On September 11, 2025, the radar Ransomware Group added Epia Financial Services, a Windhoek-based firm in Namibia, to its leak site, claiming that internal files had been exfiltrated during a ransomware attack. Anyone whose personal or financial records passed through the company — clients, partners, or employees — may now have sensitive data exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from Reporting
Public reporting indicates the attackers published a sample of stolen data that includes the company’s contact details: phone number +264816013040, email info@epiafs.com, and physical address at No 17 Eulenweg Street, Hochland Park, Windhoek. The listing also references the firm’s relationships with Namibian regulatory and industry bodies such as NAMRA, NAMFISA, NBWPF, and CIFNAMIBIA. No exact victim count has been released, and the precise volume or sensitivity of the internal files remains unclear from the public leak page. The data was posted on the group’s dark-web leak site, accessible via the onion address tracked by ransomware.live.
Why This Matters for You and Your Family
When a financial services provider loses control of internal files, the information inside can include names, addresses, identification numbers, banking details, or correspondence that ties ordinary people to their money matters. Once posted on a ransomware leak site, that data rarely disappears. Copies spread quickly to other criminals who combine it with information from earlier breaches. For you and your family this means a higher chance of targeted fraud, loan applications in your name, or unwanted contact from people who now know far more about your finances than they should.
The Doxxing and Identity-Chain Risk
Financial records often act as the missing link that turns scattered online scraps into a complete profile. A phone number or email from this claimed breach can be matched to gaming usernames, social-media handles, or school records belonging to your children. The result is an identity chain that lets attackers move from one account to the next. Credential leaks like this one frequently cascade into account takeovers on gaming platforms, where children’s profiles become entry points for further harassment or extortion. Public reporting describes these chained attacks as a standard follow-on tactic after financial data appears on leak sites.