A criminal extortion syndicate has claimed the network of the Ministry of Defence and Veterans Affairs. The national response team has confirmed an attack. What follows examines the evidence, and the people who may stand behind it. It also asks what the episode means for a country that has still not passed a cybercrime law.
By Silas Mwaudasheni Nande
A listing on a Wednesday afternoon
On 16 September 2026, at 15:32 Coordinated Universal Time, a new entry appeared on a criminal leak site monitored by security researchers across the world. The victim named on the entry was the Namibian Defence Force. The internet domain recorded beside that name was www.mod.gov.na. That domain belongs to the Ministry of Defence and Veterans Affairs. The group claiming responsibility was RansomHouse.
The monitoring service that recorded the listing places the probable date of the intrusion four days earlier, on 12 September 2026. Three days after the listing appeared, the Namibia Cyber Security Incident Response Team confirmed the substance of the claim. The confirmation was reported by The Namibian on 19 September 2026.
Namibia has therefore crossed a line. A state telecommunications operator was emptied of customer records in December 2024. The national airports company was listed by a different syndicate in March 2026. Those events damaged commercial confidence and personal privacy. This event touches the defence establishment of a sovereign state. A breach at a telecommunications operator is a data protection failure. A breach at a defence ministry is a counterintelligence event.
What is established
Careful reporting on an incident of this kind must begin by separating what is confirmed from what is merely circulating. Four matters are established on the record.
First, a cyberattack occurred. The Namibia Cyber Security Incident Response Team, known as Nam-CSIRT, identified unauthorised network activity on the systems of the Ministry of Defence and Veterans Affairs. Nam-CSIRT is the national response body, hosted by the Communications Regulatory Authority of Namibia and launched on 16 April 2025.
Second, the attack has been attributed to RansomHouse by the national response team itself. This is not a claim advanced only by the criminals. It is an attribution by the state body charged with incident response.
Third, the response team has described the method. The Namibian reported that Nam-CSIRT linked the attack to a group known for double extortion operations. In such operations, attackers encrypt systems while also threatening to publish material they have already removed.
Fourth, the head of Nam-CSIRT has spoken publicly. Emilia Nghikembua, who is also the Chief Executive Officer of the Communications Regulatory Authority of Namibia, said the following.
“Cybersecurity incidents of this nature serve as a reminder that no organisation, regardless of size or mandate, is immune to the evolving threat landscape.” — Emilia Nghikembua, head of Nam-CSIRT
She added that collective digital security depends on timely reporting, on information sharing, and on continuous investment in preparedness. The response team is working with the ministry on investigation, on technical support, and on restoration.
What is claimed, but not established
Beyond those four points, the record becomes thinner, and honest analysis must say so plainly.
The Xinhua news agency, reporting from Windhoek on 19 September 2026, stated that Namibia is examining a reported attack on the Namibian Defence Force. The agency cited reporting by the Namibian Broadcasting Corporation. According to that reporting, files appearing to originate from systems connected to the Defence Force were distributed online after the ransomware claim.
The same reporting describes the structure of the leaked directory. It is said to contain folders identified as Commander, Defence, Military, Financials and Personal. If accurate, that structure suggests command records, financial records and personnel records in one collection.
Two cautions are necessary. The folder names have not been independently verified. Folder names in any case describe containers rather than contents. A folder marked Commander may hold a parade seating plan. It may equally hold a deployment order.
A second claim requires even firmer handling. The broadcaster reporting cited by Xinhua suggests a possible compromise involving an officer of the Defence Force, holding the rank of captain, stationed at Okahandja. The officer is said to have possibly clicked on a malicious link. The language of that report is conditional throughout. It describes a line of inquiry, not a finding.
No investigating authority has confirmed that account, and no disciplinary process has been announced. The responsible position is that the point of initial entry remains undetermined. Premature blame directed at one serving officer would be unjust and strategically unhelpful. Institutions that hunt for an individual to punish rarely fix the system that failed.
The shape of what was taken
The question asked most often after a breach concerns volume. How much was stolen? On the present record, that question cannot be answered.
