Ransomware victim disclosure
← All victimsNile Petroleum Corporation (NILEPET)
listed as nilepet.com · Claimed by Krybit · listed 6 days ago
Status timeline
- ListedJul 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Krybit
- Status
- Data leaked
- Country
- Egypt
- Sector
- Retail & E-Commerce
- Listed on leak site
- Jul 23, 2026
About the victim
AI dossier — public-source company profileNile Petroleum Corporation (NILEPET) is the state-owned national oil and gas company of the Republic of South Sudan. The company operates across exploration and production (E&P), downstream operations (begun May 2012), training and development, and retail/marketing of petroleum products. NILEPET also oversees joint operating companies and community development initiatives.
- Industry
- Oil & Gas Exploration, Production, and Downstream
- Address
- P.O. Box 390, Plot 496-Block no. 3k, Opp. Arkel Restaurant, Off Airport-Ministries Road, Juba, South Sudan
Attack summary
Severity: medium — State-owned critical infrastructure (national oil & gas company) with confirmed data publication, but no specific proof count, data inventory detail, or confirmation of sensitive data exfiltration provided in the available post. Potential regulatory/national security significance given South Sudan government ownership.The ransomware group Krybit claims to have breached NILEPET and published data. No specific details on encryption status, exfiltration scope, or data types are provided in the truncated leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate/operational records
- Potentially financial or personnel data
What the group claims
Nile Petroleum Corporation (NILEPET) is the state-owned national oil and gas company of the Republic of South Sudan, est...
Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

