ransomware Credible Ghana (GH)

Volta River Authority listed by the blacksuit ransomware group

Volta River Authority

📅 07 March 2024
CompanyVolta River Authority
Domainvra.com
CountryGhana (GH)
Sector
Breach date2024-03-07
People affectedNot disclosed
Ransomware groupblacksuit
Data typesNot disclosed

Overview

The Volta River Authority (VRA), Ghana's main electricity generation and transmission body, was listed by the BlackSuit ransomware group in March 2024. The attack date recorded is 7 March 2024. VRA operates hydroelectric and thermal power plants that supply a substantial share of the country's electricity.

What was published

BlackSuit's listing identified VRA as a victim but did not disclose the volume of data exfiltrated. The group, which emerged from the former Royal ransomware operation, typically publishes selected stolen files after a negotiation deadline. No data archive from this incident was publicly released during the observation period.

Risks for affected individuals

VRA employees and contractors could face exposure of payroll, human resources and internal communications data. The authority's role in national infrastructure also raises the risk that operational documents related to power systems were taken, which could inform future social engineering campaigns against staff and suppliers.

What remains unknown

The scope of the exfiltration, whether operational data on the national grid was included, and the final outcome of the group's disclosure deadline are not confirmed. VRA has not published a detailed account of the attack or its investigation.

What affected people should do

VRA staff and business partners should treat unsolicited messages with caution, reset credentials for systems connected to the authority, and follow official communications from the organisation. Consumers should rely on VRA's official channels for any notices about services.

Sources

  • http://weg7sdx54bevnvulapqu6bpzwztryeflq3s23tegbmnhkbpqz637f2yd.onion/?id=ObPmwfVMqXdhy8Au