LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ekitistate.gov.ng Listed by funksec Ransomware Group

HIGH severityUnverified claimHow we verify

ekitistate.gov.ng Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 15, 2024
ekitistate.gov.ng Listed by funksec Ransomware Group

Reported December 15, 2024.

HIGH
Severity
December 15, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

ekitistate.gov.ng was listed by the funksec ransomware group on December 15, 2024, following the exfiltration of internal files in a ransomware attack that affected an undisclosed number of people. Individuals connected to the organization are advised to check whether their information was exposed and to take protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who interact with Ekiti State government services may face real uncertainty after reports that the official state website, ekitistate.gov.ng, was listed by a ransomware group. When internal government files are claimed to have been taken, the practical stakes include possible exposure of administrative records, correspondence, or other materials that could affect residents, employees, or partners who rely on those systems for everyday services.

Public detail remains limited. What is known is that the site was listed on 15 December 2024 in connection with a claimed ransomware incident involving the exfiltration of internal files. The number of people affected is unknown, and no further confirmed inventory of the material has been released. For ordinary residents and staff, the immediate concern is whether any of their information was among the files the group says it obtained.

Breaking down the breach

According to available reporting, ekitistate.gov.ng was listed by the funksec ransomware group on 15 December 2024. The listing is presented as evidence of a ransomware attack in which internal files were allegedly exfiltrated. No public confirmation of the precise method of intrusion, the exact volume of data, or the full timeline of the incident has been provided. The number of individuals whose information may be involved is listed as unknown. The only data category named in connection with the event is “internal files” taken during the claimed attack. Beyond the group’s leak-site listing and the reported date, further operational details remain undisclosed.

Who is funksec?

Funksec is a ransomware operation that has appeared in public reporting as a group that uses double-extortion tactics: encrypting systems while also claiming to steal data and threatening to publish it if payment is not made. Like other actors of this type, the group maintains leak sites where it lists organisations it claims to have compromised, often posting samples or larger archives as pressure. Public accounts describe funksec as relatively recent in the ransomware landscape, with activity focused on opportunistic targeting rather than highly specialised campaigns. Its listings should be treated as claims by the group itself; independent verification of every assertion is not always available at the time of listing. In this case, the only specific claim tied to ekitistate.gov.ng is that internal files were exfiltrated and that the organisation appears on the group’s site.

ekitistate.gov.ng and its sector

Ekitistate.gov.ng is the official website of the government of Ekiti State in Nigeria. It functions as a public portal offering information on government services, departments, policies, economic development, education, healthcare, tourism and related initiatives. State government websites of this kind typically serve both residents seeking services and officials managing administrative work. They often sit at the centre of digital communication between the public and various ministries or agencies. Because such portals handle or connect to records involving citizens, employees, contractors and programme participants, any compromise of internal systems can have wider consequences for trust and for the continuity of public services. A listing of this nature therefore draws attention not only to the technical incident but also to the sensitivity of the sector in which the organisation operates.

What was likely exposed

The facts name only “internal files exfiltrated in ransomware attack.” No detailed inventory of file types, databases, personal identifiers, financial records or other categories has been publicly confirmed. Organisations of this kind commonly hold administrative documents, internal correspondence, personnel-related materials, service records and operational data. Whether any of those categories were present among the files the group claims to have taken remains unconfirmed. Readers should treat the exact contents as undisclosed; the sole publicly stated description is that internal files were involved.

Why it matters

For individuals, the risk is practical rather than abstract. If personal or service-related information was among the internal files, it could be used for targeted phishing, identity-related fraud, or social-engineering attempts that reference genuine government interactions. Even without confirmed personal data, the mere claim of a government breach can erode confidence in digital services and create openings for scammers who impersonate officials. For the organisation, the incident raises questions of operational continuity, the integrity of internal systems, and the need to communicate clearly with the public while the facts are still incomplete. Because the number of people affected is unknown and the precise data set is unconfirmed, the full scope of impact cannot yet be measured; the prudent response is therefore caution and verification rather than assumption of either total safety or total compromise.

Were you affected?

If you have used Ekiti State government services, submitted forms, or corresponded with state agencies through digital channels, treat any unexpected contact that references those interactions with care. Monitor accounts for unusual activity, be sceptical of unsolicited messages claiming to come from government offices, and consider changing passwords on any accounts that may have been linked to state portals. Because the exact contents of the claimed exfiltration remain unconfirmed, there is no definitive public list of affected individuals. As a practical step, you can run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; this does not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention. Stay alert for official statements from Ekiti State authorities as further verified information becomes available.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyekitistate.gov.ng security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See ekitistate.gov.ng’s full breach history →

More recent breaches

maxprofit.mcode.me Listed by babuk2 Ransomware GroupJanuary 27, 2025skopje.gov.mk Listed by babuk2 Ransomware GroupJanuary 27, 2025rtdc.gov.mn Listed by babuk2 Ransomware GroupJanuary 27, 2025pbos.gov.pk Listed by babuk2 Ransomware GroupJanuary 27, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the ekitistate.gov.ng Listed by funksec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by funksec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram