Ransom! Dosab (JUN-2026)
Dosab (Demirtaş Organize Sanayi Bölgesi, DOSAB) in South Africa reported a ransomware incident involving the threat actor “nova,” who allegedly exfiltrated data and provided “tree and samples” of stolen information after the organization contacted their support department. The attack impacted DOSAB’s operations and services across its industrial community in South Africa. #SouthAfrica

Incident Details

  • Victim: Dosab
  • Sector: Manufacturing
  • Country: SA
  • Actor: nova
  • Source: http://novadmrkp4vbk2padk5t6pbxolndceuc7hrcq4mjaoyed6nxsqiuzyyd.onion/dosab
  • Discovered: 2026-06-20T14:34:33.556803+00:00
  • Published: 2026-06-20T14:34:22.085069+00:00

Information

  • Demirtaş Organize Sanayi Bölgesi (DOSAB) provides wastewater treatment, energy supply, and social facilities to support industrial clients.
  • The industrial zone hosts more than 573 active companies and employs around 44,000 people, with a focus on sectors such as automotive and textile.
  • DOSAB promotes sustainability by offering online services and resources for its members.
  • The organization also supports social responsibility through community engagement and educational initiatives.
  • Nova stated it would provide a tree and samples from stolen data to the company upon contact with the support department.

Disclaimer: This post is based on public claims made by the ransomware group "nova". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live