The Independent Patriots for Change and the Namibia Economic Freedom Fighters are demanding answers from the government on a recent ransomware attack on the Namibian Defence Force.
The calls follow The Namibian’s report last week on the hack, which took place last week on Saturday.
Cybercrime group RansomHouse has listed the NDF as one of its victims and claimed it had encrypted its computer systems.
The group published an ‘evidence pack’, which it claimed showed it had gained access to the NDF’s systems.
It also threatened to release confidential information unless the NDF contacted the group.
“A listing on a ransomware group’s leak site, on its own, does not establish that an organisation was successfully compromised or that sensitive information was actually exfiltrated,” says IPC shadow minister of defence and veterans affairs Aloisius Kangulu.
He says the matter needs attention because the NDF holds information on personnel, administration, logistics, communications and other defence-related activities.
Kangulu says any compromise of such systems could have implications beyond an ordinary cybersecurity incident.
He says the incident also raises questions about Namibia’s ability to prevent, detect and respond to cyberthreats.
Kangulu calls for properly funded cybersecurity structures, continuous monitoring, staff awareness and better coordination between defence, intelligence, law enforcement and cybersecurity authorities.
Last week, minister of defence and veterans affairs Frans Kapofi told The Namibian he was unaware of the extent of the attack and he had only been informed the ministry was experiencing difficulties accessing some information.
NEFF deputy president and member of parliament Kalimbo Iipumbu calls on the government to explain whether the NDF had been compromised and whether sensitive or classified information was at risk.
“This is not an ordinary cyberincident. The NDF is responsible for the defence of Namibia, and any compromise of its systems raises serious questions about the protection of our national security information.
“If an institution as sensitive as the NDF can be targeted, what about the rest of our critical government infrastructure?” he asks.
Iipumbu calls on Kapofi and minister of information and communication technology Emma Theofelus to explain what systems or information may have been accessed.
He also wants the government to explain whether the NDF has a dedicated cybersecurity team and what role the Namibia Cybersecurity Incident Response Team (Nam-CSIRT) has played in responding to the attack.
“National security cannot be left to chance. The government must urgently investigate this matter, secure all potentially affected systems, and assure the nation that our defence, intelligence and other critical state institutions are adequately protected,” Iipumbu says.
Nam-CSIRT, housed at the Communications Regulatory Authority of Namibia, on Friday confirmed it had detected unauthorised activity on the defence ministry’s computer network.
Nam-CSIRT said it is working with the ministry to investigate the attack, provide technical support and restore affected systems.
It is also reviewing the incident and working to strengthen the ministry’s cybersecurity.
In June, a global cybersecurity incident, known as FortiBleed, may have exposed administrator credentials and firewall configuration data at 13 Namibian organisations.








