Ransomware victim disclosure
← All victimsKurdistan Regional Government (KRG)
listed as gov.krd · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Iraq
- Sector
- Public Sector
- Listed on leak site
- Mar 30, 2026
About the victim
AI dossier — public-source company profileThe Kurdistan Regional Government (KRG) is the official governing body of the Kurdistan Region of Iraq, headquartered in Erbil. It administers public services, education, finance, security, and digital transformation across the Kurdistan Region. The gov.krd portal serves as the central e-government portal for KRG ministries and public service delivery.
- Industry
- Regional Government Administration
- Address
- Erbil, Kurdistan Region, Iraq
Attack summary
Severity: critical — The victim is a regional government entity; the attack involves confirmed data publication (data_published status) against a public sector target with likely access to large volumes of PII (including payroll records for 760,000+ public employees referenced on the site), government administrative records, and potentially sensitive inter-governmental communications.LockBit 5 claims to have attacked the Kurdistan Regional Government, specifically referencing the Ministry of Higher Education and Scientific Research, with data published indicating exfiltration of government data; the status is listed as data_published.
Data the group says was taken
AI dossier — extracted from the leak post- Government administrative records
- Ministry of Higher Education data
- Public sector employee/payroll data
- Digital government service records
- Internal government communications
What the group claims
The Ministry of Higher Education and Scientific Research oversees higher education institutions in t...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

