Desk live·
ForensicPost
Ransomware/Public sector/File 22-1104

Vanuatu Government Systems Stayed Offline for Weeks as Officials Used Personal Email

Vanuatu’s government network was compromised in early November 2022. Ministries lost email, file shares and phone systems; the main hospital worked on paper; and a month later officials were still running the state from personal email accounts.

Constructed geometry · not a chart of case data
JurisdictionVanuatuPort Vilathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetGovernment of Vanuatu
ActorUnattributed
D. Kennedy12 min readConfidence: medium3 sources reviewed

Vanuatu’s government servers were reported taken out on 4 November 2022, with the government broadband network confirmed compromised from 6 November. Reporting traces the start to suspicious phishing activity in email directed at the Ministry of Finance.

Email, network shares, VoIP and other online services went down across ministries and departments. Emergency services, email and phone lines were affected for weeks. Staff at Port Vila Central, the main hospital, used pen and paper into late November. By early December around 70% of the network was reported restored, and more than a month after the attack many officials were still conducting business from personal email accounts.

Not An Emergency Declaration — Just Offline

We filed Costa Rica at 22-0508, where a state met a ransomware campaign by declaring a national emergency and invoking the powers that come with it.

Vanuatu is the same category of event with none of that apparatus. A small state lost its administrative capacity for weeks and the response was recovery work, quietly, over a month. Both are what national-scale availability harm looks like; only one produced an instrument anyone can point at afterwards.

The Workaround Is The Next Incident

Officials moved to personal email to keep the state running. That was the correct decision — the alternative was for government to stop — and it means a month of government correspondence sat in consumer mailboxes with no retention policy, no records management and no institutional control.

We have recorded degraded-mode operation as the realistic posture at 26-0728 and 22-1002, where a hospital system ran on paper. This file records its cost: the fallback creates exposure that outlives the outage, and nobody counts that either.

Scale Is Not Proportion

By record count this incident is invisible. No figure for affected individuals was published, no notification letters were sent, and no regulator produced a finding.

What was lost was a national government’s ability to function, for a population of a few hundred thousand people who have one. We have argued at 24-1231 that availability harm goes uncounted; the corollary this file adds is that small jurisdictions are undercounted twice, because the absolute numbers never look large enough to report.

How we reported this

Compiled from contemporaneous reporting, principally regional outlets, listed below. Ransomware was suspected and widely described as such; no operation was authoritatively identified and none is named here, which is the main reason this file is graded medium. No ransom demand, payment or data-theft claim is asserted — none was established. Corrections: corrections@forensicpost.com.

Sources
  1. Vanuatu Government Struggling Back Online After CyberattackThe Diplomat
  2. Vanuatu Struggles Back Online After CyberattackSecurityWeek
  3. Vanuatu Govt network paralysed by cyber attackIslands Business
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary