Senegal temporarily shut down operations at the Directorate of File Automation (DAF)—the government office responsible for national ID cards, passports, and biometric services—after a cyberattack disrupted systems supporting these functions. Authorities notified the country’s ~19.5 million residents that services were suspended while the incident was contained and systems were restored, and a senior police official publicly asserted that the integrity of citizens’ personal data “remains intact,” though the full impact was still being assessed.
A ransomware actor calling itself Green Blood Group claimed responsibility, alleging theft of 139 GB of data including citizen records, biometric information, and immigration documents, and published samples as proof. Both reports cite a leaked email from Quik Saw Choo (senior GM at Malaysia’s IRIS Corporation Berhad, involved in Senegal’s digital ID card program) stating that two DAF servers were breached on Jan. 19, with card personalization data stolen from one; IRIS reported taking containment steps such as cutting network access to one server, changing passwords on another, and blocking network connections to foreign missions while coordinating with Malaysian cybersecurity experts and planning on-site support in Dakar. The incident occurred amid a reported contractual/payment dispute between Senegal and IRIS related to the digital national ID project.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
Senegalese authorities publicly confirmed a cyber incident affecting the Directorate of File Automation and temporarily shut the office's operations. Officials said services were being restored securely and stated that the integrity of citizens' data had not been affected.
The ransomware group Green Blood Group claimed responsibility for the intrusion into DAF and alleged it stole 139 GB of data, including citizen records, biometric information, and immigration documents. The group published sample data and a leaked IRIS email as purported proof.
By February 5, local reporting indicated DAF had been disrupted for at least five days, affecting services tied to national ID cards, passports, and biometric records. Restoration efforts were underway while questions persisted about a payment dispute between Senegal and IRIS.
Following the reported server breach, IRIS said it disconnected a server, changed a password, and cut network links to foreign missions and offices to contain the incident. The company also sought to send a team to Dakar with Malaysian cybersecurity experts on January 22.
An email attributed to IRIS Corporation Berhad said two servers at Senegal's Directorate of File Automation (DAF) were breached on January 19, resulting in theft of card personalization data. The compromised environment supported Senegal's national ID infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourceteiss.co.uk
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.