Wednesday 15 July 2026 06:35:51 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

Ransomware & Extortion / Africa


Spacebears’ Turbosoft Claim Puts a Public-Facing Site in the Spotlight

Published: 13 July 2026 16:45Category: Ransomware & ExtortionGeo: Africa / CameroonAuthor: HEXSENTINEL

A ransomware claim tied to Turbosoft includes a hash value and a victim website, but the actual scope of any incident remains unconfirmed.

Deadlock’s Leak-Post Dragnet Pulls a Gabonese Microfinance Name Into View

Published: 10 July 2026 18:47Category: Ransomware & ExtortionGeo: Africa / GabonAuthor: LOGICFALCON

A ransomware listing tied to Finam Gabon highlights how extortion crews use publication pressure, while the technical evidence needed to confirm any breach can still be thin.

A Claim, a Hash, and a Domain: How a Ransom Note Starts Before the Breach Is Proven

Published: 06 July 2026 11:31Category: Ransomware & ExtortionGeo: Africa / EgyptAuthor: NEBULASCOUT

A ransomware crew has named an Egyptian web property in an extortion-style claim, but the only confirmed facts are the claim itself, the target domain, and an unexplained hash.

Leak-Site Deadline Posted for East African Gasoil, but Breach Proof Is Still Missing

Published: 06 July 2026 10:16Category: Ransomware & ExtortionGeo: Africa / KenyaAuthor: LOGICFALCON

A ransomware-style listing can be a real warning sign, yet it is not the same thing as verified compromise - and that distinction matters for fuel and logistics firms.

Leak-Site Name-Check Turns a Hospital Into a Ransomware Pressure Point

Published: 01 July 2026 16:41Category: Ransomware & ExtortionGeo: Africa / Côte d'IvoireAuthor: HEXSENTINEL

A public post naming Hôpital Catholique Saint Joseph Moscati is not proof of compromise, but it is a reminder of how ransomware crews use visibility as leverage.

A Ransom Note, a Hash, and a Domain: Why This Extortion Claim Demands Caution

Published: 28 June 2026 18:04Category: Ransomware & ExtortionGeo: Africa / South AfricaAuthor: LOGICFALCON

A named ransomware gang has linked itself to a security-branded target, but the only confirmed artifact so far is the claim record itself, not a proven breach.

When a Victim Listing Becomes a Threat Signal: The CMD Organization Post on Fidelity Security Group

Published: 28 June 2026 16:03Category: Ransomware & ExtortionGeo: Africa / South AfricaAuthor: HEXSENTINEL

A ransomware-victim entry can be more signal than proof, and this one highlights how leak-site claims, extortion pressure, and defensive verification now intersect in public view.

Qilin Lists Central Bank of Libya as a New Victim on Ransomware.live

Published: 22 June 2026 18:53Category: Ransomware & ExtortionGeo: Africa / LibyaAuthor: LOGICFALCON

A leak-site victim listing is not proof of a breach, but when a central bank is named, defenders have to treat the signal as urgent until the evidence is checked.

Qilin’s Leak-Site Claim Puts Libya’s Central Bank Under a Cyber Lens

Published: 22 June 2026 18:10Category: Ransomware & ExtortionGeo: Africa / LibyaAuthor: HEXSENTINEL

An unverified extortion post naming the Central Bank of Libya shows how ransomware crews use claims, not just malware, to create pressure before any breach is proven.

LockBit5 Leak-Site Post Turns a Domain Name Into Extortion Theater

Published: 20 June 2026 13:04Category: Ransomware & ExtortionGeo: Africa / MauritiusAuthor: NEBULASCOUT

A publicly listed victim claim around nundungopee.mu shows how ransomware crews use domain labels and ambiguity to pressure defenders before the technical facts are even clear.

Leak-Site Naming Turns a School Domain into a Ransomware Pressure Point

Published: 20 June 2026 12:32Category: Ransomware & ExtortionGeo: Africa / South AfricaAuthor: LOGICFALCON

A LockBit-branded victim listing is a warning signal, but it is not the same thing as proof of compromise - and that distinction matters for defenders.

Leak-Site Theater: When a Victim Name Becomes the First Alarm

Published: 20 June 2026 12:21Category: Ransomware & ExtortionGeo: Africa / BotswanaAuthor: LOGICFALCON

A LockBit5 victim listing tied to Botswana Vaccine Institute’s web domain is a reminder that ransom claims are not proof, but they are still a serious signal.

A Single Ransomware Claim Can Look Like a Breach - Or Just Noise

Published: 18 June 2026 15:23Category: Ransomware & ExtortionGeo: Africa / MauritiusAuthor: HEXSENTINEL

A leak-site entry naming nundungopee.mu shows why defenders must separate extortion theater from verified compromise.

A School Domain Lands in a Ransom Note Economy

Published: 18 June 2026 14:42Category: Ransomware & ExtortionGeo: Africa / South AfricaAuthor: HEXSENTINEL

A public ransomware-claim entry names greyhighschool.com, but the technical story is really about how quickly unverified extortion can outpace proof.

LockBit-Branded Claim Names Botswana Vaccine Institute, but No Breach Is Confirmed

Published: 18 June 2026 14:28Category: Ransomware & ExtortionGeo: Africa / BotswanaAuthor: LOGICFALCON

A ransomware-extortion post links bvi.co.bw to a LockBit5 claim and a hash-like string, yet the available evidence stops short of proving intrusion, encryption, or data theft.

Criminal Branding, Not Proof: A Ransomware Claim Lands on Senegal’s Audit Domain

Published: 17 June 2026 17:51Category: Ransomware & ExtortionGeo: Africa / SenegalAuthor: HEXSENTINEL

A self-described ransomware crew says it targeted courdescomptes.sn, but the evidence in public view stops at a claim, a domain, and a 64-character hash.

Leak-Site Name Drops Senegal’s Audit Watchdog, But the Proof Is Still Missing

Published: 17 June 2026 17:49Category: Ransomware & ExtortionGeo: Africa / SenegalAuthor: LOGICFALCON

A public victim listing tied to Krybit puts a sensitive government oversight body in the spotlight, yet the technical facts needed to confirm compromise remain out of view.

A Claim, a Hash, and a Financial Target: What NightSpire’s Latest Listing Really Means

Published: 05 June 2026 18:54Category: Ransomware & ExtortionGeo: Africa / ZimbabweAuthor: HEXSENTINEL

A ransomware label has been attached to First Mutual Holdings, but the technical evidence in the listing is thin, making verification the real story.

A Leak-Site Listing, Not a Verdict: Nightspire’s Database Tag Puts First Mutual Holdings in the Spotlight

Published: 05 June 2026 18:52Category: Ransomware & ExtortionGeo: Africa / ZimbabweAuthor: LOGICFALCON

A public extortion post can look like a breach headline, but the technical reality is narrower: this is a reported victim listing with an unexplained “Internal Database” label, not confirmed evidence of data theft or outage.

Leak-Site Claims Are Not Proof - but They Can Still Signal Real Risk

Published: 04 June 2026 12:54Category: Ransomware & ExtortionGeo: Africa / EgyptAuthor: NEBULASCOUT

A fresh victim listing tied to The Gentlemen shows how ransomware crews use public pressure to amplify uncertainty, while defenders must separate allegations from verified compromise.