Ransomware victim disclosure
← All victimsGulf Business Machines (GBM)
listed as gbmme.com · Claimed by Incransom · listed 5 months ago
Status timeline
- ListedJan 13, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- UAE
- Sector
- Technology
- Listed on leak site
- Jan 13, 2026
- Data size
- 200 GB
About the victim
AI dossier — public-source company profileGulf Business Machines (GBM) is a leading end-to-end digital solutions provider headquartered in Abu Dhabi, UAE, with over 36 years of experience and 7 offices across the GCC region. The company employs over 1,500 staff and offers a broad portfolio of technology, security, infrastructure, managed services, and cloud solutions. GBM serves local, regional, and international organisations and maintains partnerships with major global technology vendors including IBM, Red Hat, and Cisco.
- Industry
- IT Solutions & Digital Infrastructure Services
- Address
- Abu Dhabi, United Arab Emirates
- Employees
- 1500
- Founded
- 1990
Attack summary
Severity: high — 200 GB of confirmed exfiltrated data including financial records, internal communications, and budget documents from a major regional IT solutions provider with 1,500+ employees and significant government and enterprise clientele; data has been published, elevating impact beyond a mere listing.The Incransom group claims to have exfiltrated 200 GB of data from GBM, including fiscal data, internal email communications, budgets, and other unspecified materials. The disclosed status indicates data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- Fiscal data
- Internal email communications
- Budgets
- Unspecified additional business data
What the group claims
Founded in 1990, based out of Abu Dhabi, United Arab Emirates, Gulf Business Machines (GBM) is a IT solutions provider, fulfilling the IT requirements of local, regional and international organisations in the GCC. We have 200GB of data at our disposal (fiscal data, internal mail,budgets and many other things)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

