Ransomware victim disclosure
← All victimsDepartment of Records Automation (DAF)
listed as DAF SENEGAL · Claimed by The Green Blood Group · listed 6 months ago
Status timeline
- ListedFeb 4, 2026
- Data leakeddate unknown
At a glance
- Status
- Data leaked
- Country
- Senegal
- Sector
- Public Sector
- Listed on leak site
- Feb 4, 2026
About the victim
AI dossier — public-source company profileDAF (Département de l'Automatisation des Fichiers) is a Senegalese governmental agency operating under the Ministry of the Interior and Public Security. It manages national population databases, issues biometric identity cards (CNI CEDEAO), and maintains critical civil registration systems.
- Industry
- Government Administration & Civil Registry
Attack summary
Severity: critical — Confirmed exfiltration of personally identifiable information (PII) at national scale. Biometric data, population records, and civil registration systems represent sensitive governmental data affecting potentially millions of citizens. Regulatory and national security implications are severe.The Green Blood Group claims to have breached DAF's systems. The post indicates exfiltration of data from national population databases and civil registration records, though specific data categories or volume are not detailed in the provided excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- national population database records
- biometric identity card data (CNI CEDEAO)
- foreign national identity documentation
- civil registration records
What the group claims
Department of Records Automation (DAF) is a Senegalese governmental agency operating under the Ministry of the Interior and Public Security. The agency manages national population databases, issues biometric identity cards (CNI CEDEAO), processes foreign national identity documentation, and maintains other critical civil registration systems.
Source
Indexed 6 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

