Eservices.gov.zm listed by the Flocker ransomware group
Eservices.gov.zm
Overview
The Flocker ransomware group has listed Eservices.gov.zm, a Zambian government e-services portal, on its leak site. The group's post claims the portal's main servers, backup and internal network were compromised and all data exfiltrated. The listing appeared on 12 February 2025. At the time of analysis, the group's leak page was not reachable.
What was published
The group claims to have compromised the portal's main servers, backup and internal network, and to have exfiltrated all data. Government service portals hold citizen records and administrative data, which are the likely contents of the exfiltration.
Risks for affected individuals
- Citizen personal data may be exposed.
- Government systems data is sensitive.
- The claimed scope of the compromise is wide.
What remains unknown
- The volume of data exfiltrated.
- The exact contents of the leak.
- The response status of the government.
What affected people should do
The government should coordinate with Zambian cybersecurity authorities, review affected systems, and inform the public if citizen data is involved. Citizens should monitor official channels for statements and be alert to phishing.
Sources
- http://flock4cvoeqm4c62gyohvmncx6ck2e7ugvyqgyxqtrumklhd5ptwzpqd.onion/?p=384