Ransomware victim disclosure
← All victimsCFM - Caminhos de Ferro de Moçambique
listed as CFM Mozambique · Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 16, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Mozambique
- Sector
- Transportation/Logistics
- Listed on leak site
- Jan 16, 2026
About the victim
AI dossier — public-source company profileCaminhos de Ferro de Moçambique (CFM) is Mozambique's national railway and port authority, operating rail lines and ports across the country's northern, central, and southern regions. Its services encompass freight logistics, passenger transport, and port cargo handling at major facilities including Nacala, Beira, and Maputo. As a state-linked entity and SADC transport-protocol member, it plays a critical role in regional infrastructure.
- Industry
- National Railway & Port Infrastructure
- Address
- Praça dos Trabalhadores, Maputo, Moçambique
Attack summary
Severity: high — CFM is a critical national infrastructure operator (railways and ports) in Mozambique; confirmed data publication by Qilin indicates successful exfiltration from a strategically significant state-linked transport entity, posing high risk of sensitive operational, financial, and personnel data exposure.The Qilin ransomware group claims to have attacked CFM Mozambique and has published data (disclosed status: data_published), indicating exfiltration of company data. No specific ransom amount or data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Internal company documents
- Operational/logistics data
- Financial records
- Employee information
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

