Ransomware victim disclosure
← All victimsAlghanim International General Trading & Contracting Co. WLL
listed as Fouad Alghanim & Sons Group of Companies Holding W.L.L. · Claimed by radar · listed 7 months ago
Status timeline
- Listed
Oct 31, 2025
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileAlghanim International General Trading & Contracting Co. WLL is a Kuwaiti company operating under the domain falghanim.com and associated with the Fouad Alghanim & Sons Group of Companies. The group is a major Kuwaiti conglomerate engaged in general trading and contracting activities. It is a distinct entity from the similarly named Alghanim Industries.
- Industry
- General Trading & Contracting
- Address
- Kuwait
Attack summary
Severity: high — Data has been published (disclosed status: data_published) and confidential business documents have been exfiltrated and made available on a Tor server, indicating confirmed exfiltration of sensitive business data from a significant regional conglomerate.The Radar ransomware group claims to have exfiltrated confidential files from the company and published a link to files marked confidential on a Tor-based server, demanding contact for removal of the data.
Data the group says was taken
AI dossier — extracted from the leak post- Files marked confidential
The group's post references roughly 1 proof file.
What the group claims
The full company name associated with the website falghanim.com is Alghanim International General Trading & Contracting Co. WLL. This company is an associate of the Fouad Alghanim & Sons Group of Companies, a separate entity from the similarly named Alghanim Industries (which uses the website alghanim.com). Files Marked Confidential - http://4q5tsu5o3msmv4am4dfhupwhzlyg7wv3lpswbvbhcrknr4ega7xetxad.onion/falghanim.com%20KUWAIT/Files%20Marked%20Confidential.txt . Contact us to remove the files from our servers!
Source
Indexed 7 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
