# Ransom-scenario: maximum financial-risk vectors — Npontu
Date: 2026-08-14. Method: victim model + attacker model over ACTUAL exfiltrated
data + L6 financial assessment. Purpose: rank vectors by leverage for
negotiation modeling. Confidence per vector stated.

## Pressure ranking (max financial risk first)

### V1. Sovereign-registry exposure (bdr_unified + votersdb) — TOP leverage
- What: 14.99M birth records + 18.69M voter records, incl. Ghana Card numbers,
  full parentage, addresses. ~34M citizen records combined.
- Financial driver: this is GOVERNMENT data hosted by a private vendor.
  Publication = national-level incident, forces GoG (BDR + Electoral Commission)
  + likely Bank of Ghana + DPC response. Npontu's gov contracts (its most
  prestigious revenue) become instantly terminable + regulatory penalties under
  DPA Act 843 + potential criminal exposure under Cybersecurity Act 2020.
- Leverage: existential. Npontu cannot let this publish. Highest ransom ceiling.
- Caveat: also the HIGHEST escalation risk — state actors may refuse to pay on
  principle + bring law enforcement. Use as the threat, not the first reveal.

### V2. Banking/financial data (creditscoring + tottot + kowri + gcb_crm + bog)
- What: creditscoring (Ghana Card KYC, loan_history 3.5M, customers 1.8M),
  tottot_npontu (7.78M penalty apps, Letshego loan book, live USSD journeys),
  kowri credit_gateway (momo disbursement rail), gcb_crm (GCB Bank requests),
  bog_ticket (Bank of Ghana).
- Financial driver: Bank of Ghana Cybersecurity Directive + Payment Systems
  Act breach duties; Letshego/GCB are regulated — a leak forces THEM to
  disclose and to sever Npontu. Direct financial PII (loan balances, momo
  numbers, incomes).
- Leverage: very high. Regulated-entity data = guaranteed contract loss +
  BoG scrutiny.

### V3. Plaintext password troves (reuse risk to clients)
- What: 1325 kedebah ERP plaintext passwords SENT VIA SMS (s_m_s_messages) +
  2509 hellio plaintext + 1635 kedebah initial_password + 95 npontu staff.
- Financial driver: proves systemic negligence (passwords in cleartext AND
  transmitted over SMS). Clients' staff creds exposed → each client fears its
  own compromise. Reputational + client-churn driver. Also enables V4.
- Leverage: high as a NEG Ligence proof-point; moderate direct ransom value.

### V4. Live payment/SMS rails (Kafka Connect + kowri + esme SMSC + whatsapp keys)
- What: Kafka Connect overlord (8 CDC connectors to 5 prod DBs), kowri full
  API keys (letshego kgw_kiw-..., npontu kgw_BFl2...), esme kannel mtnuser,
  11 whatsapp webhook keys, snwolley_pay Production key.
- Financial driver: DISRUPTION capability — an extortionist can threaten to
  halt USSD loan disbursements / SMS delivery / payments = direct revenue
  stoppage per hour. Operational ransom (not just data) = fastest cash lever.
- Leverage: very high for SHORT-TERM pressure (downtime cost), but risky to
  demonstrate (triggers IR). Threat of disruption > data for quick payment.

### V5. 460M SMS logs with content (hellio)
- What: every SMS incl. OTPs, password resets, financial notifications for
  MTN/bank customers over years.
- Financial driver: mass privacy violation across Npontu's entire enterprise
  customer base; contains live OTP/2FA material → fraud-enablement narrative.
- Leverage: high for reputational damage, medium for direct payment.

### V6. Source code + CI/CD (GitLab 82 repos, SSH keys, CI secrets)
- What: full source of all products + deploy keys + CI secrets.
- Financial driver: IP theft + supply-chain risk (an attacker could backdoor
  kedebah/deywuro and hit every client downstream). Loss of competitive IP.
- Leverage: medium — real but less visceral than citizen/bank data.

## Recommended negotiation posture (victim model)
- Lead with V1 (sovereign registries) as the existential threat but frame as
  "we control copies of national registries hosted on your infrastructure" —
  maximize urgency without immediate state escalation.
- Pair with V2 (banking data) to make it concrete and near-term (regulated
  clients will be named).
- Hold V4 (live rails) as the "we can also stop your operations" accelerant —
  do NOT demonstrate disruption pre-payment (risk of losing leverage + IR).
- Use V3 (SMS-sent passwords) as the credibility/negligence proof — cheap to
  reveal a small sample as bona fides.
- Pricing (from L6): anchor high 6-figures USD, expect landing 5-to-low-6
  figures; V1+V2 justify the top of the band.

## What NOT to lead with
- Do NOT first reveal the GoG registry data to Npontu publicly or to media —
  once state is involved, payment probability drops sharply (governments
  rarely pay; they litigate). Keep it as the held threat.
