Ransomware victim disclosure
← All victimsRoad Transport Administration Department (RTAD)
Claimed by DYSPHOR1A · listed 6 days ago
Status timeline
- ListedSep 7, 2026
Current state: Listed for ransom
At a glance
- Group
- DYSPHOR1A
- Status
- Listed for ransom
- Country
- Myanmar
- Sector
- Government
- Listed on leak site
- Sep 7, 2026
- Data size
- 1.08 GB
About the victim
AI dossier — public-source company profileRoad Transport Administration Department (RTAD) is the official Myanmar government agency responsible for public transport services, driving license issuance, vehicle registration, and safety regulations.
- Industry
- Government Administration
Attack summary
Severity: high — Government agency compromised with 1.08 GB of databases exfiltrated. Road transport administration systems typically contain citizen PII, identification numbers, and vehicle ownership records at scale, affecting critical government functions and public safety infrastructure.DYSPHOR1A claims to have obtained a full databases dump of 1.08 GB from RTAD's systems. The group lists this as part of a broader multi-victim disclosure but provides no specific details on the content or nature of the exfiltrated data.
Data the group says was taken
AI dossier — extracted from the leak post- driving license records
- vehicle registration data
- transport administration databases
What the group claims
Official government portal providing public transport services, driving license issuance, vehicle registration, and safety regulations.
The leak post
captured from the group's site1.08 GB — full databases dump Road Transport Administration Department (RTAD) — official government portal providing public transport services, driving license issuance, vehicle registration, and safety regulations. Full databases dump total 1.08 GB. Victim domain https://rtad.gov.mm. Digital Wallet / Payment Platform Digital Wallet / Payment Platform Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. Compromised agent user information — total data size 30 GB. Price range $7,000 to $25,000. Victim domain https://ctzpay.com. 209,970 user records — full dump Myanmar Broadband Telecom Co., Ltd. (MBT) is a leading fiber internet service provider and telecommunications network solutions company established in Myanmar in 2013. Full database compromise exposing 209,970 user records including PII, passwords, and device information. Source code, IPs, payment databases, customer PII — full infrastructure Netim is a French domain name registrar and web hosting provider. Full compromise of internal systems — source code, infrastructure IPs, payment processing databases, customer PII,…
Data the group says was taken
- databases
Screenshot of the leak post

Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

