Skip to main content

Ransomware victim disclosure

← All victims

China Railway Construction Corporation Saudi Branch / Sama Construction

listed as World Cup 2034 · Claimed by Wallstreet · listed 4 hours ago

Today
Age
since listed · data leaked

Status timeline

  1. ListedOct 3, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Listed on leak site
Oct 3, 2026

About the victim

AI dossier — public-source company profile

A joint venture between China Railway Construction Corporation's Saudi branch and Sama Construction, serving as the main contractor for the Jeddah Central Stadium—a flagship infrastructure project for the FIFA World Cup 2034 in Saudi Arabia.

Industry
Construction & Infrastructure
Address
Saudi Arabia (Jeddah)
Employees
150000+

Attack summary

Severity: critical — Confirmed exfiltration of large-scale PII (150,000+ employees including Saudi nationals), sensitive infrastructure design for a major World Cup venue, and confidential commercial/contract data for a high-profile public megaproject. Regulatory exposure (Saudi PII) and geopolitical sensitivity.

Wallstreet claims to have exfiltrated 17 TB and 1.5 million files from the contractor's network, including contract documents, payment certificates, dispute records, employee personal data, stadium design documentation, and supplier/subcontractor commercial information.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • Main contract documents
  • Interim payment certificates
  • Dispute and suspension claim records
  • Personal data of 150,000+ employees
  • IFC stadium design documentation
  • Supplier and subcontractor bid tabulations

What the group claims

We compromised the network of the China Railway Construction Corporation Saudi Branch / Sama Construction consortium, the MAIN CONTRACTOR building the Jeddah Central Stadium for the FIFA World Cup 2034. 17 TB / 1.5M files exfiltrated, including: - Main contract documents, interim payment certificates, and claims against the owner (Jeddah Central Development Company, PIF) - Active dispute and suspension claim records - Personal data of 150,000+ employees, incl. Saudi employees - IFC design documentation for the stadium - Supplier and subcontractor commercial data (bid tabulations)

Source

Indexed 4 hours ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About WALLSTREET

WALLSTREET has claimed 5 victims and remains active as of July 2026, operating a single onion mirror. The group's limited victim count makes sector or geographic patterns unclear at this stage. The group has been linked to 28 public disclosures across our corpus. The operation is currently active.

Timeline of this disclosure

  • October 3, 2026World Cup 2034 listed by WALLSTREET on the group's public leak site

Sector and geography

Geographically, World Cup 2034 is reported in Saudi Arabia, a country with 16 ransomware disclosures in our corpus.

If your organisation is affected

A listing by WALLSTREET means World Cup 2034 appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Monitor for the data appearing on WALLSTREET's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.