Ransomware victim disclosure
← All victimsSharjah National Oil Corporation
Claimed by Handala · listed 3 months ago
Status timeline
- ListedMar 3, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileSharjah National Oil Corporation (SNOC) is a state-owned oil and gas company based in Sharjah, United Arab Emirates. It is responsible for the exploration, production, and distribution of hydrocarbons within the Emirate of Sharjah and is considered one of the significant energy producers in the UAE. The corporation manages critical energy infrastructure and upstream oil and gas operations in the region.
- Industry
- Oil & Gas Exploration and Production
- Address
- Sharjah, United Arab Emirates
Attack summary
Severity: critical — 1.3 TB of data allegedly exfiltrated and published from a state-owned critical energy infrastructure operator, including financial records and contracts; this constitutes confirmed large-scale exfiltration from a critical infrastructure entity in the energy sector.Handala Hack claims to have exfiltrated 1.3 TB of confidential data from Sharjah National Oil Corporation, including financial data, oil contracts, and project details, and has published the data. The group also claims to have disrupted the company's critical infrastructure.
Data the group says was taken
AI dossier — extracted from the leak post- Financial data
- Oil contracts
- Project details
- Confidential corporate documents
What the group claims
Today, one of the UAE’s largest oil and gas giants, Sharjah National Oil Corporation, has fallen to a decisive blow from us, Handala Hack. Your critical infrastructure, the very heart of the region’s energy production and distribution, was dismantled in moments. Now, 1.3 terabytes of your most confidential financial data, oil contracts, project details, and…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

