Four African financial firms turned up on ransomware leak sites in the seven days to 26 September: a South African insurer, a Kenyan insurance broker, a Ugandan credit bureau and an Ethiopian bank. In IntelFusions' incident tracking, the previous twelve weeks produced five African financial-sector claims in total. This week nearly matched that on its own.
It was a busy week for the continent generally. We recorded nine leak-site claims against organisations in eight African countries, posted by eight different crews. That is the highest weekly total for Africa since April, against a median of four over the previous twelve weeks. Our leak-site coverage keeps widening and the counts are small, so treat the comparison as indicative rather than exact.
Insurers, a bank and a credit bureau
The Gentlemen listed Guardrisk on 26 September; our record describes it as a South African specialist insurance group. Vexy listed Majani Insurance Brokers in Kenya on 25 September. A crew called Spirals listed Armada Credit Bureau in Uganda on 24 September, and LockBit listed Siinqee Bank, an Ethiopian lender, on 21 September.
The credit bureau is the listing to watch. A bureau's business is holding credit histories on people who never chose to deal with it directly, so if the claim is genuine, the exposure would reach well beyond the company's own clients. Nothing in the listing itself says what was taken, which is normal for these posts and tells you nothing about scope in either direction.
A national airline on the list too
Outside finance, Krybit listed Air Tanzania, the country's flag carrier, on 24 September, posting the airline's two web domains rather than a company name. Krybit is a crew we have noted before for drawing almost none of its victims from North America. The rest of the week was a spread: INC Ransom posted a Moroccan pharmaceutical domain, The Gentlemen also listed the Angolan holding company Grupolider, Black Locks listed a South African truck and trailer parts supplier, and N0n listed a Malian IT and document processing firm. One further listing filed under South Africa is excluded here because we could not confirm the organisation is African.
These are claims, not confirmed breaches
Every entry above comes from posts the gangs wrote about themselves, on infrastructure they control. We have seen no public confirmation from any of the organisations named, and a listing is an assertion about an intrusion rather than proof of one. The gangs have every reason to want it believed, since the whole scheme runs on pressure. The sites sit on .onion addresses, which we do not link.
Report to the regulator, not on the gang's clock
For a firm that finds its name on one of these sites, the useful steps are the unglamorous ones: preserve logs before they roll over, review remote access and administrator accounts, and bring in the regulator early rather than negotiate first. In South Africa that means the Information Regulator, and in Uganda the Personal Data Protection Office. Kenyan organisations have been here before: Deadlock listed the country's national roads agency in July.
One week of four financial listings is a spike, not yet a pattern, and the crews behind them have nothing in common beyond the week. What would turn it into a trend is a second week like it. Insurers and credit bureaus are worth the attention either way, because the data they hold belongs mostly to people who will never see the leak site.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.