Skip to main content

Ransomware victim disclosure

All victims

UAE Federal Customs Authority

Claimed by NASIR · listed 6 days ago

30+ TB
Data size
6d
Age
since listed · data leaked

Status timeline

  1. ListedJun 11, 2026
  2. Data leakeddate unknown

At a glance

Group
NASIR
Status
Data leaked
Listed on leak site
Jun 11, 2026
Data size
30+ TB

About the victim

AI dossier — public-source company profile

The UAE Federal Customs Authority is the official government agency responsible for customs operations, trade regulation, and border control for the United Arab Emirates. It manages import/export documentation, tariff collection, and goods inspection across UAE ports and entry points.

Industry
Government / Customs Authority

Attack summary

Severity: critical — Confirmed exfiltration of 30+ TB from a critical government infrastructure entity (customs authority). Data includes classified information, personnel records, and operational customs/trade data affecting national security and government operations. Government/critical infrastructure breach at national scale.

NASIR group claims to have exfiltrated 30+ TB of classified data from UAE Federal Customs Authority databases and data centers, including internal communications, personnel records, trade documents, and customs records. The group states the data reveals UAE export relationships and has shared material with Hezbollah.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • Internal messages and communications
  • Personnel photographs and records
  • Trade documents and invoices
  • Customs clearance records
  • Economic asset information
  • Export transaction data
  • Trade license records

The group's post references roughly 4 proof files.

What the group claims

The group claims to have obtained over 30 terabytes of classified data from the UAE Federal Customs Authority, including messages, documents, photos of personnel, economic assets, and cargo information allegedly revealing goods exported from the UAE to Israel.

The leak post

captured from the group's site
#  UAE Customs (Federal Customs Authority) - ACCESS GRANTED ! 
Peace be upon the Resistance and its martyrs.God has favored us, and we have obtained thirty terabytes or more of classified information belonging to the treacherous United Arab Emirates’ customs authority.This data includes messages, documents, photos of individuals and personnel, economic assets, and other materials that reveal goods and information exported from the UAE to the accursed Zionist Israeli entity.This cyber infiltration is among the largest hacking and penetration operations in recent times, targeting databases and data centers.We, the sons of the supporters, have released a small portion of this data to confront the UAE, discourage its relationship with evil Israel, and demonstrate our ability to strike the Emirates and others.If the UAE denies the authenticity of this information, we will disclose much more, so that the world will see the extent of the UAE’s betrayal of the Islamic and Arab nation, and its decades-long service to cursed Israel, both before and after normalization.The data has been shared with our brothers in the Resistance, Hezbollah, for appropriate action.As for a word concerning our …

Data the group says was taken

  • messages
  • documents
  • photos
  • personnel records
  • economic asset records
  • cargo/trade documents

Screenshot of the leak post

Leak screenshot for UAE Federal Customs Authority

Sources

Source

Indexed 6 days ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About NASIR

NASIR is an emerging ransomware group first observed in June 2026 with a apparent financial motivation, having claimed responsibility for attacks against at least seven known victims across the Middle East region. The group's targeting pattern strongly suggests a geopolitical or regional focus, with victim organizations concentrated in the United Arab Emirates, Israel, Saudi Arabia, and Kuwait, spanning high-value sectors including government, energy and oil, transportation, aviation, and cultural and memorial institutions. Given the limited open-source intelligence currently available on NASIR, its country of origin, affiliation with known threat actor ecosystems, and whether it operates under a Ransomware-as-a-Service model or as an independent closed group have not been publicly confirmed by authoritative sources such as CISA, the FBI, or Mandiant as of this writing. The group's sector targeting — particularly government, energy infrastructure, and aviation — suggests a deliberate focus on critical national infrastructure across Gulf Cooperation Council states and Israel, which may indicate either a financially motivated actor seeking high-value targets capable of large ransom payments, or an actor with ideological or geopolitical objectives. No specific tools, encryption methods, or extortion tactics employed by NASIR have been publicly documented or attributed by reputable security researchers at this time, and no major law enforcement actions against the group have been publicly reported. NASIR should be considered an emerging and closely monitored threat given its critical infrastructure targeting pattern, with the expectation that additional technical attribution and campaign details will surface as the group's operational tempo develops. The group has been linked to 8 public disclosures across our corpus. First observed on a leak site on June 10, 2026; most recent post June 11, 2026. The operation is currently active.

Timeline of this disclosure

  • June 11, 2026UAE Federal Customs Authority listed by NASIRon the group's public leak site
Data size
30+ TB

Sector and geography

This disclosure adds to ransomware activity in the Government / Customs sector. Geographically, UAE Federal Customs Authority is reported in United Arab Emirates, a country with 9 ransomware disclosures in our corpus.

If your organisation is affected

A listing by NASIR means UAE Federal Customs Authority appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, aeCERT (United Arab Emirates), as required for your jurisdiction.
  • Monitor for the data appearing on NASIR's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.

UAE Federal Customs Authority data breach — NASIR ransomware leak (2026) · Darkfield