Ransomware victim disclosure
← All victimsSemenya Furumele Consulting (Pty) Ltd
listed as Semenya Furumele Consulting Engineers · Claimed by Nightspire · listed 3 months ago
Status timeline
- ListedMar 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- South Africa
- Sector
- Construction
- Listed on leak site
- Mar 22, 2026
About the victim
AI dossier — public-source company profileSemenya Furumele Consulting (Pty) Ltd (SFC Engineers) is a Level 1 BEE civil and infrastructure consulting engineering firm established in 1995 in South Africa. The firm offers services across water, sanitation, waste management, transportation, buildings, municipal services, facilities management, and project management. Operating from six offices with national coverage, it also undertakes international projects.
- Industry
- Civil & Infrastructure Consulting Engineering
- Address
- Centurion, Gauteng, South Africa (head office; phone 012 643 0560)
- Employees
- 51-200
- Founded
- 1995
Attack summary
Severity: medium — Data is marked as published (data_published status), indicating exfiltration has been claimed, but the leak post content is unavailable and no specific data types, volume, or proof files are documented, preventing a higher severity classification.The Nightspire ransomware group claims to have attacked Semenya Furumele Consulting Engineers and lists the disclosure status as data_published, suggesting exfiltration and/or publication of company data; however, the leak post content is currently unavailable, limiting confirmation of specific claims.
What the group claims
Data is not available now.
Sources
- Victim sitewww.sfce.co.za
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