The monitoring page for the listing carries an exposure report compiled by a third party research service. That report records a small number of passwords and a larger number of browser cookies associated with the domain. Those figures measure credential exposure detected in the wild. They are not a measure of the volume of material removed from the ministry. To present them as such would be to mislead.
No verified figure in gigabytes or in file counts has been published. The absence matters. In the Telecom Namibia case of December 2024, the volume was eventually fixed at 626.3 gigabytes. That figure allowed the public to judge the seriousness of the failure. No equivalent figure exists yet for the defence case.
Who are RansomHouse
RansomHouse emerged in late 2021. It is best understood not as a gang of intruders but as a platform. The core operators build and maintain tooling, infrastructure and a leak site. Affiliates conduct the actual intrusions and share the proceeds.
The group has an unusual signature. For much of the period since 2021, RansomHouse did not encrypt at all. Analysts at Fortra note that the group often skips encryption entirely, preferring simply to steal the data. A profile published by Malwarebytes makes the same observation, and records that the group explicitly denied using ransomware despite the name it chose.
That posture has shifted. Threat intelligence published by Halcyon describes three phases. The first, to the middle of 2023, was theft only. The second added an encryption tool known as Mario. The third, from 2024 onward, built a structured affiliate programme.
The public persona of the group shapes how victims are treated. RansomHouse describes itself as a professional mediators community. It asserts that the culprits are not those who found the vulnerabilities, but those who failed to prioritise security. Victims should expect that vocabulary in any negotiation.
Scale and method
By September 2026, monitoring services listed 209 victims for RansomHouse. The sectors most affected were manufacturing, professional services and healthcare. The country most affected, by a wide margin, was the United States. The victim listed immediately after the Namibian entry was Pertamina, the national energy company of Indonesia.
The technical method is documented, and is directly relevant to Namibia. Halcyon records that the group gains initial access by exploiting unpatched edge appliances. The named products include Citrix NetScaler, Palo Alto GlobalProtect and Check Point security gateways. These devices sit at the boundary of a network.
After entry, the pattern involves harvesting credentials, moving sideways, and removing multiple terabytes to commercial cloud storage. Where encryption is used, the tooling targets virtualisation hosts directly. The edge device is the modern castle gate. In too many African public institutions, it is a gate bought once, installed once, and then never inspected again.
Who stands behind RansomHouse
This is the question the public most wants answered. It is also the question where speculation does the most damage. The evidence supports several propositions at different levels of confidence. They should be set out separately, and never merged.
Proposition one: a Russian speaking criminal enterprise
This proposition carries the strongest evidentiary support. A detailed study by the threat intelligence firm Analyst1 concluded that the group comprises Russian speaking actors, as evidenced by the language used. The same study recorded connections originating from servers based in Russia, alongside other technical artefacts.
Halcyon reaches a compatible assessment. It records that Russian speaking operators run the group, and cites targeting patterns together with activity on the Russian language RAMP forum. RAMP is a well known marketplace where affiliates are recruited and access is traded.
Two independent commercial assessments therefore converge. That is meaningful. It is not the same as proof. Language and infrastructure can be adopted deliberately to mislead, and this is a known practice in the field.
Proposition two: state alignment without state direction
A more contested proposition holds that the group operates with a degree of political alignment. The Analyst1 study documented amplification of affiliated material by pro Russian Telegram channels with large audiences. It also recorded the use of bulletproof hosting services in Russia.
Analyst1 concluded that three factors point towards the likelihood of potential state involvement. Those factors are the alignment of the activities of the group with state objectives, the support from pro Russian media channels, and the historical precedent of state supported cyber activity. The firm then qualified that conclusion. It stated that the question of state involvement remains uncertain, and requires additional strong evidence.
That qualification must be carried into any Namibian discussion. The most defensible reading of the open evidence is tolerance rather than tasking. Certain jurisdictions decline to prosecute criminal groups that avoid domestic targets. Tolerance is not the same as instruction, and the difference matters in diplomacy.
Proposition three: a state sponsored access broker in the supply chain
A third proposition is documented in an official advisory, and is therefore worth stating precisely. On 28 August 2024, three agencies of the United States issued a joint advisory numbered AA24-241A. They were the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and the Department of Defense Cyber Crime Center.
