ransomware Credible South Africa (ZA) government

National Credit Regulator (NCR) listed by the DragonForce ransomware group

National Credit Regulator (NCR)

📅 24 December 2025
CompanyNational Credit Regulator (NCR)
CountrySouth Africa (ZA)
Sectorgovernment
Breach date2025-12-24
People affected500,000
Ransomware groupdragonforce
Data typescredit industry records, regulatory data, employee information

Overview

The DragonForce ransomware group has listed the National Credit Regulator (NCR), the statutory body established under the National Credit Act 34 of 2005 to regulate the South African credit industry, on its leak site. The regulator registers credit providers, credit bureaus and debt counsellors. The listing appeared on 24 December 2025.

What was published

The group claims to have exfiltrated data from the regulator. The archive is expected to include registration records, regulatory data and employee information.

Risks for affected individuals

  • Credit industry professionals' records may be exposed.
  • Regulatory data is sensitive.
  • Employees' information may be included.

What remains unknown

  • The volume of data exfiltrated.
  • Whether the release is scheduled.
  • The response status of the regulator.

What affected people should do

The regulator should coordinate with South African cybersecurity authorities, review affected systems, and inform staff and registered entities. Industry participants should be alert to phishing referencing the regulator.

National Credit Regulator leak listing

Sources

  • http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/blog/?post_uuid=86439ee0-fe94-4bf3-8cf7-056c60e87c1d