Namibia's national cybersecurity team has confirmed that the Ministry of Defence and Veterans Affairs (MODVA) suffered a ransomware intrusion attributed to RansomHouse, the double-extortion operation that listed the Namibian Defence Force (NDF) on its dark web leak site in mid-September 2026. The Namibia Cyber Security Incident Response Team (Nam-CSIRT), housed at the Communications Regulatory Authority of Namibia (CRAN), said analysis of affected systems found unauthorised activity on the ministry's network and linked it to RansomHouse. Neither the group nor the government has published a data volume, a record count, or a ransom figure. The defence minister, Frans Kapofi, told The Namibian he had been informed only that staff were "experiencing difficulties accessing some of their information" and said the extortion threat itself was news to him.
Every source available for this brief is outlet or lower tier. There is no vendor advisory, no regulator filing, and no NDF statement. The Nam-CSIRT confirmation, relayed through The Namibian and Informanté, is the closest thing to authoritative material in the record, and it is weighted accordingly here.
What Happened
RansomHouse added the Namibian Defence Force (listed against the domain www.mod.gov.na) to its victim roster and posted a message aimed directly at NDF leadership, accusing the military's own IT staff of burying the incident:
"Dear management of the Namibian Defence Force. We were waiting for you for quite some time, but it seems your IT department decided to conceal the incident that took place in your company. We strongly recommend you to contact us to prevent your confidential data, projects documents from being leaked."
That framing matters operationally. It implies the intrusion predates the leak site listing by some margin, and that RansomHouse attempted contact before going public. It also suggests the attackers believed the compromise had been detected internally without being escalated, which is consistent with a minister who first heard of the extortion threat from a newspaper.
Nam-CSIRT publicly confirmed the unauthorised activity on Friday, characterising RansomHouse as an internationally known criminal syndicate that uses ransomware alongside double-extortion tactics: encrypting systems while threatening to publish allegedly stolen data. Nam-CSIRT said it is coordinating technical support, investigation, remediation, and a post-incident review with the ministry under Namibia's National Cyber Security Incident Management Guidelines. CRAN chief executive and Nam-CSIRT head Emilia Nghikembua said the case is "a reminder that no organisation, regardless of size or mandate, is immune to the evolving threat landscape."
What Was Taken
No source states a volume. RansomHouse has not published a byte count, file count, or victim record total, and the government has not characterised the scope of data loss.
What is described is the shape of the exposure rather than its size. The Namibian Broadcasting Corporation (NBC), relayed by Kayi News and Namibia Daily News via Xinhua, reported that files apparently originating from NDF-connected systems were circulating online late Friday, and that the leaked directory included folders labelled Commander, Defence, Military, Financials, and Personal, alongside other documents. The Namibian separately reported that RansomHouse published an "evidence pack" it claims demonstrates access to defence force systems, and that the group is explicitly threatening "confidential data" and "project documents."
Taken together, the folder labels point at command-level correspondence, operational or planning material, financial records, and personnel data. Personnel files on serving military members are the highest-consequence category here: they support targeting, coercion, and recruitment operations by foreign services long after any encrypted system is rebuilt. Treat the folder listing as a threat-actor-sourced claim relayed by a broadcaster, not as a verified inventory. Nam-CSIRT has confirmed the intrusion; it has not confirmed what left the network.
Where Accounts Differ
The record is genuinely inconsistent on timing and on the maturity of the leak, and it is worth stating plainly rather than smoothing over.
Date of the listing. The automated Yazoul Security report places the leak site listing "on or around September 12, 2026." Undercode News, citing a ThreatMon Threat Intelligence Team alert, gives a precise timestamp of approximately 23:11:29 UTC+3 on 16 September 2026, and says independent ransomware trackers also carry a 16 September date under the Government and Defense category. The Namibian, in its 20 September report, says the hack "took place on Saturday." These are not reconcilable from the sources available, and the dates of intrusion, of listing, and of publication are being conflated across outlets. The safest reading: the intrusion predates mid-September, the leak site listing surfaced in the 12 to 16 September window, and file circulation and official confirmation followed on 18 and 19 September.
Whether proof was published. Yazoul's automated report states that no proof-of-compromise samples, file trees, or negotiation details had surfaced and that the claim was "entirely unverified." That is contradicted by later reporting from The Namibian (an evidence pack), NBC (a directory listing with named folders), and Nam-CSIRT's own confirmation of unauthorised activity. The Yazoul assessment reads as an early snapshot that was overtaken by events.
RansomHouse's track record. Yazoul's automated profile describes RansomHouse as having "a limited public footprint," an unknown victim count, and no documented tooling, initial access vectors, or post-exploitation tradecraft. Nam-CSIRT, the national CERT, describes the same group as "internationally known." RansomHouse has been running data-extortion and leak site operations against large enterprises and public bodies since late 2021 and is well documented by mainstream threat intelligence vendors. Defenders should disregard the "unknown actor" framing; it appears to be an artefact of automated report generation rather than an intelligence gap.
Why It Matters
This is a national military ministry, and the extortion leverage is state information rather than customer PII. That changes the calculus in three ways.
