Ransomware victim disclosure
← All victimsMinistry of Agriculture and Land Reclamation (Egypt)
listed as moa.gov.eg · Claimed by LockBit · listed 3 months ago
Status timeline
- Listed
Feb 23, 2026
- Data leaked
At a glance
- Group
- LockBit
- Status
- Data leaked
- Country
- Egypt
- Sector
- Public Sector
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileThe Ministry of Agriculture and Land Reclamation is an Egyptian governmental body responsible for agricultural policy, land reclamation, veterinary services, food security, and rural development across Egypt. It oversees agricultural research centres, licensing of animal and poultry production, fertiliser distribution, and international agricultural cooperation. The ministry operates nationwide through regional agricultural directorates.
- Industry
- Government – Agriculture & Land Reclamation
- Address
- Cairo, Egypt
Attack summary
Severity: critical — The victim is a national government ministry; data_published status confirms exfiltration and public release of government data, which likely includes sensitive administrative, personnel, and policy records from a sovereign public-sector entity — meeting the threshold for critical severity.LockBit claims to have attacked the Ministry of Agriculture and Land Reclamation of Egypt, with the disclosure status recorded as data_published, indicating that exfiltrated data has been released or made available; no ransom amount or specific data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Government administrative records
- Agricultural licensing data
- Veterinary services records
- Land reclamation project files
- Internal ministry documents
- Staff/personnel records
- Tender and auction documents
- Annual reports and research studies
What the group claims
The Ministry of Agriculture and Land Reclamation is a governmental body focused on advancing agricul...
Sources
- Victim sitemoa.gov.eg
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
