, which had initially been reported as an unverified ransomware claim.

According to NAM-CSIRT, analysis of the affected systems established that the incident is associated with RansomHouse, an internationally known cybercriminal syndicate that uses ransomware and so-called “double-extortion” tactics.

These tactics typically involve encrypting systems while threatening to disclose allegedly stolen information.

NAM-CSIRT, which is housed at the Communications Regulatory Authority of Namibia (CRAN), said it remains involved in coordinating technical support, investigation activities, remediation measures and post-incident reviews.

The response is being conducted in line with the National Cyber Security Incident Management Guidelines, which provide a coordinated and risk-based approach to detecting, containing and recovering from cyber incidents.

CRAN Chief Executive Officer and Head of NAM-CSIRT Emilia Nghikembua said the incident highlights the growing cybersecurity risks faced by organisations.

“Cybersecurity incidents of this nature serve as a reminder that no organisation, regardless of size or mandate, is immune to the evolving threat landscape,” Nghikembua said.

She said NAM-CSIRT remained committed to supporting the Ministry of Defence and Veterans Affairs and affected stakeholders with the investigation, recovery and strengthening of cyber resilience across government and critical sectors.

NAM-CSIRT also urged government institutions, critical infrastructure operators and private-sector organisations to maintain strong cybersecurity practices, implement incident response plans, conduct regular security assessments and promptly report significant cyber incidents.

Nghikembua further called for timely reporting, proactive information sharing and continued investment in cybersecurity preparedness.

“We urge all organisations to strengthen their cyber defences and work closely with NAM-CSIRT to safeguard critical systems, data, and services that citizens depend upon every day,” she said.

The development follows an earlier report by cybersecurity researchers that RansomHouse had listed the Namibian Defence Force through the domain mod.gov.na on its leak site.

At the time, the claim had not been independently verified, with no publicly released proof-of-compromise samples, file listings or negotiation details. NAM-CSIRT’s latest update now confirms unauthorised activity within the ministry’s network and its association with RansomHouse.

The latest update does not disclose the extent of the incident, the specific systems affected, whether information was exfiltrated or encrypted, or whether any ransom demand was made.

Picture for illustrative purposes only. Photo: Contributed

Related posts