parliament.iq Listed by babuk2 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On 14 March 2025, parliament.iq appeared on a list published by the babuk2 ransomware group, which claims to have stolen internal files from the site. Anyone who has interacted with parliament.iq should review any communications or services they use with the organisation and change passwords or enable additional safeguards if advised.
For people whose personal details, correspondence or professional records may sit inside the systems of Iraq’s parliament, a ransomware group’s public listing of parliament.iq creates immediate practical concern. Even when the precise contents of any stolen material remain unconfirmed, the mere claim that internal files were taken can leave individuals wondering whether their information is now circulating beyond official control and what steps they should take next.
On 14 March 2025 the domain parliament.iq appeared on a leak site operated by the group known as babuk2. Public reporting summarises the incident as “parliament.iq By Babuk Locker 2.0” and states that internal files were exfiltrated in a ransomware attack. The number of people affected is unknown, and further technical detail has not been released.
Inside the incident
According to the available record, parliament.iq was listed by the babuk2 ransomware group on 14 March 2025. The group’s own presentation of the event describes the victim under the label “Babuk Locker 2.0” and asserts that internal files were removed from the organisation’s systems as part of a ransomware operation. No figure for the volume of data, no list of specific file types beyond the general description “internal files,” and no timeline of the intrusion itself have been published in the source material. Whether encryption was also deployed, whether a ransom demand was issued, or whether any negotiation took place are all undisclosed. The listing therefore stands as an unverified claim by the threat actor rather than a confirmed forensic finding. Public detail on the method of initial access, the duration of the attackers’ presence, or any subsequent containment steps remains limited.
Who is babuk2?
Babuk2 is the name associated with a continuation or rebrand of the Babuk ransomware operation, sometimes styled Babuk Locker 2.0. The original Babuk group emerged in 2021 and quickly became known for a double-extortion model: encrypting victim systems while simultaneously copying data and threatening to publish it on a dedicated leak site if payment was not made. Affiliates typically gained access through compromised credentials, phishing or exploitation of remote-access services, then moved laterally to locate high-value file shares before deploying the encryptor. After the original operators publicly claimed to have shut down and released source code, variants and successor brands continued to appear, preserving the same core tactics of data theft followed by public shaming. Babuk-linked actors have historically targeted organisations across government, manufacturing and professional services, using the threat of data release to increase pressure. In the present case the group claims to have listed parliament.iq; that claim has not been independently verified in the supplied facts, and no additional statements attributed specifically to this victim have been recorded beyond the leak-site entry itself.
About parliament.iq
Parliament.iq is the public-facing web presence of the Council of Representatives of Iraq, the country’s national legislature. Like the digital platforms of other parliamentary bodies, it serves as a portal for legislative information, member directories, committee records and official communications. Systems supporting such an organisation routinely process correspondence between elected representatives and constituents, internal administrative files, personnel records of parliamentary staff, and documents related to legislative drafting and oversight. A breach affecting these systems is consequential because the data often includes both sensitive personal information of citizens who have contacted their representatives and material that bears on the functioning of democratic institutions. Even limited exposure of internal files can undermine public confidence and create secondary risks for individuals whose details appear in those files.
What data was at risk
The only data category named in the available facts is “internal files exfiltrated in ransomware attack.” No further breakdown—such as whether the files contained personal identifiers, email archives, financial records, or classified legislative drafts—has been disclosed. Organisations of this type typically hold constituent correspondence, staff personnel files, internal memoranda, and operational documents. Because the exact contents remain unconfirmed, it is not possible to state with certainty which categories of information, if any, left the organisation’s control. The claim of exfiltration originates with the ransomware group’s listing and should be treated as such until independent verification appears.
What's at stake
For individuals whose data may have been among the internal files, the practical risks include unwanted contact, social-engineering attempts that leverage knowledge of their interactions with parliament, or longer-term identity-related fraud if personal identifiers were present. For parliamentary staff and elected members, exposure of internal correspondence or administrative records can create personal security concerns and complicate official duties. For the institution itself, the incident raises questions of operational continuity, the integrity of legislative processes, and the need to reassure the public that sensitive civic information remains protected. None of these outcomes is guaranteed; they depend on what was actually taken and how it is subsequently used. The absence of confirmed numbers of affected people or confirmed file inventories simply means the scale of residual risk cannot yet be measured with precision.
If your data was in this claimed breach
If you have had dealings with the Iraqi parliament—whether as a constituent, staff member, contractor or correspondent—treat the possibility of exposure seriously but calmly. Begin by reviewing any accounts that use the same email address or contact details you have shared with parliamentary offices; enable multi-factor authentication where available and change passwords that may have been reused. Monitor financial and government-related accounts for unexpected activity. Be sceptical of unsolicited messages that reference parliamentary business or claim knowledge of your personal details. Finally, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; such a scan provides an additional data point without requiring you to supply further personal information. Official guidance from Iraqi authorities, if issued, should take precedence over general advice.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) Listed by babuk2 Ransomware GroupIraqi Council of Ministers Listed by babuk2 Ransomware GroupIraqi Ministry of Finance Listed by babuk2 Ransomware Grouptecnologias.mspz2.gob.ec Listed by babuk2 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the parliament.iq Listed by babuk2 Ransomware Group →
Publicly posted by babuk2 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.