National cyber team confirms the breach, but not whether data was stolen or encrypted.
Namibia's computer security incident response team has confirmed unauthorized activity in the defense ministry's network and linked it to the RansomHouse cybercrime group.
In a direct attribution, NAM-CSIRT named the group after RansomHouse listed the supposed victim on its leak site on September 16.
RansomHouse identified the victim as the "Namibian Defence Force," although the domain in its listing belongs to the Ministry of Defence and Veterans Affairs (MODVA), the government department overseeing the military.
Either way, openly extorting a country's defense establishment is a move even by ransomware standards.
RansomHouse's website stated: "Dear management of Namibian Defence Force."
The listing treated the target as a company with $434 million in annual revenue, but NAM-CSIRT later confirmed unauthorized activity within MODVA's network.
NAM-CSIRT said in a statement: "Analysis of the affected systems established that the incident is associated with the RansomHouse ransomware group, a cybercriminal syndicate known internationally for deploying ransomware and engaging in so-called double extortion tactics where threat actors encrypt systems while simultaneously threatening to disclose alleged stolen information."
Emilia Nghikembua, chief executive of the Communications Regulatory Authority of Namibia and head of NAM-CSIRT, said the team would support MODVA throughout its investigation and recovery.