Ransomware victim disclosure
← All victimsSingita
listed as singita.com · Claimed by Dragonforce · listed 2 months ago
Status timeline
- ListedApr 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- South Africa
- Sector
- Hospitality and Tourism
- Listed on leak site
- Apr 2, 2026
About the victim
AI dossier — public-source company profileSingita is a South Africa-headquartered luxury hospitality company operating 10 lodges and 9 villas across prime wilderness areas in South Africa, Zimbabwe, Tanzania, Rwanda, and Botswana. Founded in 1993, the company is dedicated to environmentally conscious hospitality, sustainable conservation, and community collaboration. Singita offers exclusive, limited-guest wildlife experiences positioned at the ultra-luxury end of the African safari market.
- Industry
- Luxury Safari & Wildlife Conservation Hospitality
- Founded
- 1993
Attack summary
Severity: high — Data has been published (confirmed exfiltration) by DragonForce against a hospitality operator handling high-net-worth guest PII, booking/financial records, and potentially passport-level identity data typical of ultra-luxury travel clients, constituting significant business and personal data exposure.DragonForce claims to have exfiltrated data from Singita, with the disclosure status recorded as data_published, indicating stolen data has been released or made available. The specific data categories and volume exfiltrated have not been enumerated in the truncated leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Company data (type unspecified in post)
What the group claims
Singita is committed to providing unforgettable wildlife experiences, offering accommodations in lodges, camps, and private villas located in some of Africa’s most stunning and sought-after destinations. The company is committed to environmentally responsible hospitality and sustainable conservation, and has been working with local communities since its founding in 1993.
The leak post
captured from the group's site```
{"data":{"count":483,"publications":[{"uuid":"b008b8b7-0e47-416f-adcd-2313d8136de4","created_at":"2026-05-08T20:56:13.122134Z","name":"CF Evans Construction","website":"www.cfevans.com","address":"125 Regional Pkwy Ste 200, Orangeburg, South Carolina, 29118, United States","description":"A recognized leader in the multi-family housing construction industry, CF Evans Construction provides a product for developers. The company has thrived amid six decades.\nThe data of this company includes:\n Corporate correspondence of senior executives\n Financial documents\n HR documents\n Accounting documents\n Certificates, contracts, passwords, databases, and much more.","weight":4775795351552,"is_timer_publication_stopped":false,"timer_publication":"2026-05-22T07:48:00Z","try_again":false,"tags":[],"logo_uuid":"f4e582dd-6562-4590-bac8-2b9e5c564853","is_transfering":false},{"uuid":"3827192f-9bb3-490c-9c1c-d28b382510cd","created_at":"2026-05-08T17:53:24.736605Z","name":"CMC Expertise Comptable","website":"cmcexpertise.fr","address":"32 Rue De La Clairière, Fort-de-France,","description":"CMC Expertise Comptable is a certified accounting firm located in Martinique, dedicated t…Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

