ransomware
Credible
South Africa (ZA)
telecom
Megasurf listed by the Krybit ransomware group
Megasurf
CompanyMegasurf
Domainmegasurf.co.za
CountrySouth Africa (ZA)
Sectortelecom
Breach date2026-04-08
People affected1,000,000
Ransomware groupkrybit
Data typessubscriber data, network records, corporate information
Overview
The Krybit ransomware group has listed Megasurf, a South African internet service provider and data centre operator, on its leak site. The company provides high-speed fibre and wireless internet services. The listing appeared on 8 April 2026.
What was published
The group claims to have exfiltrated data from the ISP. The archive is expected to include subscriber records, network configuration data and corporate information. The full dataset has not been released publicly at this stage.
Risks for affected individuals
- Subscriber personal data may be exposed.
- Network records could reveal infrastructure details.
- Employees' information may be included.
What remains unknown
- The volume of records involved.
- Whether the data has been published.
- The extent of the intrusion.
What affected people should do
Subscribers should be alert to phishing messages and monitor account activity. Megasurf should review affected systems, notify customers and regulators if subscriber data is involved, and communicate transparently about the incident.

Sources
- http://krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion/blog/0f09749244704dd7eda6e563ddd286eb4bd7ab0138dfefbc93a237c6179c0b21/