National Credit Regulator (NCR) listed by the DragonForce ransomware group
National Credit Regulator (NCR)
Overview
The DragonForce ransomware group has listed the National Credit Regulator (NCR), the statutory body established under the National Credit Act 34 of 2005 to regulate the South African credit industry, on its leak site. The regulator registers credit providers, credit bureaus and debt counsellors. The listing appeared on 24 December 2025.
What was published
The group claims to have exfiltrated data from the regulator. The archive is expected to include registration records, regulatory data and employee information.
Risks for affected individuals
- Credit industry professionals' records may be exposed.
- Regulatory data is sensitive.
- Employees' information may be included.
What remains unknown
- The volume of data exfiltrated.
- Whether the release is scheduled.
- The response status of the regulator.
What affected people should do
The regulator should coordinate with South African cybersecurity authorities, review affected systems, and inform staff and registered entities. Industry participants should be alert to phishing referencing the regulator.

Sources
- http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/blog/?post_uuid=86439ee0-fe94-4bf3-8cf7-056c60e87c1d