CSIDB logo
Incident

Directorate of File Automation

Incident posture

Attack window
Jan 2026
Location
Senegal
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-01 09:56

Linked entities

Victim
Directorate of File Automation
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2026
Discovered
Jan 2026
Disclosed
Feb 2026
Resolved
Pending

Summary

A newly emerged ransomware group known as The Green Blood Group compromised two servers belonging to Senegal's Directorate of File Automation, the government agency responsible for national identification and biometric records. The attackers exfiltrated sensitive data including birth records, national ID cards, and immigration files belonging to nearly the entire population, later announcing the breach on a dark web leak site. The intrusion disrupted operations at the agency for at least five days, during which the attackers gained access to a domain controller enabling potential lateral movement and a database server storing citizens' personal information. In response, the agency temporarily suspended new national ID card production, though it did not address the confidentiality of the stolen data, raising concerns about long-term risks of fraud and erosion of public trust in government-held digital identity systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On January 19, 2026, a newly formed ransomware group identifying itself as "The Green Blood Group" breached two servers belonging to Senegal's Directorate of File Automation (DAF), the government agency responsible for handling passports, national ID cards, and biometric data for the country's nearly 20 million residents. The attackers announced the intrusion on the Dark Web, claiming to have exfiltrated biometric data, immigration records, and other personal information belonging to nearly the entire population of the West African nation. The compromised servers consisted of the organization's domain controller, from which lateral movement across the network would have been possible, and a "Perso" server, which likely referred to the database where citizens' personal information was stored. After the breach was discovered, IRIS employee Quik Saw Choo notified employees at Senegal's Ministry of Interior and Public Security, the parent agency of the DAF, that the attack had occurred. The disruption to DAF operations lasted at least five days, though it is unclear whether that downtime was caused by the attackers or by mitigation measures taken by IRIS and government staff.

Following the initial intrusion, The Green Blood Group maintained access to the DAF systems long enough to obtain and later leak internal emails documenting the breach response. On February 4, 2026, analysts identified the group's leak site on the Dark Web, where it claimed to have stolen 139TB of data from the DAF, though the ransom note sent to the agency referenced 139GB, suggesting a possible typo in the leak site claim. French-Senegalese cybersecurity researcher Clement Domingo examined the leaked data and confirmed that it contained real birth records, national ID cards, and other highly sensitive material belonging to Senegalese citizens. The day after the leak site appeared, on February 5, the DAF issued a public acknowledgment of the breach, more than two weeks after the initial intrusion occurred on January 19. The agency's open letter announced a temporary suspension of new national ID card production and assured citizens that the "integrity" of their personal data remained intact, though Domingo publicly disputed this claim, and the agency notably did not address the confidentiality of the stolen data. Adding to the embarrassment of the delayed response, the official contact email address listed at the bottom of the DAF's open letter was a generic Yahoo address.

Beyond the immediate operational disruption to Senegal's national ID system, the breach carries significant long-term consequences for the country's nearly 20 million residents. The exfiltration of biometric data, including fingerprints and facial recognition information tied to national ID cards, exposes the population to permanent risks of identity theft and fraud that cannot be mitigated by simply changing a password or canceling a credit card. The compromised information included immigration records alongside birth records and national ID card data, providing attackers with a comprehensive profile of affected individuals. The scale of the breach, affecting nearly the entire population of Senegal, represents one of the largest biometric data exposures in recent history.

The Green Blood Group, despite being a newly identified ransomware outfit, demonstrated a high level of technical capability in this and other operations. Researchers at Foresiet described the group as "technically competent" with a "mature ransomware design," noting that the gang employed its own Golang-based locker and operated under a double-extortion business model in which victims are threatened with both file destruction and public leak. By the time the Senegal breach became public, the Green Blood Group had already compromised organizations in Colombia and India, indicating that the attack on the DAF was part of a broader campaign rather than an isolated incident targeting Senegal. The DAF acknowledged that the attackers maintained persistent access for an extended period before the data was eventually leaked online.

Shortly after the DAF breach became public, a second cyberattack was reported against Sénégal Numérique SA, a government-adjacent organization that plays a key role in managing Senegal's digital infrastructure and modernization efforts. Local reports speculated that the close timing of the two incidents might indicate a wider-scale offensive against Senegalese government infrastructure, though representatives of Sénégal Numérique SA had not confirmed the details of their attack at the time of reporting. The Green Blood Group's successful exfiltration of internal DAF emails regarding the initial breach response suggests that containment efforts by IRIS and government staff were insufficient to fully evict the attackers from the network. The breach of the domain controller specifically raised concerns about the attackers' potential to conduct lateral movement throughout the organization's network infrastructure.

Sources

Sources available to members: 1 source.

CSIDB