Namibia Cyber Security Incident Response Team — detects and responds to cyber threats and vulnerabilities, housed under the Communications Regulatory Authority of Namibia.
Key points drawn from coverage. Tap a point to see the original sentence.
July 2026
The Namibian
Nam-CSIRTdetected513,921 cyber vulnerabilities during April-June quarter
Source
“According to Nam-CSIRT's second-quarter cybersecurity newsletter, 513 921 cyber vulnerabilities were detected during the reporting period, representing a 39.8% increase from the previous quarter.”
Nam-CSIRTreported31.3% decline in cyber vulnerabilities in Q1 2026
Source
“Mufaro Nesongano, Executive: Communication and Consumer Relations, emphasised that detected cyber vulnerabilities across Namibia declined by 31.3%, while reported cyber threat events decreased by 47.3% during the period January to March 2026.”
NAM-CSIRTalerted13 Namibian organisations of exposure in FortiBleed cyber attack
Source
“The Namibia Cyber Security Incident Response Team (NAM-CSIRT) has alerted 13 Namibian organisations that their systems may have been exposed in connection with a major global cyber security incident known as FortiBleed, a large-scale attack that has compromised tens of thousands of internet security devices worldwide.”
NAM-CSIRTcontacted and provided guidance toall potentially affected organisations on securing systems
Source
“NAM-CSIRT, which is housed within the Communications Regulatory Authority of Namibia (CRAN), said it has already contacted all potentially affected organisations and provided guidance on measures to secure their systems and reduce the risk of unauthorised access.”
“The Namibia Cyber Security Incident Response Team on Saturday said it had been made aware of the international cybersecurity threat and identified the Namibian organisations that could be exposed.”
“The guidelines, developed by the Namibia Cyber Security Incident Response Team (NAM-CSIRT) under the Communications Regulatory Authority of Namibia (CRAN), were launched in Ondangwa under the theme "Building a Cyber Resilience Ecosystem."”
NAM-CSIRTconfirmed thatat least part of stolen data has been released online
Source
“Meanwhile, the Namibia Cyber Security Incident Response Team (NAM-CSIRT), operating under the Communications Regulatory Authority of Namibia (Cran), also confirmed that at least part of the stolen data has been released online.”
Namibia Cyber Security Incident Response Team (NAM-CSIRT)has confirmedsome data stolen during cyberattack on NAC has been published online
Source
“THE Namibia Cyber Security Incident Response Team (NAM-CSIRT) has confirmed that some of the data stolen during the recent cyberattack on the Namibia Airports Company (NAC) has been published online, as investigations continue to determine the full extent of the breach and whether sensitive information has been compromised.”
Namibia Cyber Security Incident Response Team (Nam-CSIRT)confirmed thatleaked data include financial records, internal reports and engineering documents
Source
“The Namibia Cyber Security Incident Response Team (Nam-CSIRT) – housed under Cran – has confirmed that data leaked include financial records, internal reports and engineering and project documents.”
Namibia recorded more than half a million cyber vulnerabilities between April and June, representing a 39.8% increase from the previous quarter, according to the Namibia Cyber Security Incident Response Team. The Communication Regulatory Authority chief executive urged organisations to tighten cybersecurity measures, implement national incident management guidelines, and report incidents early.
Namibia recorded more than half a million cyber vulnerabilities between April and June, representing a 39.8% increase from the previous quarter, according to the Namibia Cyber Security Incident Response Team. The Communication Regulatory Authority chief executive urged organisations to tighten cybersecurity measures, implement national incident management guidelines, and report incidents early.
Namibia's cyber security incident response team reported that detected cyber vulnerabilities declined by 31.3% and reported cyber threat events decreased by 47.3% during the first quarter of 2026, though exposed remote management services and legacy network protocols remain significant risks.
Namibia's cyber security incident response team has warned 13 local organisations that their systems may have been exposed in FortiBleed, a global cyber attack affecting tens of thousands of Fortinet FortiGate security devices worldwide. The incident exposed administrator usernames, passwords, remote access credentials and security settings, potentially allowing criminals unauthorised network access.
