
Namibia’s Ministry of Defence and Veterans Affairs has been hit by a ransomware attack involving tactics that can include both encrypting systems and threatening to release allegedly stolen information, the Namibia Cyber Security Incident Response Team (NAM-CSIRT) has confirmed.
NAM-CSIRT said its analysis of affected systems established that the incident was associated with RansomHouse, a cybercriminal group known internationally for using so-called “double-extortion” tactics.
Under this type of attack, threat actors encrypt targeted systems while simultaneously threatening to disclose information they claim to have obtained from the victim.
The cybersecurity agency, which is housed at the Communications Regulatory Authority of Namibia (CRAN), confirmed that unauthorised activity had occurred within the Defence Ministry’s network environment.
NAM-CSIRT said it is coordinating technical support, investigations, remediation measures and post-incident reviews as authorities work to contain the impact and strengthen affected systems.
“Cybersecurity incidents of this nature serve as a reminder that no organisation, regardless of size or mandate, is immune to the evolving threat landscape. As Namibia’s national cybersecurity coordination centre, NAM-CSIRT remains committed to supporting the Ministry of Defence and Veterans Affairs and all affected stakeholders to ensure a thorough investigation, effective recovery, and the strengthening of cyber resilience across government and critical sectors,” CRAN Chief Executive Officer and Head of NAM-CSIRT Emilia Nghikembua said.
The response is being undertaken in line with the National Cyber Security Incident Management Guidelines, which provide for a coordinated approach to detecting, containing and recovering from cyber incidents.
NAM-CSIRT has also called on government institutions, operators of critical infrastructure and private-sector entities to strengthen cybersecurity measures, maintain incident-response plans, conduct regular security assessments and promptly report significant cyber incidents.
“The collective security of Namibia’s digital ecosystem depends on timely reporting, proactive information sharing, and continuous investment in cybersecurity preparedness. We urge all organisations to strengthen their cyber defences and work closely with NAM-CSIRT to safeguard critical systems, data, and services that citizens depend upon every day,” Nghikembua said.
NAM-CSIRT did not disclose in the statement what information may have been accessed, whether any data was stolen or encrypted, or the extent of disruption to the Ministry’s systems.







