Ransomware victim disclosure
← All victimsLootah Group
Claimed by Snatch · listed 5 years ago
Status timeline
- ListedDec 2, 2021
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- UAE
- Sector
- Business Services
- Listed on leak site
- Dec 2, 2021
About the victim
AI dossier — public-source company profileLootah Group is a Dubai-based international conglomerate founded in 1973 by Ibrahim Saeed Ahmed Lootah, a member of one of Dubai's founding families. The group has grown over nearly five decades into a multinational corporation with a broad portfolio of businesses and a worldwide presence. It operates across multiple sectors as a diversified holding entity headquartered in the UAE.
- Industry
- Diversified Conglomerate
- Address
- Dubai, United Arab Emirates
- Founded
- 1973
Attack summary
Severity: high — Data has been confirmed as published by the threat actor against a large, internationally operating conglomerate, indicating exfiltration of potentially significant business and corporate data. The scale of the organisation and the confirmed publication elevate this beyond medium severity.The Snatch ransomware group claims to have compromised Lootah Group and has published data ('data_published' status), indicating exfiltration of company data. The specific categories of data exfiltrated and the volume are not detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
What the group claims
Formed at the heart of UAE in 1973 by the vision of Mr. Ibrahim Saeed Ahmed Lootah who hails from a Founding Family in Dubai, Lootah Group has consistently grown to become an international corporation with a strong world-wide presence. A 47-year old global conglomerate,
Source
Indexed 5 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

