Ransomware victim disclosure
← All victimsAl Rawdah Springs (Al Rawdah Green Sweet Water L.L.C)
listed as rswater.ae · Claimed by INC Ransom · listed 4 months ago
Status timeline
- ListedFeb 12, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- Saudi Arabia
- Listed on leak site
- Feb 12, 2026
About the victim
AI dossier — public-source company profileAl Rawdah Springs is the consumer brand of Al Rawdah Green Sweet Water L.L.C, an Emirati company specialising in the production and bottling of natural mineral water in multiple sizes (150 ml to 5-gallon) for homes, offices, and businesses across the UAE. The company has operated since 2003 and holds EQM, ESMA, and ISO 22000 certifications, as well as a Superior Taste Award. It distributes across all seven emirates with free delivery on orders above AED 250.
- Industry
- Natural Mineral Water Production & Bottling
- Address
- United Arab Emirates (delivers across all 7 emirates; exact street address not stated)
- Founded
- 2003
Attack summary
Severity: medium — Data has been published (disclosed status: data_published), confirming exfiltration beyond a mere listing. However, no specific sensitive regulated data categories (e.g., large-scale PII, financial, medical) are enumerated, and the victim is a mid-sized consumer water brand rather than critical infrastructure, placing this at medium rather than high or critical.INC Ransom claims to have compromised Al Rawdah Springs and has moved to a data-published status, indicating exfiltration and publication of company data. No specific data categories, ransom amount, or file count were stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal data (nature unspecified)
What the group claims
Al Rawdah Springs is a brand affiliated to Al Rawdah Green Sweet Water L.L.C an Emirati firm with local management specializing in the production and bottling of water in various sizes.
Sources
- Victim siterswater.ae
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

