Ransomware victim disclosure
← All victimsSerengeti Estates
listed as www.serengetiestates.co.za · Claimed by Krybit · listed 1 day ago
Status timeline
- ListedAug 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Krybit
- Status
- Data leaked
- Country
- South Africa
- Listed on leak site
- Aug 7, 2026
About the victim
AI dossier — public-source company profileSerengeti Estates is a premier South African luxury residential golf and wildlife estate offering golfing experiences, fine dining, sports facilities, and secure residential properties. The estate features two world-class golf courses, multiple restaurants, and conferencing facilities, catering to retirees, professionals, and families seeking high-end leisure and lifestyle amenities.
- Industry
- Luxury Residential Golf & Wildlife Estate
- Address
- South Africa (exact address not disclosed; contact: +27 (0)11 552 7200)
Attack summary
Severity: medium — Data published status confirmed, but truncated leak post provides insufficient detail on proof volume or data sensitivity. Likely includes PII (customer names, contact info, property ownership) and business records from a private residential estate, but scale and regulatory sensitivity are unclear.The krybit group claims to have compromised Serengeti Estates and published data. The leak post is truncated and provides minimal detail on the scope of exfiltration or encryption; no specific data categories or operational impact are stated in the available excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- residential property records
- membership information
- customer contact details
- booking/transaction data
- golf membership records
What the group claims
Serengeti Estates (Serengeti Golf and Wildlife Estate) is a premier South African luxury residential golf and wildlife e...
Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

