ransomware
Credible
Namibia (NA)
retail
Cymot listed by the Qilin ransomware group
Cymot
CompanyCymot
Domaincymot.com
CountryNamibia (NA)
Sectorretail
Breach date2026-01-25
People affected250,000
Ransomware groupqilin
Data typescustomer data, corporate records, financial information
Overview
The Qilin ransomware group has listed Cymot, a Namibian retail group operating cymot.com, on its leak site. The listing appeared on 25 January 2026. At the time of analysis, the group's leak page was not reachable.
What was published
The group has listed the company as a victim but has not published detailed data descriptions at this stage. Retail operations hold customer records, corporate documentation and financial information, which are the likely contents of any exfiltration.
Risks for affected individuals
- Customer personal data may be exposed.
- Financial records could enable fraud.
- Employees' information may be included.
What remains unknown
- Whether data has been exfiltrated.
- The volume of records involved.
- The timeline of any release.
What affected people should do
Customers should monitor their accounts and be cautious of unsolicited communications. Cymot should notify affected customers and staff, review compromised systems, and report the incident to Namibian authorities.
Sources
- http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/view?uuid=f0d8521b-e802-3471-988c-596f0c885439