Ransomware victim disclosure
← All victimsNobani Co
Claimed by Deadlock · listed 5 hours ago
Status timeline
- ListedJun 15, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileNobani & Co is a professional accounting and advisory firm established in 1994 and headquartered in Amman, Jordan. The company is an independent member of the Praxity international alliance and specializes in audit, tax, payroll, secretarial and business advisory services across multiple sectors including manufacturing, IT, telecommunications, healthcare, real estate, and NGO sectors.
- Industry
- Accounting, Tax, Audit & Advisory Services
- Address
- P.O. Box 1219, Amman, 11118 Jordan; Wadi Saqra, Al Sharif Nasser Bin Jamil Street, Al-Mirad Building #39, 2nd Floor, Amman, Jordan
- Founded
- 1994
Attack summary
Severity: medium — Data published status indicates exfiltration; however, no proof files are described, data volume is unstated, and the post excerpt is truncated. Given the firm's access to sensitive client financial, tax, and payroll data across regulated sectors, exposure is of moderate-to-high sensitivity but lacks concrete proof quantification.The Deadlock group claims to have attacked Nobani & Co; however, the truncated leak post provides no detail on the nature of the attack (encryption, exfiltration, or both) or specific data compromised.
Data the group says was taken
AI dossier — extracted from the leak post- Client financial records
- Tax documentation
- Payroll data
- Business advisory files
- Due diligence materials
What the group claims
Nobani & Co a professional financial services firm established in 1994. The company is headquartered in Amman, Jordan, and functions as an independent member of the Praxity international alliance of accounting and advisory firms.
Sources
- Victim sitenobani.com
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

