dpfza.gov.dj listed by the ransomhub ransomware group
dpfza.gov.dj
Overview
On 27 August 2024, the RansomHub ransomware group listed the Djibouti Ports and Free Zones Authority (DPFZA) on its data leak site. DPFZA manages the strategic ports and free zones of Djibouti, a country positioned as a logistics hub for East Africa and the Red Sea corridor. The listing was active on the group's leak blog for a period before the data deadline.
What was published
RansomHub presented DPFZA as a victim without detailing the volume of stolen records in the initial listing. The group operates a double-extortion model, threatening to publish exfiltrated files if a ransom is not paid. No archive or sample of the authority's data was publicly released during the observation window.
Risks for affected individuals
The authority handles shipping, customs and free zone operations, so documents involving port operators, logistics firms and government stakeholders could be at risk. Leaked commercial and administrative data could enable phishing, fraud and targeted attacks against organisations connected to the Djibouti port sector.
What remains unknown
The nature and volume of the exfiltrated data, the outcome of any negotiation, and whether the group later published files are not confirmed. DPFZA has not released an official statement describing the incident or its response.
What affected people should do
Businesses operating in Djibouti's ports and free zones should verify the integrity of contracts and credentials, and watch for communications claiming to originate from the authority. Staff should reset passwords and enable multi-factor authentication on all systems that interact with DPFZA services.
Sources
- http://ransomxifxwc5eteopdobynonjctkxxvap77yqifu2emfbecgbqdw6qd.onion/fc9f244d-90fa-481e-8722-d10f8be63125/