Ransomware victim disclosure
← All victimsMinistry of Agriculture and Land Reclamation (Egypt)
listed as moa.gov.eg · Claimed by Lockbit5 · listed 4 months ago
Status timeline
- ListedFeb 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Egypt
- Sector
- Public Sector
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileThe Ministry of Agriculture and Land Reclamation is an Egyptian federal government ministry responsible for agricultural policy, land reclamation, veterinary services, agricultural research, and food security initiatives across Egypt. It oversees licensing of animal and poultry production, fertilizer distribution, agricultural cooperative development, and international agricultural cooperation agreements. The ministry operates through a network of regional directorates covering all Egyptian governorates.
- Industry
- Government – Agriculture & Land Reclamation
Attack summary
Severity: critical — Target is a national government ministry; data_published status confirms exfiltration and public release of data. Likely contains PII of citizens, farmers, and civil servants at scale, as well as sensitive government operational and policy data from a sovereign state body.LockBit 5 claims to have compromised the Ministry of Agriculture and Land Reclamation of Egypt, with the disclosure status recorded as data_published, indicating exfiltration and publication of stolen data. No ransom amount or specific data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Government ministry internal documents
- Agricultural licensing records
- Land reclamation data
- Ministerial correspondence
- Potentially citizen/farmer PII from agricultural services
- Tender and procurement records
- Research and annual reports
What the group claims
The Ministry of Agriculture and Land Reclamation is a governmental body focused on advancing agricul...
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

