Ransomware victim disclosure
← All victimsDepartment of Defence – South Africa
listed as Department of Defence South African (DARPA) · Claimed by Snatch · listed 3 years ago
Status timeline
- ListedAug 21, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- South Africa
- Sector
- Government
- Listed on leak site
- Aug 21, 2023
About the victim
AI dossier — public-source company profileThe Department of Defence of South Africa (mod.gov.za) is the national government department responsible for the defence and protection of South Africa, operating under the Minister of Defence and Military Veterans. It oversees the South African National Defence Force (SANDF), encompassing the Army, Navy, Air Force, and Military Health Service. As a sovereign defence institution it manages military operations, procurement, and classified national security matters.
- Industry
- National Defence & Military Affairs
- Address
- Armscor Building, 370 Nossob Street, Erasmuskloof, Pretoria, 0048, South Africa
- Founded
- 1994
Attack summary
Severity: critical — The victim is a national government defence department; the claimed exfiltrated data includes military contracts and internal call signs (operationally sensitive classified material) as well as personal data of likely military personnel — all categories representing a severe national security and PII breach at the highest level of sensitivity.The Snatch ransomware group claims to have exfiltrated data from the South African Department of Defence, asserting possession of military contracts, internal call signs, and personal data, with the disclosure status indicating the data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- Military contracts
- Internal call signs
- Personal data of personnel
What the group claims
Military contracts, internal call signs and personal data
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

