Ransomware victim disclosure
← All victimsDepartment of Defence South African
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedAug 21, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- South Africa
- Sector
- Government
- Listed on leak site
- Aug 21, 2023
About the victim
AI dossier — public-source company profileThe Department of Defence of South Africa (DoD) is the national government department responsible for the defence and protection of South Africa. It encompasses the South African National Defence Force (SANDF) and administers military operations, personnel, and assets. The department operates under the Ministry of Defence and Military Veterans.
- Industry
- National Defence & Military Affairs
- Address
- Armscor Building, 370 Nossob Street, Erasmuskloof, Pretoria, 0181, South Africa
Attack summary
Severity: critical — The victim is a national defence/military government department. Any confirmed data exfiltration from a DoD entity constitutes a critical severity incident due to the potential exposure of classified or sensitive national security information, military personnel PII, and operational data.The Snatch ransomware group claims to have attacked the South African Department of Defence and has published data ('data_published' status), suggesting exfiltration of government/military files. No ransom amount or specific data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Government documents
- Military personnel records
- Internal communications
- Operational files
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