The advisory concerns Iran based cyber actors known variously as Pioneer Kitten, Fox Kitten, UNC757, Parasite, RUBIDIUM and Lemon Sandstorm. It states that these actors have been observed to be collaborating with ransomware groups including NoEscape, RansomHouse and ALPHV, also known as BlackCat, to extort their victims.
The relationship described is specific. A state linked group obtains access to networks. It then sells or passes that access to criminal extortion operations, which monetise it. The advisory concerned targeting of organisations in the United States and the Middle East.
The caution here must be emphatic. Nothing in that advisory concerns Namibia. Nothing suggests that an Iranian linked broker supplied the access used against the Ministry of Defence and Veterans Affairs. The advisory establishes only that the affiliate structure of RansomHouse has accepted access from a state linked actor. That is a reason to investigate. It is not a finding.
Proposition four: an opportunistic affiliate of unknown nationality
The final proposition is the least dramatic and, on the balance of probabilities, the most likely. Under an affiliate model, the person who breached the network may have no connection to the founders of the platform. Affiliates are recruited on forums. They are paid a share. They select targets by scanning the internet for exposed and unpatched devices.
On that reading, Namibia was not selected for strategic reasons. A vulnerable appliance was found by an automated scan, and it happened to sit in front of a defence network. The intruder may be of any nationality, including a nationality from within the region. This possibility is unglamorous. It is also the pattern that fits the majority of documented cases.
What the evidence does not support
Three claims should be resisted, because they are currently unsupported.
- There is no published evidence that a foreign state directed an operation against Namibia. The observable motive is financial extortion.
- There is no published evidence identifying any individual. No arrest has been announced. Naming individuals on the basis of rumour would be defamatory and reckless.
- There is no published evidence that the attack forms part of a coordinated regional campaign against Southern African defence establishments. The regional record shows multiple syndicates acting separately.
A fourth possibility deserves mention precisely because it has not been excluded. Insider facilitation, whether deliberate or negligent, is a standard line of inquiry in defence breaches. The unverified report concerning an officer at Okahandja falls into the negligent category if it proves accurate. A deliberate insider remains an open question that only the investigation can close.
Why a defence ministry is not an ordinary victim
Public commentary after a breach tends to focus on identity theft. That focus is adequate for a telecommunications operator. It is inadequate here. Harm from a defence breach is different in character, and unfolds over years rather than weeks.
Counterintelligence value
Defence records reveal structure. They show who reports to whom, which units exist, where they are based, and what they lack. A foreign intelligence service that obtains such material does not publish it. It files it.
Procurement records are particularly sensitive. They reveal which systems were purchased, from which supplier, at what price, and on what maintenance schedule. A maintenance schedule indicates when a capability is unavailable. That is operational intelligence of a high order, derived from ordinary administrative paperwork.
Personnel data and the risk of coercion
A folder marked Personal, if it contains what the name suggests, is the most dangerous category of all. Personnel files record debts, medical histories, disciplinary records, family details and home addresses. Every one of those categories is an instrument of coercion in the hands of a hostile service.
The threat is not hypothetical, and the region has seen it before. An officer with concealed debt is a recruitment target. An officer with a concealed medical condition is a blackmail target. Once such records circulate, the exposure of the individuals concerned does not expire. It persists for the remainder of a career. Stolen equipment can be replaced within a budget cycle. A stolen personnel file cannot be recalled. It remains available to every adversary for the rest of a career.
Financial records and the integrity of the state
A folder marked Financials raises a second order of risk. Defence budgets in Namibia are substantial. The Ministry of Defence and Veterans Affairs was allocated approximately N$7.49 billion under Vote 8 for the financial year 2025/2026. More than 60 per cent of that allocation was assigned to personnel expenditure. About 22 per cent went to goods and services, and about 18 per cent to capital assets and infrastructure.
Detailed financial records permit two kinds of exploitation. The first is fraud, through impersonation of suppliers and diversion of payments. The second is political, through selective release of material designed to embarrass.
