[DEVMAN] – Ransomware Victim: NSSF KENYA
![[DEVMAN] - Ransomware Victim: NSSF KENYA 1 image](https://www.redpacketsecurity.com/wp-content/uploads/2024/09/image.png)
Ransomware Group: DEVMAN
VICTIM NAME: NSSF KENYA
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating to the content of the files should be directed at the attackers directly, not RedPacket Security. This blog is simply posting an editorial news post informing that a company has fallen victim to a ransomware attack. RedPacket Security is in no way affiliated or aligned with any ransomware threat actors or groups and will not host infringing content. The information on this page is fully automated and redacted whilst being scraped directly from the DEVMAN Onion Dark Web Tor Blog page.
AI Generated Summary of the Ransomware Leak Page
The ransomware leak page pertains to an incident involving a public sector organization in Kenya. The attack was discovered on May 19, 2025, and involved the encryption of all devices, with an estimated theft of approximately 4.5 million USD worth of data. The attackers, identified as part of the group “devman,” claim to have stolen 2.5 terabytes of sensitive data, including information stored on a specific web page. The threat appears to give the victim a 24-hour window to contact the attackers before the stolen information is publicly disclosed. The compromised data likely includes confidential files pertinent to the organization’s operations, emphasizing the seriousness of the breach.
The leak page does not provide particular details about the nature of the stolen data or the specific vulnerabilities exploited. It mentions a URL indicating a file named “nssf.html,” which suggests that internal or organizational information may have been compromised. The incident highlights the ongoing threat to public institutions in the region, especially those handling sensitive or critical data. No images or screenshots are available on the page, but the communication suggests an imminent risk of exposure if demands are not met within the specified timeframe. Overall, this incident underscores the importance of cybersecurity measures to safeguard sensitive government data from cybercriminal groups.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.