Ransomware victim disclosure
← All victimsGauteng Provincial Government
Claimed by kazu · listed 1 hour ago
Status timeline
- Listed
May 21, 2026
Current state: Listed for ransom
At a glance
- Group
- kazu
- Status
- Listed for ransom
- Country
- South Africa
- Sector
- Government
- Listed on leak site
- May 21, 2026
About the victim
AI dossier — public-source company profileGauteng Provincial Government is the provincial government authority serving Gauteng, South Africa's most populous province. It administers public services, infrastructure, and governance for the region.
- Industry
- Government Administration
Attack summary
Severity: medium — Government entity listing indicates potential sensitivity, but absence of proof files, data inventory, or confirmed exfiltration limits severity assessment. Listed alongside healthcare and financial entities suggesting data theft claim, but unsubstantiated.The kazu ransomware group lists Gauteng Provincial Government among claimed victims, but the leak post provides no details on attack method, data exfiltration, encryption, or specific compromised data.
The leak post
captured from the group's siteA847 8A8C E2A4 3B58 FB12 D678 3BA4 C334 C85C EE56 HealthDaq Dublin based healthcare recruitment platform Data Breach Spain - HT Médica Data breach Peru - Natclar (S.G. Natclar S.A.C.) SA - Gauteng Provincial Government Statistics South Africa – Official National Data and Insights Portal
Sources
Source
Indexed 1 hour agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