A cybersecurity incident called FortiBleed may have exposed administrator credentials and firewall configuration data at 13 Namibian organisations that use Fortinet infrastructure. The Namibia Cyber Security Incident Response Team identified the affected organisations and recommended they reset credentials, add multifactor authentication, and upgrade their Fortinet devices.
Data breached in a cyberattack on Namibia Airports Company has been released on the dark web by the INC Ransomware Group, including airport permits, parking databases, engineering files, and financial records. Authorities are investigating whether sensitive or personally identifiable information is among the leaked files and urge organisations to strengthen cybersecurity measures.
NAM-CSIRT has confirmed that data stolen in a cyberattack on Namibia Airports Company has been published online, with preliminary assessments indicating the leaked data may include airport permit records, parking management information, engineering documentation, financial records, and internal reports. The attack, detected on 6 March 2026, involved approximately 500GB of data and is linked to the INC Ransomware Group, marking the second known attack by this group in Namibia.
The Communication Regulatory Authority of Namibia (Cran) has called for responsible handling of information related to the Namibia Airports Company data leak, warning that circulation of unverified data may place individuals and organisations at further risk. The NAC was attacked by the Inc Ransomware Group on 19 March; leaked data includes financial records, internal reports, and engineering documents, though NAC says operations remain unaffected.
Namibia Airports Company has confirmed that data stolen in a March 2026 cybersecurity breach by the INC Ransomware Group has been released on the dark web. The leaked data may include airport permit systems, parking databases, engineering documents, and financial records; NAC is verifying the breach extent while airport operations remain unaffected.
The Namibia Airports Company suffered a ransomware attack by the INC Ransomware Group, with hackers claiming to have stolen 500 gigabytes of sensitive data including financial records, HR files, and customer information. The attackers have threatened to release the data after a countdown timer expires unless demands are met, making NAC the second confirmed Namibian victim of the group after an Otjiwarongo Municipality breach in 2025.
The Namibia Cyber Security Incident Response Team confirmed that hackers linked to the INC Ransomware Group unauthorisedly accessed Namibia Airports Company's network and stole approximately 500GB of data, including financial records, HR data, and customer information. The group uses "double-extortion" tactics involving data theft and system encryption, and has threatened to release the stolen data after a countdown period.
The Bank of Namibia has warned the public against a fraudulent investment scheme using a fake website impersonating a media outlet and falsely claiming endorsement by Deputy Governor Leonie Dunn. The central bank stressed that neither it nor the Deputy Governor endorses any investments and urged the public to verify information through official channels and avoid clicking suspicious links or sharing personal information.
The Namibia Airports Company (NAC) disclosed a cybersecurity breach detected on 6 March involving unauthorised network access, though airport services have been restored and there is no confirmed data theft. The incident prompted the Namibia Cyber Security Incident Response Team to issue a public advisory and call on all organisations to strengthen cyber resilience through enhanced security measures.
Namibia's cybersecurity team detected 535,204 cyber vulnerabilities during October–December 2025, a 4.28% decrease from the previous quarter, though phishing scams and ransomware threats remain persistent concerns. The team has identified emerging ransomware groups and emphasises the need for continued vigilance in protecting critical infrastructure.
Following a cybersecurity incident at Namibia Airports Company, the Communication Regulatory Authority of Namibia has urged organisations to tighten security by implementing robust controls, enforcing governance policies, activating multifactor authentication, and conducting continuous cybersecurity awareness training.
Namibia Airports Company detected a cybersecurity incident on 6 March 2026 involving unauthorised access to network infrastructure and administrative accounts. Services have been restored with limited operational impact, and there is no evidence of data exfiltration, though investigations continue; NAM-CSIRT and NAC are working together to enhance security resilience.
An executive from the Communications Regulatory Authority of Namibia argues that continuous monitoring of an organisation's external attack surface—all internet-facing digital assets and entry points—is essential to modern security. The article outlines key components to monitor including public-facing infrastructure, cloud assets, third-party connections, digital certificates, and exposed credentials.
The Namibia Cyber Security Incident Response Team, housed under Cran, hosted a Domain Name System Resilience Training from 17 to 20 February 2026 in Windhoek to strengthen DNS security awareness and response capabilities across the region, addressing vulnerabilities that pose significant threats to internet integrity including botnets, denial-of-service attacks, and phishing.