ransomware Credible South Africa (ZA) telecom

Megasurf listed by the Krybit ransomware group

Megasurf

📅 08 April 2026
CompanyMegasurf
CountrySouth Africa (ZA)
Sectortelecom
Breach date2026-04-08
People affected1,000,000
Ransomware groupkrybit
Data typessubscriber data, network records, corporate information

Overview

The Krybit ransomware group has listed Megasurf, a South African internet service provider and data centre operator, on its leak site. The company provides high-speed fibre and wireless internet services. The listing appeared on 8 April 2026.

What was published

The group claims to have exfiltrated data from the ISP. The archive is expected to include subscriber records, network configuration data and corporate information. The full dataset has not been released publicly at this stage.

Risks for affected individuals

  • Subscriber personal data may be exposed.
  • Network records could reveal infrastructure details.
  • Employees' information may be included.

What remains unknown

  • The volume of records involved.
  • Whether the data has been published.
  • The extent of the intrusion.

What affected people should do

Subscribers should be alert to phishing messages and monitor account activity. Megasurf should review affected systems, notify customers and regulators if subscriber data is involved, and communicate transparently about the incident.

Megasurf leak listing

Sources

  • http://krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion/blog/0f09749244704dd7eda6e563ddd286eb4bd7ab0138dfefbc93a237c6179c0b21/