First, there is no clean remediation path for exposure. A company can notify customers and offer credit monitoring. A defence force cannot un-disclose command correspondence, deployment planning, or the identities and personal details of serving officers. Cybersecurity expert Paulinus Sheehama, speaking to Desert Radio, framed the core unanswered questions correctly: authorities need to establish what was actually accessed, and whether the attackers still hold access to affected systems. The second question is the more urgent one, and no source indicates it has been answered.
Second, the internal reporting failure is as significant as the intrusion. RansomHouse's public accusation that the IT department concealed the incident, combined with the minister's admission that he was unaware of the extent of the attack or of the extortion threat, points to a breakdown between technical detection and political escalation. Criminal groups now routinely exploit that gap, publicising incidents specifically to force executive awareness and restart stalled negotiations.
Third, Namibia is responding without a completed legal framework. The Namibian reports that drafting of the cybercrime bill was said to be complete roughly six months ago with submission to parliament expected in March, and that in July the minister of information and communication technology, Emma Theofelus, said the cybercrime and data protection bills were being finalised. Neither is law. Nam-CSIRT is coordinating this response on guidelines rather than statute, which constrains mandatory reporting, enforcement, and cross-border cooperation. Nam-CSIRT's repeated public appeals for organisations to report major incidents promptly should be read in that light: it is asking for voluntary cooperation because it cannot yet compel it.
More broadly, defence and government entities in smaller states are attractive to financially motivated groups precisely because the data is high-leverage while the security budget is not commensurate. RansomHouse does not need to be a sophisticated operator to profit from that asymmetry.
The Attack Technique
The confirmed technical detail is thin. Nam-CSIRT has stated only that it found unauthorised activity on the ministry network and that analysis linked the incident to RansomHouse and its double-extortion pattern. The ThreatMon alert relayed by Undercode News provides no initial access vector, no affected systems, no encryption status, and no ransom demand.
The one substantive lead is unverified and single-sourced. NBC News reported, and Kayi News and Namibia Daily News repeated, that information gathered by the broadcaster suggests a possible compromise involving an NDF captain stationed in Okahandja who may have clicked a malicious link. This is reporting on an open investigation, not a finding. It is plausible and consistent with RansomHouse's typical reliance on commodity access rather than exotic exploitation, but it should not be treated as the established root cause.
What can be inferred from the actor's own message is a dwell time measured in weeks rather than hours ("we were waiting for you for quite some time"), enough lateral movement to reach command, financial, and personnel file shares, and successful exfiltration prior to any encryption event. That is the standard RansomHouse sequence: access, quiet staging and bulk exfiltration, then extortion, with encryption used as pressure rather than as the primary objective.
What Organizations Should Do
-
Answer the persistence question before the recovery question. Sheehama's framing is the right operational priority. Assume the adversary retains access until proven otherwise: hunt for web shells, scheduled tasks, new service accounts, unauthorised remote access tooling, and rogue VPN or federation trust relationships. Force a credential reset across privileged accounts, service accounts, and any identity that touched an affected system, and rotate Kerberos krbtgt and API keys. Restoring from backup into an environment the attacker still holds simply resets the clock.
-
Instrument for bulk exfiltration, not just encryption. RansomHouse monetises stolen data first. Alert on unusual data staging (large archive creation, compression on file servers), anomalous outbound volume to cloud storage and file transfer services, and access patterns where a single account suddenly enumerates large numbers of shares. These behavioural signals fire during the phase where intervention still prevents the leak. Do not wait for actor-specific signatures.
-
Segment command, financial, and personnel data. The folder labels in this leak (Commander, Defence, Military, Financials, Personal) describe an environment where one compromised endpoint reached several distinct sensitivity tiers. Enforce separate authentication boundaries and tiered administration around the highest-consequence shares, so a single phished officer's session cannot enumerate all of them.
-
Harden against the credential-phishing entry path. If the malicious-link account proves accurate, the controls that would have mattered are phishing-resistant MFA (FIDO2 or certificate-based, not SMS or push approval), conditional access that blocks legacy authentication, attachment and link detonation at the mail gateway, and application allowlisting on endpoints belonging to staff with access to sensitive shares.
-
Fix the escalation path, in writing. A minister learning about a military extortion threat from the press is a governance failure with a governance fix. Define a mandatory internal notification trigger, with a named escalation chain and a clock (hours, not days), that fires on suspected compromise rather than on confirmed compromise. Pre-authorise the decision to notify the national CERT so no one has to seek permission mid-incident.
-
Engage the national CERT early and contract retainers now. Nam-CSIRT is explicitly offering coordination, technical support, remediation, and post-incident review, and is asking to be told about major incidents quickly. For organisations without internal forensic capability, that relationship plus a pre-signed incident response retainer is the difference between a contained event and a public leak. Test the arrangement with a tabletop exercise that includes the extortion and media-handling phases, not just the technical recovery.
Sources: Hackers hit NDF: RansomHouse threatens state secrets - News - The... | Cyber team confirms NDF hack - News - The Namibian | RansomHouse ransomware attack confirmed in Defence Ministry network... | Namibian Defence Force Ransomware Claim by ransomhouse (Sep 2026) | RansomHouse Claims Namibian Defence Force as a New Ransomware Victi... | Namibian military hit by cyberattack | Namibia investigates reported cyberattack on defense force – Namibi... | NDF cyberattack raises national security concerns - Desert Radio