ransomware Credible Senegal (SN)

Trésor Public listed by the AuditTeam ransomware group

Trésor Public

📅 10 May 2026
CompanyTrésor Public
CountrySenegal (SN)
Sector
Breach date2026-05-10
People affectedNot disclosed
Ransomware groupAuditTeam
Data typesNot disclosed

Overview

On 10 May 2026, a group operating under the name AuditTeam listed the Direction Generale de la Comptabilite Publique et du Tresor (DGCPT) of Senegal on its leak site. DGCPT is the Senegalese public treasury authority under the Ministry of Finance, responsible for public accounting, government fund management, cash flow and public debt operations. The listing targeted a core institution of the country's financial administration.

Leak site listing for Trésor Public

What was published

The AuditTeam listing presented the treasury authority as a victim and made a data archive available for download. Given the role of DGCPT, the leaked material may include accounting records, payment documents and administrative data held by the institution. The exact volume and contents of the archive were not fully inventoried at the time of analysis.

Risks for affected individuals

Public servants, suppliers to the Senegalese state and citizens whose data passes through treasury operations could be affected. Payment records, vendor details and administrative files in the wrong hands enable invoice fraud, phishing and identity misuse. The sensitivity of the institution raises the potential impact of the disclosure.

What remains unknown

The full contents and size of the released archive, the methods used by the attackers, and the response taken by Senegalese authorities are not fully confirmed. No official statement from the Ministry of Finance about the incident was observed.

What affected people should do

Suppliers and employees connected to the Senegalese treasury should verify payment instructions through official channels, watch for fraudulent invoices, and avoid opening unsolicited attachments that reference treasury documents. Organisations should monitor their accounts for unauthorised activity.

Sources

  • http://6tdqqaxftvradka5d2frzgwixis7fmro7rfh4ettzcx7jfapkebe6jad.onion/entity/A62A883688D9CFC1