ransomware Credible Namibia (NA) retail

Cymot listed by the Qilin ransomware group

Cymot

📅 25 January 2026
CompanyCymot
Domaincymot.com
CountryNamibia (NA)
Sectorretail
Breach date2026-01-25
People affected250,000
Ransomware groupqilin
Data typescustomer data, corporate records, financial information

Overview

The Qilin ransomware group has listed Cymot, a Namibian retail group operating cymot.com, on its leak site. The listing appeared on 25 January 2026. At the time of analysis, the group's leak page was not reachable.

What was published

The group has listed the company as a victim but has not published detailed data descriptions at this stage. Retail operations hold customer records, corporate documentation and financial information, which are the likely contents of any exfiltration.

Risks for affected individuals

  • Customer personal data may be exposed.
  • Financial records could enable fraud.
  • Employees' information may be included.

What remains unknown

  • Whether data has been exfiltrated.
  • The volume of records involved.
  • The timeline of any release.

What affected people should do

Customers should monitor their accounts and be cautious of unsolicited communications. Cymot should notify affected customers and staff, review compromised systems, and report the incident to Namibian authorities.

Sources

  • http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/view?uuid=f0d8521b-e802-3471-988c-596f0c885439