LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › mof.gov.la Listed by funksec Ransomware Group

HIGH severityUnverified claimHow we verify

mof.gov.la Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 30, 2024
mof.gov.la Listed by funksec Ransomware Group

Reported December 30, 2024.

HIGH
Severity
December 30, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

mof.gov.la was listed by the funksec ransomware group on 30 December 2024 after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may be affected; check the ministry’s site and monitor official channels for guidance on next steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On December 30, 2024, the domain mof.gov.la, belonging to the Ministry of Finance of Laos, was listed by the ransomware group funksec. Public reporting indicates that internal files were exfiltrated in a ransomware attack, though the number of people affected remains unknown and further details on the incident’s scale and method have not been disclosed.

The listing places a national finance ministry among claimed victims of a ransomware operation. Because ministries of this type handle budgeting, taxation and fiscal records, any confirmed compromise of internal material can carry consequences for government operations and for individuals whose information may appear in those files. At present the claim rests on the group’s leak-site listing and has not been independently verified in the available record.

Breaking down the breach

According to the reported information, mof.gov.la was listed by funksec on December 30, 2024. The only data category named is “internal files exfiltrated in a ransomware attack.” No figure for the volume of data, no specific file names or categories beyond that description, and no confirmed date of initial intrusion have been made public. The number of people affected is listed as unknown. Timing of the attack itself, the entry vector, and whether systems remain encrypted or operational are all undisclosed. The sole concrete assertion available is the group’s claim that it obtained and removed internal files from the ministry’s environment.

The group behind it: funksec

Funksec is a ransomware operation that became publicly visible in late 2024. Open-source reporting describes the group as relying heavily on AI-assisted tooling for code generation, negotiation scripts and leak-site content. It has typically demanded relatively low ransoms compared with more established ransomware crews and has listed victims across multiple sectors, including government and critical infrastructure, on its dedicated leak site. The group’s standard pattern is to claim data exfiltration, post a victim name or domain, and threaten publication if payment is not received. In this case the group claims that mof.gov.la is among its victims and that internal files were taken; no further statements attributed specifically to this incident appear in the public record beyond that listing.

Who is mof.gov.la?

mof.gov.la is the official web presence of the Ministry of Finance of the Lao People’s Democratic Republic. The ministry is responsible for managing the country’s public finances: preparing and overseeing the national budget, collecting revenue, administering taxation, setting fiscal policy and supporting economic planning. Like finance ministries elsewhere, it routinely processes and stores records related to government spending, tax filings, contracts, personnel and inter-agency financial transfers. A breach affecting such an organisation is consequential because the data it holds can include both sensitive state financial information and personal or commercial details of citizens, businesses and public servants. Disruption or leakage can therefore affect fiscal administration, public trust and the privacy of individuals who interact with the ministry.

What data was at risk

The only category named in the available facts is “internal files exfiltrated in a ransomware attack.” Exact contents, file counts and whether personal data, tax records, payroll information or classified fiscal documents were among them remain unconfirmed. Organisations of this type typically hold budgeting documents, tax and revenue data, employee records, contractor information and internal correspondence. Until more precise inventories are released by the ministry or by independent investigators, it is not possible to state which of those categories, if any, were actually taken. The public record simply records the group’s claim of internal-file exfiltration.

What's at stake

For individuals whose data may have been present in the exfiltrated files, the practical risks include identity misuse, targeted phishing that references real financial or personal details, and longer-term exposure of tax or employment information. For the ministry itself, the stakes include potential disruption of fiscal operations, the need to validate the integrity of remaining systems, and the reputational and diplomatic costs of a claimed compromise of national financial records. Because the number of people affected is unknown and the precise data types are undisclosed, the full scope of harm cannot yet be measured. The incident nonetheless underscores the value of the information such ministries hold and the interest ransomware groups show in government targets.

What to do if you're exposed

If you have had dealings with the Lao Ministry of Finance—through tax filings, employment, contracts or other official channels—treat the possibility of exposure seriously even while details remain limited. Practical first steps include:

Official confirmation from the ministry, if and when it is issued, should take precedence over third-party claims. Until then, cautious monitoring and basic hygiene remain the most useful responses available to potentially affected individuals.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companymof.gov.la security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See mof.gov.la’s full breach history →

More recent breaches

gstpam.org Listed by babuk2 Ransomware GroupJanuary 27, 2025pbos.gov.pk Listed by babuk2 Ransomware GroupJanuary 27, 2025rtdc.gov.mn Listed by babuk2 Ransomware GroupJanuary 27, 2025skopje.gov.mk Listed by babuk2 Ransomware GroupJanuary 27, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the mof.gov.la Listed by funksec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by funksec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram