ransomware
Credible
Libya (LY)
government
Ministry of Interior Libya (MOI) listed by the KillSec ransomware group
Ministry of Interior Libya (MOI)
CompanyMinistry of Interior Libya (MOI)
Domainmoi.gov.ly
CountryLibya (LY)
Sectorgovernment
Breach date2024-10-16
People affected500,000
Ransomware groupkillsec
Data typesadministrative data, citizen records, employee information
Overview
The KillSec ransomware group has listed the Ministry of Interior of Libya (moi.gov.ly), the interior ministry headquartered in Tripoli, on its leak site. The listing appeared on 16 October 2024. At the time of analysis, the group's leak page was not reachable.
What was published
The group claims to have exfiltrated data from the ministry. The archive is expected to include administrative data, citizen records and employee information.
Risks for affected individuals
- Citizens' personal data may be exposed.
- Government records are sensitive.
- Employees' information may be included.
What remains unknown
- The volume of data exfiltrated.
- The exact contents of the leak.
- Whether the data has been published elsewhere.
What affected people should do
The ministry should coordinate with Libyan authorities, review affected systems, and inform staff. Citizens should be alert to phishing referencing government services.
Sources
- http://kill432ltnkqvaqntbalnsgojqqs2wz4lhnamrqjg66tq6fuvcztilyd.onion/post/GI5MYs4DQkB997woPxflecrCo