RansomHouse picks a fight with Namibia's defense establishment

National cyber team confirms the breach, but not whether data was stolen or encrypted

Namibia's computer security incident response team has confirmed unauthorized activity in the defense ministry's network and linked it to the RansomHouse cybercrime group.

In an unusually direct attribution, NAM-CSIRT named the group after RansomHouse listed the supposed victim on its leak site on September 16.

RansomHouse identified the victim as the "Namibian Defence Force," although the domain in its listing belongs to the Ministry of Defence and Veterans Affairs (MODVA), the government department overseeing the military.

Either way, openly extorting a country's defense establishment is a bold move even by ransomware standards.

RansomHouse's website stated: "Dear management of Namibian Defence Force. We were waiting for you for quite some time, but it seems that your IT department decided to conceal the incident that took place in your company.

"We strongly recommend you to contact us to prevent your confidential data, projects documents from being leaked."

The listing treated the target as a company with $434 million in annual revenue, but NAM-CSIRT subsequently confirmed unauthorized activity within MODVA's network.

NAM-CSIRT said in a statement: "Analysis of the affected systems established that the incident is associated with the RansomHouse ransomware group, a cybercriminal syndicate known internationally for deploying ransomware and engaging in so-called double extortion tactics where threat actors encrypt systems while simultaneously threatening to disclose alleged stolen information.

"NAM-CSIRT remains actively engaged in coordinating technical support, investigation activities, remediation measures, and post-incident reviews in line with the National Incident Management framework outlined in the National Cyber Security Incident Management guidelines."

Emilia Nghikembua, chief executive of the Communications Regulatory Authority of Namibia and head of NAM-CSIRT, said the team would support MODVA throughout its investigation and recovery. She urged organizations across Namibia to report cyberattacks promptly so authorities can build a fuller picture of the threat landscape.

"The collective security of Namibia's digital ecosystem depends on timely reporting, proactive information sharing, and continuous investment in cybersecurity preparedness," she said.

"We urge all organizations to strengthen their cyber defences and work closely with NAM-CSIRT to safeguard critical systems, data, and services that citizens depend upon every day."

NAM-CSIRT did not answer The Register's questions about the expected recovery timeline, whether a ransom had been demanded, or whether any payment was under consideration.

It has not disclosed which systems or data were affected, whether information was stolen, or whether any files were encrypted.

RansomHouse is associated with double extortion, in which attackers encrypt systems while threatening to publish stolen data. However, many modern extortion attacks dispense with encryption and rely solely on stolen information as leverage.

Active since 2021, RansomHouse is not among the most prolific extortion groups, but it has outlasted many rivals that appeared and disappeared during the same period.

According to Halcyon's Ransomware Research Center, the group has listed a steady number of victims each year since it began operating, although it remains less active than dominant operations such as The Gentlemen and Qilin. ®

Original source RansomHouse picks a fight with Namibia's defense establishment

Back to home