RANSOMWARE VICTIMENERGY

Golden Star Resources

cmd organization📍 GH (GH)📅 July 11, 2026
8
same group

Attack Intelligence

Golden Star Resources was compromised in a ransomware attack attributed to cmd organization in July 2026. The organization, operating in the Energy sector in GH, was added to the group's data leak site as part of an extortion campaign.

cmd organization operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Wassa is located in south-western Ghana. Golden Star commenced production from the surface operation at Wassa in 2005 and commercial production was achieved at Wassa Underground on January 1, 2017. In early 2018 Wassa transitioned into an underground-focused operation. Thanks to the scale of the historical open pit mining operation the processing plant has significant excess capacity and is currently only running at 70-80% (based on 2020 actuals) utilization. Development of the large inferred mineral resource which comprises the southern Extension zone, was the subject of a Preliminary Economic Assessment which was included in the March 2021 Technical Report. Given the scale of the resource at Wassa, the Company is exploring the potential to increase the mining rate in order to fill the mill.

Additional Details

Other Victims — cmd organization (8)

Quick Facts

CountryGH (GH)
SectorEnergy
Attack DateJul 11, 2026
Intel Sourceransomlook

Threat Group

cmd organization
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.