The confidence of partners
The least visible cost may prove the most expensive. The Namibian Defence Force, established on 2 June 1990, maintains cooperation with several partners. It participates in regional arrangements under the Southern African Development Community. It has procured equipment from suppliers including China, Brazil, Russia, India and the United States.
Every such partner shares information on the assumption that it will be protected. A confirmed breach of a defence network causes partners to reassess that assumption. The reassessment is rarely announced. It shows itself in the quiet narrowing of what is shared, and in the slower approval of joint activity.
A pattern, not an accident
The most important observation about this incident is that it is not isolated. It is the third publicly confirmed compromise of a significant Namibian institution within twenty one months.
In December 2024, Telecom Namibia, the state owned operator, was attacked by the Hunters International group. The intrusion was detected on 11 December 2024. The company refused to pay. The attackers published the material. Local reporting established that more than 619,000 clients were affected, and that 626.3 gigabytes were exposed.
Stanley Shanapinda, then Chief Executive Officer of Telecom Namibia, was unambiguous about the refusal to pay. He stated that the company does not negotiate with cyber terrorists, and that the sums demanded were exorbitant and unaffordable.
The Presidency responded through Alfredo Hengari, who said that any threat to the security architecture of the country, including cyberattacks, is dealt with the urgency it deserves. An investigation was announced involving the responsible ministry, the regulator, the police and the company.
In March 2026, the Namibia Airports Company was compromised, and material was published on the dark web. Reporting identified the INC group as responsible. The material was said to include permit system files, engineering documentation, financial records and internal reports. The company noted that the data raised serious concerns about the exposure of operational intelligence.
Three sectors have now been struck in sequence. Telecommunications, aviation and defence are, in every recognised framework, critical national infrastructure. The sequence suggests a national exposure rather than three unrelated misfortunes.
The legal vacuum
Namibia has responded to each of these events with investigation and advice. It has not been able to respond with prosecution, because the statutory instruments do not yet exist in force.
At the time of the Telecom Namibia breach in December 2024, the national response team noted publicly that Namibia lacked dedicated cybercrime and data protection legislation. That position has improved, but it has not been resolved.
Reporting published in 2026 records that the Cybercrime Bill has completed drafting, and that it is expected to reach Parliament following a validation workshop. The Data Protection Bill has received approval at cabinet committee level, and has been referred to the Ministry of Justice and Labour Relations for further review. Earlier reporting indicated an intention to table the Data Protection Bill during 2025.
The practical consequence deserves to be stated without softening. A country without a data protection statute has no legal obligation to notify the people whose records were taken. A country without a cybercrime statute has a weakened basis for mutual legal assistance with foreign jurisdictions. Both gaps are being felt now.
There is a countervailing concern that must also be recorded, in fairness. Namibian journalists have argued publicly that the draft Cybercrime Bill carries risks for press freedom. Those concerns have been raised in the national press. A bill passed in panic after a defence breach is more likely to contain such flaws than a bill passed after proper scrutiny. Urgency is a reason to legislate carefully. It is never a reason to legislate carelessly.
The institutional question
Nam-CSIRT has performed in this episode broadly as designed. It detected or received notice of unauthorised activity. It attributed the activity. It communicated publicly within days. It is supporting restoration. Those are the correct actions in the correct order.
The question is not competence. The question is architecture. Nam-CSIRT is hosted by the communications regulator, and its natural constituency comprises licensees and operators. A defence network is a different proposition. It requires classified handling, cleared personnel and a chain of custody that survives military and judicial scrutiny.
Mature systems separate these functions. A national computer emergency response team serves the civilian economy. A defence cyber command, or an equivalent military unit, protects military networks and answers to the military chain of command. The two cooperate, but they are not the same body.
Namibia does not appear to have a publicly identified military cyber defence unit with such a mandate. If such a capability exists, it has not been described publicly, and it did not feature in the public response to this incident. This is the single most significant structural finding available from the episode.
The measure of preparedness
International assessment confirms the picture. The Global Cybersecurity Index published by the International Telecommunication Union for 2024 placed Namibia in Tier 4, described as evolving.
