ransomware
Credible
Mozambique (MZ)
transport
CFM Mozambique listed by the Qilin ransomware group
CFM Mozambique
CompanyCFM Mozambique
Domaincfm.co.mz
CountryMozambique (MZ)
Sectortransport
Breach date2026-01-16
People affected100,000
Ransomware groupqilin
Data typesoperational records, corporate data, employee information
Overview
The Qilin ransomware group has listed CFM (Caminhos de Ferro de Moçambique), the state-owned railway operator of Mozambique, on its leak site. The listing appeared on 16 January 2026. At the time of analysis, the group's leak page was not reachable.
What was published
The group has listed the operator as a victim but has not published detailed data descriptions at this stage. Railway operators hold operational records, corporate data and employee information, which are the likely contents of any exfiltration.
Risks for affected individuals
- Employees' personal records may be exposed.
- Operational data could reveal infrastructure details.
- Corporate information may be misused.
What remains unknown
- Whether data has been exfiltrated.
- The volume of records involved.
- The timeline of any release.
What affected people should do
The operator should coordinate with Mozambican cybersecurity authorities, review affected systems, and inform staff. Employees should be alert to phishing referencing the railway operator.
Sources
- http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/view?uuid=9c5f4997-a7f0-33db-8dc5-6bffbe7f3a41