Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Ransomware » Ransomware Group KryBit Claims Breach of Sudan’s Nile Petroleum

Ransomware Group KryBit Claims Breach of Sudan’s Nile Petroleum

Last updated:July 24, 2026
Human Written
  • KryBit, a ransomware gang, claims they hacked Sudan’s Nile Petroleum Company, NILEPET.

  • The group hasn’t provided any proof or said what kind of data they stole. So far, no one knows if they’re telling the truth.

  • This incident highlights a growing focus of ransomware groups on the energy sector, where a small disruption could seriously hurt the economy.

Ransomware Group KryBit Claims Breach of Sudan's Nile Petroleum

The ransomware gang KryBit has reportedly claimed responsibility for hacking Sudan’s state-owned petroleum company Nile Petroleum Corporation.

Currently, no evidence from the hackers to support the claim, and NILEPET hasn’t released any statement confirming any security incident. So for now, the claim remains unverified.

Details of the Latest KryBit Claim

KryBit listed Nile Petroleum on their leak site on July 23, 2026. The listing did not include any information regarding what data the hackers claimed they stole. The posting did not also indicate whether the threat actors made any system encryption or ransom demands. No sample files, screenshots, or other forms of evidence to back the hackers’ claim.

Posting claims on leak sites is common among ransomware groups. The goal is often simple: pressure the victim to pay a ransom to avoid releasing their sensitive data publicly. Nonetheless, since there’s no evidence, we can’t conclude that the incident KryBit claims actually happened.

Cybersecurity experts often urge people not to run with such announcements until there’s evidence to prove it. Ransomware gangs sometimes exaggerate claims or brag about attacks they never carried out to boost their credibility as well as attract new affiliates to work with them.

Who is KryBit and What Do They Want?

KryBit is one of the recently developed ransomware operations that started operating in March 2026. KryBit operates as a Ransomware-as-a-Service (RaaS) organization. This entails that the members of this group develop the ransomware malware but rent it to affiliates that perform the cyber attack. The group’s operational model was also seen in its attack on Eurohold Bulgaria.

It operates under the double extortion model, according to cybersecurity experts. Here, the affiliates steal important data from the targeted victims prior to encrypting their computers. Then, they threaten the victims with publishing the data if they fail to pay the ransom.

Threat intelligence indicates that KryBit has attacked targets in different industries and nations. According to the organizational model of this group, the affiliates get 80% while the main operators get 20%.

Questions About KryBit’s Credibility

Researchers have brought into question the validity of some of KryBit’s claims. In an in-depth study by Halcyon, they found the use of fake listings of victims during a dispute between the group and another ransomware gang known as 0APT.

While fighting back against 0APT in their dispute, KryBit was able to hack their systems, steal data from them, and deface their leak site. This revealed that the 190 victims listed by 0APT were purely fictitious.

But this doesn’t mean KryBit’s claim against Nile Petroleum is not valid. In such cases, it is important to conduct independent verification when new victims emerge on the leak sites. So far, Nile Petroleum has not issued any statement regarding the alleged compromise of its systems.

Why Energy Companies are Prime Targets for Hackers

Energy, oil, and gas companies keep attracting ransomware hackers for a number of reasons. The first is that energy companies deal with critical infrastructure and manage valuable business information.

Although the attackers don’t often interrupt the operations, they may use the documents related to engineering, finance, personnel information, and other contracts in the negotiation of ransom.

The risk of reputational damage from such public data leaks is huge for organizations in politically and economically sensitive countries. There has been an increasing tendency towards targeting energy companies by ransomware groups all over the world in the past few years. It reflects a broader trend of hackers going after companies that render essential services.

If the attack on a major national energy company such as NILEPET turns out to be true, then a lot would be at stake. It could affect financial markets, supply chain, and even national security depending on the scope of the attack.

About Nile Petroleum

Nile Petroleum Company is a national oil company in Sudan, also popularly referred to as Nilepet. The company plays an important role in managing activities in the country’s oil sector from exploration through production to transport.

Nilepet has been linked to Sudan’s oil sector for many years. The oil sector has remained a crucial part of the nation’s economy in spite of years of political unrest in the country.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.