The pillar scores tell a sharper story than the headline. Reporting on the index recorded legal measures at 5.66, technical measures at 3.54, organisational measures at 16.35, capacity development at 4.57, and cooperation measures at 6.81. The organisational score is respectable. The technical and capacity scores are very low.
A discrepancy should be flagged. One Namibian publication reported an overall score of 37.93, while another reported 36.93. The difference is immaterial to the argument, but readers deserve to know that the published figures are not identical. The tier placement is consistent in both reports.
The interpretation is straightforward. Namibia has built policies, strategies and a response team. It has not built the technical depth or the trained workforce to defend the systems those policies describe.
The continental context is consistent. The Interpol Africa Cyberthreat Assessment Report, published on 23 June 2025, found that around 95 per cent of surveyed African countries reported inadequate training, resources and specialised tools. About 75 per cent reported the need for improved legal frameworks and prosecution capacity. Two thirds reported that cyber offences account for a medium to high share of all recorded crime.
What should now happen
The following programme is offered as a considered view, arranged in order of urgency.
- Establish the scope before speaking further about volume. The ministry should complete a forensic determination of what was accessed and removed. Public statements about scale should follow that determination.
- Notify affected personnel directly, and early. Members should be warned about targeted approaches, unexpected contact from strangers, and attempts at coercion.
- Audit every edge device in government immediately. Remote access appliances should be inventoried, checked for current software, and reconfigured. The documented method of this group begins at precisely these devices.
- Enforce multiple factor authentication across the defence estate. Credential theft is the common second stage in the documented pattern.
- Segment the networks. Command, financial and personnel systems should not be reachable from one another by an intruder holding one set of credentials. Segmentation limits a breach to a room rather than surrendering the building.
- Create a military cyber defence capability with a clear mandate. It should sit within the defence structure, answer to the military chain of command, and cooperate with Nam-CSIRT under a written protocol.
- Pass the Data Protection Bill and the Cybercrime Bill, with proper scrutiny. That scrutiny should include the concerns raised by the press about the cybercrime provisions.
- Mandate reporting for critical infrastructure, within a fixed period, and with penalties for concealment.
- Invest in people, not only in equipment. The technical and capacity scores of Namibia are the lowest of the five pillars. Bursaries, secondments and a defined career path for state cybersecurity officers would address the deficit at source.
- Report to Parliament. The National Assembly should receive a formal report, in open session where possible and in closed session where necessary.
The questions that deserve answers
An analytical piece should end by naming what it could not establish. The following questions remain open, and the public interest in each is legitimate.
- What volume of material was removed from the ministry, and over what period was access maintained before detection?
- Were classified records held on the compromised systems, and if so, at what level of classification?
- What was the point of initial entry? Was it an unpatched edge appliance, a stolen credential, a phishing message, or an insider?
- Has a ransom been demanded, and what is the position of the government on payment? The Telecom Namibia precedent of refusal is a useful benchmark.
- Which foreign partners have been notified, and what arrangements have been made to reassure them?
- Does Namibia possess a military cyber defence unit, and if not, when will one be established?
The people whose records may now sit in a criminal archive are citizens before they are soldiers. They are entitled to know what happened to their information. Taxpayers who fund Vote 8 are entitled to know what was lost. Silence protects the institution in the short term. Over time it corrodes the trust on which every defence force depends.
Namibia has been fortunate so far. Three major institutions have been breached, and no life has been lost. The fortune should not be mistaken for a strategy. The next intrusion may reach a system that controls something rather than merely records it. The preparation for that day begins with an honest accounting of this one.
Silas Mwaudasheni Nande is a Namibian school principal, a doctoral candidate in education, and an analytical writer on African governance, justice and public policy. The views expressed are personal.
Similar Posts by The Mt Kenya Times:
- Inspired by the poem “Time”
- The use of digital educational technologies in the prevention of dental diseases
- Behind the visor: How Nairobi’s ‘Brayo Oyaah’ is redefining Kenya’s road safety culture
- Trauma, Friendship, Love, and the Search for Self-Worth in Hanya Yanagihara’s A Little Life
- Kenya’s scouting laws face overhaul: Kiarie leads push to align movement with devolved governance