Back to timeline
Moderate severity Cyber Cyber advisory

Credential-harvesting campaign targets INGO sector

Reported
19:00
1 d ago
Location
Regional
Uganda
Source
INGO ADVISORY cyber TI
Reference
INC-2626
Friday, July 31, 2026

Analyst narrative

Spear-phishing lures impersonating donor agencies observed against three INGOs. Advisory pushed with IOCs and mitigation steps.

The incident falls within INGO ADVISORY's cyber monitoring stream and has been logged against Uganda. Analysts assess this event at a moderate severity level based on reported impact, actor intent and proximity to client operations in the sector.

Reporting has been correlated across open-source channels and INGO ADVISORY's in-country liaison networks. Where applicable, information has been cross-checked against INGO ADVISORY cyber TI. Analysts continue to monitor secondary indicators including movement of security forces, communications traffic and follow-on incidents in the immediate area.

A cyber advisory has been issued to relevant subscribers. Portfolio clients with personnel, assets or supply-chain exposure in Uganda should review current standing instructions, verify accountability of team members, and confirm that hold, move and evacuate triggers remain valid against the evolving threat picture.

Operational considerations

  • Validate patch status on internet-facing infrastructure; audit VPN and remote-access appliances.
  • Escalate monitoring on identity, email and finance systems; review privileged-access controls.
  • Rehearse ransomware and business-continuity playbooks with senior stakeholders.
Client subscribers

Detailed threat assessments, actor profiles and country-specific mitigations are published to Professional and Enterprise subscribers via the Intelligence Centre.