ransomware Credible Cameroon (CM)

CNPS Cameroun listed by the spacebears ransomware group

CNPS Cameroun

📅 29 July 2024
CompanyCNPS Cameroun
Domaincnps.cm
CountryCameroon (CM)
Sector
Breach date2024-07-29
People affectedNot disclosed
Ransomware groupspacebears
Data typesNot disclosed

Overview

On 29 July 2024, the Space Bears ransomware group listed the National Social Security Fund of Cameroon (CNPS) on its leak site. CNPS is a Cameroonian public institution created on 7 June 1967, covering family benefits, old age, disability and death pensions, and professional risks. It operates under the supervision of the Ministry of Labour and Social Security.

Leak site listing for CNPS Cameroun

What was published

The Space Bears listing presented CNPS as a victim without disclosing the volume of data exfiltrated. Given the institution's role, the stolen material may include records of contributors, pension payments and administrative files. No archive linked to CNPS was observed during the analysis window.

Risks for affected individuals

Millions of Cameroonian workers and pensioners contribute to CNPS, and their personal data, salary histories and pension records could be highly sensitive if exposed. Such data enables identity fraud, phishing and fraudulent claims against the social security system.

What remains unknown

The full scope and contents of the exfiltration, and whether the group published files, remain unconfirmed. CNPS has not issued a detailed public statement about the incident at the time of analysis.

What affected people should do

Contributors and pensioners should be alert to unsolicited messages referencing their CNPS records and report them to the fund. Anyone concerned about fraud should contact CNPS through its official channels and monitor for unauthorised activity on their records.

Sources

  • http://5butbkrljkaorg5maepuca25oma7eiwo6a2rlhvkblb4v6mf3ki2ovid.onion/companies/36/cnps-cameroun