Namibia's national cybersecurity agency has publicly confirmed unauthorized access to the Ministry of Defence and Veterans Affairs network and directly linked the intrusion to RansomHouse, an international cybercrime operation. The acknowledgment came after RansomHouse posted the supposed victim on its leak site on September 16, threatening to release confidential files and project documents unless officials made contact. The move to openly target a nation's defense apparatus represents an aggressive escalation even in the ransomware landscape.

NAM-CSIRT's analysis identified the incident as the work of RansomHouse, a criminal syndicate that deploys ransomware and uses double extortion methods in which hackers encrypt systems while simultaneously threatening to publish allegedly stolen information. RansomHouse listed the target as the "Namibian Defence Force" with $434 million in annual revenue, though the domain belongs to the Ministry of Defence and Veterans Affairs, the government department that oversees the military. The agency has not disclosed which systems or data were affected, whether information was stolen, or whether files were encrypted. Officials also declined to say whether a ransom demand was made or whether payment is being considered.

According to Emilia Nghikembua, chief executive of the Communications Regulatory Authority of Namibia and head of NAM-CSIRT, the team will support the ministry throughout investigation and recovery efforts. "The collective security of Namibia's digital ecosystem depends on timely reporting, proactive information sharing, and continuous investment in cybersecurity preparedness," she said. NAM-CSIRT emphasized it's coordinating technical support, investigation activities, remediation measures, and post-incident reviews in line with the national incident management framework. Nghikembua urged organizations across the country to report cyberattacks promptly so authorities can build a fuller picture of the threat landscape.

RansomHouse's tactic of double extortion gives attackers two forms of leverage: they can paralyze an organization by locking its files, and they can threaten reputational damage by publishing sensitive data. Many modern extortion attacks skip encryption entirely and rely solely on stolen information as leverage. Active since 2021, RansomHouse isn't among the most prolific extortion groups, but it has outlasted many rivals that appeared and disappeared during the same period. According to Halcyon's Ransomware Research Center, the group has listed a steady number of victims each year since it began operating, though it remains less active than dominant operations such as The Gentlemen and Qilin.

NAM-CSIRT's call for strengthened cyber defenses and closer collaboration reflects the challenge facing government agencies: even with robust security frameworks, determined adversaries can find entry points. The agency's appeal for organizations to work closely with national security teams aims to safeguard critical systems, data, and services that citizens rely on every day. Openly attributing an attack to a named group signals transparency, but the lack of detail about what was compromised leaves key questions unanswered as the investigation continues. Defense ministries everywhere face a delicate calculus when attackers hold sensitive national security information hostage, and the opacity of negotiations makes it difficult for observers to gauge whether paying ransoms emboldens future intrusions or whether refusing them risks catastrophic disclosure.