๐Ÿ‡ฌ๐Ÿ‡ญ

GH

GH

Ransomware victim intelligence profile ยท Ranked #83 globally ยท Updated: Sep 17, 2026

10
Total Victims
0% of global total
#83
Global Rank
8
Active Groups
6
Sectors Targeted

ThreatAI Analysis

Compiled from this database and the ransomware.live profiles of the groups active in GH. Figures are computed from the tracked records, not inferred.

GH in the global picture

GH accounts for 10 of the ransomware disclosures tracked here, ranking #83 worldwide and making up 0% of the global total. The sectors listed most often are Energy, Business Services, Retail & E-Commerce.

Who is most active in GH

Thegentlemen โ€” 3 victims in GH. Medusalocker โ€” 1 victims in GH. Medusa is a DDoS bot written in .NET 2.0. Cmdorganization โ€” 1 victims in GH. CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all aspects of the software used by a company.

Where to report an incident in GH

National computer emergency response teams for GH, as registered with ENISA and the teams themselves. Regional, sectoral and vendor response teams are excluded; verify current contact details before relying on them in an incident.

Ransomware Threat Profile: GH

GH ranks #83 globally for ransomware attacks, with 10 confirmed victims in this database โ€” representing 0% of the worldwide total. The most active ransomware groups targeting GH include Thegentlemen, Medusalocker, Cmdorganization.

The most frequently targeted industries in GH are Energy, Business Services, Retail & E-Commerce. The healthcare sector is particularly vulnerable because attacks on hospitals and medical providers can create life-threatening situations, increasing pressure to pay ransoms quickly.

GH's attack volume reflects broader trends in ransomware targeting: the volume of attacks reflects the country's integration into the global economy and the proliferation of ransomware operations that target organisations of all sizes worldwide.

Organisations in GH should consider the active threat groups documented here when assessing their cybersecurity posture, implementing detection rules, and prioritising incident response planning.

Recent Victims in GH (showing 10 of 10)

# Organization Group Sector Date
1 Hungry Lion Medusalocker Retail & E-Commerce Aug 27, 2026
2 Golden Star Resources Cmdorganization Energy Jul 11, 2026
3 xl africa group 0day syndicate Business Services May 28, 2026
4 Kasapreko Thegentlemen Agriculture and Food Production May 6, 2026
5 providentgh.com Apt73 Business Services Apr 27, 2026
6 International Maritime Hospita Thegentlemen Healthcare Apr 14, 2026
7 Ghana Bauxite Energy, Utilities & Waste Thegentlemen Energy Feb 11, 2026
8 Kasapreko Qilin โ€” Dec 6, 2025
9 Volta River Authority Blacksuit Energy Oct 11, 2024
10 ghanare.com Braincipher Consumer Services Aug 28, 2024

Frequently Asked Questions

How many ransomware attacks have occurred in GH?

GH has recorded 10 ransomware victim disclosures in this database, ranking #83 globally. This represents 0% of all tracked ransomware attacks worldwide.

Which ransomware groups target GH?

The ransomware groups most active in GH are Thegentlemen, Medusalocker, Cmdorganization, 0day syndicate. These groups collectively account for the majority of victim disclosures attributed to GH.

Which industries are most targeted by ransomware in GH?

In GH, the most frequently targeted sectors are Energy, Business Services, Retail & E-Commerce. These industries hold valuable data and often have critical operational requirements that make them attractive ransomware targets.

How does GH rank globally for ransomware attacks?

GH ranks #83 globally for ransomware attacks with 10 victim disclosures, representing 0% of the worldwide total of 21,694 tracked victims.

How can organisations in GH protect against ransomware?

Organisations in GH should implement a layered security approach including regular offline backups, network segmentation, multi-factor authentication, endpoint detection and response (EDR) tools, and employee security awareness training. Monitoring threat intelligence feeds for active groups targeting GH is also recommended.