In December 2025 the National Credit Regulator (NCR) admitted that it suffered a cyberattack that disrupted some of its systems.
The regulator confirmed the incident in December but at the time they did not provide too much info about exactly what information was accessed or who was responsible for the hack.
Debtfree Magazine previously reported on what appears to be a separate NCR website issue back in September 2025, where users were redirected to other websites on Google and where the NCR website was messed up.
At this stage, it is still unclear whether that earlier incident in September and the December attack are linked in any way, but perhaps not as the nature of the two incidents appears to be different.
A Ransomware Attack This Time
Whereas the attack in September appeared to be mainly mischievous and cosmetic, this more recent attack seems to be a ransomware attack.
New information about the December attack first emerged on 25 December 2025, when cyber security researchers monitoring ransomware activity shared details online (we think they were the first to share the identity of the hackers publicly).
The information was first published on hendryadrian.com, a website that tracks hacking groups and ransomware incidents globally. These reports suggest that a group known as DragonForce is behind the December attack.
DragonForce are a collective of hackers who sell or rent hacking software to affiliates who then pay them a percentage of whatever money they make using the software and hacking systems. They run a site on the dark web offering these tools, systems and stolen data.
The NCR has not yet publicly confirmed the identity of the attackers or hacking group but the claim seems to be accurate since DragonForce are the ones selling the data on the dark web.
42Gig of Data for sale on the dark web
Data For Sale
According to the claims made by DragonForce, more than 42 gigabytes of data were taken from the NCR and are now being sold online.
You might wonder: Why would hackers target the NCR?
In most cases, ransomware attacks are not about politics they are about money. Hackers break into systems, copy sensitive information, and then use that data as leverage. They demand payment to stop the information from being shared or sold, and sometimes also to restore access to affected systems.
‘The NCR has lots of data about consumers, about Debt Counsellors, credit bureaus, credit providers, alternative dispute resolution agents’
The NCR has lots of data about consumers, about Debt Counsellors, credit bureaus, credit providers, alternative dispute resolution agents and more. They also had a very public facing system, which it seems the hackers were able to get into and cause chaos.
The regulator has said it notified the relevant authorities, including the Information Regulator, and has been working to improve website security and restore affected systems.
There are now a bunch of questions in the wake of the attack and announcements. Such as:
What data exactly was taken?
Is this anyone’s fault?
Was a ransom paid?
Who has bought the data on the dark web?
How will they use it, and whether the September website incident and the December data theft are perhaps connected?
Some of these details are likely to become clearer once further information is released in the future. The NCR have been very open about the incident and will no doubt report on it to Parliament and others down the line.
It is currently not known whether the NCR paid any ransom following the December attack.
We use cookies (the computer type not the tasty ones) to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Yummy, Cookies... OKNo