Namibia | Epia Financial Services | Windhoek Listed by radar Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Epia Financial Services in Windhoek has been listed by the radar ransomware group, with internal files reported to have been exfiltrated. The incident was disclosed on 11 September 2025; the number of people affected has not been published. Individuals should check whether their information was exposed and follow any guidance provided by the company.
People who deal with Epia Financial Services in Windhoek may now face uncertainty about whether their personal or financial details sit among material claimed to have been taken in a ransomware incident. Public reporting lists the firm as a victim of the group known as radar, with internal files said to have been exfiltrated; the number of individuals affected remains unknown and the precise contents of those files have not been confirmed.
What is known so far is limited to the listing itself and basic organisational details that appear alongside it. For anyone whose records may have been held by the firm, the practical concern is straightforward: unauthorised access to internal files can create lasting risks of fraud, identity misuse or unwanted contact, even when full confirmation of exposure is still missing.
Inside the incident
On 11 September 2025, Epia Financial Services of Windhoek, Namibia, was reported as listed by the radar ransomware group. The available summary states that internal files were exfiltrated in a ransomware attack. No figure has been given for the number of people affected, and public detail does not describe the method of initial access, the duration of any intrusion, or whether systems were encrypted as well as data taken.
The listing includes contact and location information associated with the organisation: a telephone number (+264816013040), an email address (info@epiafs.com), and a physical address at No 17 Eulenweg Street, Hochland Park, Windhoek. It also notes related partners including NAMRA, NAMFISA, NBWPF and CIFNAMIBIA. Beyond these points and the claim of internal-file exfiltration, the scale, timeline and technical specifics of the incident remain undisclosed.
Inside radar
Radar is a ransomware group that operates by gaining access to organisational networks, exfiltrating data, and then listing victims on a dedicated leak site, typically to pressure payment. Like other groups of this type, it publicly claims responsibility for breaches and often threatens to release or sell stolen material if its demands are not met. Its listings are statements by the group itself and should be treated as claims until independently verified.
In this case the group claims to have listed Epia Financial Services and to have exfiltrated internal files. No further statements attributed specifically to radar about this victim—such as sample files, ransom amounts or deadlines—appear in the reported facts. Prior public activity by radar has followed the same pattern of data theft combined with leak-site pressure, but those earlier operations do not supply additional confirmed detail about the Epia incident.
About Epia Financial Services
Epia Financial Services is a financial-services organisation based in Windhoek, Namibia. Firms of this kind typically handle client accounts, payment processing, regulatory reporting and related administrative records. The reported address and contact details place it in Hochland Park; the listing also associates it with Namibian regulatory and industry bodies such as NAMRA and NAMFISA, indicating it operates within the country’s formal financial sector.
A breach involving a financial-services provider is consequential because such organisations routinely hold sensitive personal and commercial information. Even when only “internal files” are named, the potential for those files to contain client identifiers, transaction data or correspondence makes the incident relevant to customers, partners and staff who have dealt with the firm.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as names, identity numbers, account details or correspondence—has been disclosed. The number of people whose information may be involved is unknown.
Organisations in the financial-services sector commonly retain client contact details, identification documents, account and transaction records, contracts and internal operational documents. Because the exact contents of the files claimed by radar have not been confirmed, it is not possible to state which of these categories, if any, were present. Public detail remains limited to the general description of internal-file exfiltration.
The real-world impact
For individuals, the principal risks are those that follow any unauthorised exposure of financial-sector records: possible misuse of personal identifiers for fraud, targeted phishing that references genuine relationships with the firm, or longer-term identity-related problems. Because the volume and precise nature of the data are unconfirmed, the severity for any single person cannot yet be measured; the prudent assumption is that anyone who has been a client, employee or partner should treat the possibility of exposure seriously.
For the organisation itself, the listing creates operational, regulatory and reputational pressure. Namibian financial entities are subject to oversight by bodies such as NAMFISA; a claimed data theft may trigger notification duties, internal investigation costs and the need to reassure clients and counterparties. The absence of confirmed numbers does not remove these consequences; it simply leaves their full scope still to be established.
Were you affected?
If you have had dealings with Epia Financial Services, treat the reported listing as a reason to take basic protective steps while further information is awaited. Exact confirmation of individual exposure is not yet available from public sources.
- Monitor bank and credit accounts for unexpected activity and enable any available transaction alerts.
- Be cautious of emails, calls or messages that reference Epia or related Namibian financial partners; verify independently before sharing information or clicking links.
- Consider placing fraud alerts or credit freezes with relevant credit bureaux if you hold accounts that could be linked to the firm.
- Change passwords on any accounts that reused credentials associated with Epia communications, and enable multi-factor authentication where possible.
- Run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets.
Public detail on this incident remains limited. Further official statements from the organisation or regulators, if they appear, will provide clearer guidance on next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Fouad Alghanim & Sons Group of Companies Holding W.L.L. Listed by radar Ransomware GroupMy Florida Case Management Services, LLC Listed by radar Ransomware GroupMC INVERSIONES INMOBILIARIAS Construction company in Peru Listed by radar Ransomware GroupSold Real Estate, Sold RE PTY LTD Listed by radar Ransomware GroupLatest breaches
Publicly posted by radar — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.