{"id":6834,"date":"2025-01-08T01:00:00","date_gmt":"2025-01-08T07:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ransomware-targeting-infrastructure-telecom-namibia"},"modified":"2025-01-08T01:00:00","modified_gmt":"2025-01-08T07:00:00","slug":"ransomware-targeting-infrastructure-hits-telecom-namibia","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/08\/ransomware-targeting-infrastructure-hits-telecom-namibia\/","title":{"rendered":"Ransomware Targeting Infrastructure Hits Telecom Namibia"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltaa0c5215b7706817\/65ef244e617a0b040a5e0628\/golden_dayz-africa-digital-security-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The telecommunications provider for the African nation of Namibia suffered a significant ransomware attack late last year, becoming a visible symbol of the merging of two trends in the region: increasing attacks on critical infrastructure and the growing threat of ransomware.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last month, Telecom Namibia alerted customers that a successful attack by the ransomware-as-a-service (RaaS) group Hunters International led to users&#8217; information being leaked online. The company is working with law enforcement agencies and third-party incident responders to uncover additional details, CEO Stanley Shanapinda <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.telecom.na\/media-centre\/816-update-on-cybersecurity-incident\">said in a Dec. 16 statement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Initially, it appeared that no sensitive information was compromised, but recent analyses confirmed that some customer data was compromised,&#8221; he said. &#8220;The threat was contained about three weeks ago and further attacks on our systems and third parties were prevented, [but the exposed information] was leaked on the dark web &#8230; after we refused to negotiate to pay any ransom that may have been demanded.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Namibia is not alone in becoming a target for cyberattackers focused on profiting off of compromised infrastructure systems. In June, South Africa&#8217;s National Health Laboratory Service (NHLS) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/south-africa-healthcare-lab-still-reeling-from-ransomware-attack\">suffered a ransomware attack<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that disrupted systems, deleted backups, and took weeks for the government-run network of healthcare testing laboratories to recover. In July, Hunters International exfiltrated more than 18GB of data <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.halcyon.ai\/attacks\/ransomware-attack-on-kenya-urban-roads-authority-by-hunters-international-data-breach\">from the Kenyan Urban Roads Authority (KURA)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The same month, the Nigerian Computer Emergency Response Team (ngCERT) warned that the Phobos RaaS group had <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/cert.gov.ng\/advisories\/escalation-of-ransomware-attack-in-nigeria\">targeted critical cloud services serving the country&#8217;s organizations<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, with at least one successful compromise.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Telecoms, Critical Infrastructure in the Crosshairs\">Telecoms, Critical Infrastructure in the Crosshairs<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Overall, ransomware accounted for a third of successful attacks in the region, including attacks on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.csidb.net\/csidb\/incidents\/681e31e6-08bd-4e0a-bdd0-4088b1ce2096\/\">energy firm Eneo in Cameroon<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in January 2024 and industrial organizations in Egypt and South Africa throughout the year, according to data from Positive Technologies, a cybersecurity firm that operates in the region.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The telecommunications and manufacturing sectors were also heavily targeted, with each sector accounting for 10% of successful attacks, says Alexey Lukatsky, managing director and cybersecurity business consultant at Positive Technologies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;These attacks are driven by factors such as rapid digital transformation, geopolitical tensions, and inadequate cybersecurity measures protecting critical infrastructure,&#8221; he says. &#8220;The increasing volume of user data and expanding digital networks make sectors like telecommunications particularly attractive targets for cybercriminals seeking financial gain or engaging in cyber espionage.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The trend will continue in 2025, because the rapid digitization across multiple industries continues to outpace implementation of cybersecurity measures, Lukatsky says. The result: a growing attack surface area that remains vulnerable.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Sectors such as energy, telecommunications, and manufacturing will continue to be prime targets for cybercriminals and APT groups, motivated by financial gain, data theft, or geopolitical objectives,&#8221; he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Age of RaaS\">The Age of RaaS<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The rise of ransomware-as-a-service offerings has also accelerated attacks on critical infrastructure, says Avinash Singh, a computer science lecturer and head of the Intelligent Cyber Forensics Lab at the University of Pretoria in South Africa. RaaS has taken off in Africa, partly because some ransomware gangs appear to be using African organizations as testbeds for their latest attacks, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/criminals-test-ransomware-africa\">according to an October 2024 report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The RaaS model allows attackers to focus on high-value targets, such as large corporations or critical infrastructure providers, where the potential ransom payout is significantly higher,&#8221; Singh says. &#8220;Cyberattacks on critical infrastructure remain among the most lucrative for cybercriminals, as these systems provide essential public services, and their disruption can cause significant societal and economic damage.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition, ransomware groups are not targeting just African businesses and government agencies, but also those organizations&#8217; third-party suppliers, Singh says. Distributing malicious versions of popular software has become a popular way to infect personal and business devices in the region. A March 2024 attack targeting members of a popular Discord community, for example, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/366575534\/Topgg-supply-chain-attack-highlights-subtle-risks\">infected developers with information-stealing malware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by compromising a developer&#8217;s account and poisoning the repository.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many of the threats affecting African developers are the same as those affecting the global cyber landscape, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Over the years, threat actors have demonstrated a broad array of tactics, techniques, and procedures, including hijacking GitHub accounts, malicious Python packages, setting up fake Python infrastructures, and employing sophisticated social engineering strategies,&#8221; Singh adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">African organizations need to work to improve the cyber awareness of their employees and customers and establish secure practices while pursuing digitization, he recommends. The risks posed by cyberattacks will likely only increase, as the geopolitical tensions rise in the region and worldwide, according to Singh.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While Africa may not be a prime target compared to other continents,&#8221; he says, &#8220;many geopolitical factors can influence cyber threat activities, particularly when state-sponsored actors are involved.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ransomware-targeting-infrastructure-telecom-namibia\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The telecommunications provider for the African nation of Namibia suffered<\/p>\n","protected":false},"author":12,"featured_media":6835,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6834","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?fit=1600%2C1067&ssl=1",1600,1067,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?fit=1600%2C1067&ssl=1",1600,1067,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/ransomware-targeting-infrastructure-hits-telecom-namibia.jpg?fit=1600%2C1067&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6834","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6834"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6834\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6835"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6834"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6834"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}