LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › asecna.org Listed by lockbit3 Ransomware Group

HIGH severityUnverified claimHow we verify

asecna.org Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 15, 2022
asecna.org Listed by lockbit3 Ransomware Group

Reported September 15, 2022.

HIGH
Severity
September 15, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The asecna.org Listed by lockbit3 Ransomware Group (reported September 15, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target organisations that sit at the centre of regional infrastructure, using leak-site listings to pressure victims and advertise their reach. In mid-September 2022 one such listing named asecna.org, the online presence of a body responsible for air-navigation safety across much of Africa and the Indian Ocean. Public detail remains limited, yet the claim alone raises clear questions about the exposure of internal material and the possible consequences for people and operations that rely on the organisation.

According to available reporting, asecna.org appeared on the LockBit3 ransomware leak site on or around 15 September 2022. The group asserted that it had exfiltrated internal files during a ransomware attack. No independent confirmation of the intrusion, the volume of data, or the precise contents has been placed in the public domain, and the number of individuals potentially affected is unknown.

Inside the incident

What is known is narrow. On 15 September 2022, reporting recorded that asecna.org had been listed by the LockBit3 group. The listing itself constitutes the group’s claim that it had stolen internal data in the course of a ransomware operation. No further technical particulars—such as the initial access vector, the duration of any dwell time, the encryption of systems, or any ransom demand—have been disclosed in the material available. Equally, no figure has been given for the quantity of files taken or for the number of people whose information might be involved. In the absence of those details, the incident stands as an unverified claim of data theft paired with a public leak-site entry, nothing more and nothing less.

Inside lockbit3

LockBit3 is the name associated with a prolific ransomware operation that has been active for several years in successive iterations. The group typically gains access to networks, moves laterally, exfiltrates data, and then deploys encryption while threatening to publish the stolen material on a dedicated leak site if payment is not made. This dual pressure—operational disruption plus the prospect of public exposure—has become a standard feature of many ransomware campaigns. LockBit affiliates have previously claimed responsibility for attacks against a wide range of sectors, including government, transport, manufacturing and professional services. The group’s leak site serves both as a negotiation tool and as a form of advertising. In the present case the listing of asecna.org is precisely such a claim; it should be read as an assertion by the actors rather than as independently verified fact.

Who is asecna.org?

ASECNA—the Agency for Aerial Navigation Safety in Africa and Madagascar—is an international public organisation charged with the provision of air-traffic management, aeronautical information and related safety services across a large portion of the African continent and adjoining oceanic airspace. Its member states entrust it with responsibilities that directly affect the safe and orderly flow of civil aviation. An organisation of this type necessarily maintains operational systems, technical documentation, personnel records, contractual material and communications with airlines, airports and state authorities. Because those functions sit at the intersection of public safety and international coordination, any confirmed compromise of its internal systems would carry implications beyond a routine corporate breach. Even an unconfirmed listing therefore draws attention: the integrity of air-navigation data and the confidentiality of related administrative material are matters of legitimate public interest.

The information in question

The only description supplied is that internal files were allegedly exfiltrated. No inventory of file types, no classification of sensitivity, and no confirmation of personal data have been released. Organisations engaged in air-navigation safety commonly hold technical manuals, flight-procedure data, staff information, vendor contracts, incident reports and correspondence with civil-aviation authorities. Whether any of those categories were among the material LockBit3 claims to possess remains unconfirmed. Until verified disclosures appear, the precise contents of the alleged theft cannot be stated as fact.

What's at stake

For individuals, the principal risks that accompany any exposure of internal organisational files are identity misuse, targeted phishing and the possible surfacing of personal or professional details that were never intended for public view. Because the number of people affected is unknown and the data types are unspecified, those risks cannot be quantified here; they remain potential rather than demonstrated. For the organisation itself, the stakes include operational continuity, the confidentiality of safety-related information, and the trust placed in it by member states and the aviation community. A ransomware incident, even if only claimed, can also generate secondary costs in investigation, system hardening and stakeholder communication. None of these outcomes is inevitable, yet each is a concrete consideration when internal files are said to have left an organisation’s control.

What to do if you're exposed

Anyone who believes their information may have been caught up in this or any other incident should begin with basic hygiene: monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and treat unsolicited messages that reference the organisation with caution. If you have ever used an email address in correspondence with asecna.org or related bodies, consider changing passwords on critical accounts and reviewing privacy settings. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; such a check provides a practical starting point for deciding what further steps, if any, are warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyasecna.org security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See asecna.org’s full breach history →

More recent breaches

hacla.org Listed by lockbit3 Ransomware GroupDecember 31, 2022dof.ca.gov Listed by lockbit3 Ransomware GroupDecember 12, 2022brunoy.fr Listed by lockbit3 Ransomware GroupDecember 5, 2022westmount.org Listed by lockbit3 Ransomware GroupNovember 20, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the asecna.org Listed by lockbit3 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram