Ransomware victim disclosure
← All victimsArabian Procession Holding
Claimed by thegentlemen · listed 6 hours ago
Status timeline
- Listed
Jun 4, 2026
- Data leaked
At a glance
- Group
- thegentlemen
- Status
- Data leaked
- Country
- SA
- Sector
- Business Services
- Listed on leak site
- Jun 4, 2026
About the victim
AI dossier — public-source company profileArabian Procession Holding is a family-owned investment firm established in 1989 and based in Riyadh, Saudi Arabia. The company manages a diversified portfolio spanning aviation, real estate, contracting, and retail sectors, including duty-free retail operations in Saudi international airports. It operates across the GCC and MENA regions with strategic expansion ambitions.
- Industry
- Investment & Portfolio Management
- Address
- Riyadh, Saudi Arabia
- Founded
- 1989
Attack summary
Severity: low — No proof files, screenshots, or data samples are mentioned in the leak post. No operational impact is stated. The disclosure appears to be a listing announcement without substantiating evidence or details of data exposure.The threat actor claims to have compromised Arabian Procession Holding and published data. The leak post provides no explicit detail on whether data was exfiltrated, encrypted, or both, nor specifics on the scope or type of data accessed.
What the group claims
***.com.sa ***.com/c/arabian-procession-holding/483326397 Established in 1989, Arabian Procession Holding (APH) is a prominent family-owned investment firm based in Riyadh, Saudi Arabia, managing a diversified portfolio across the aviation, real estate, contracting, and retail sectors. Over the past three decades, the company has expanded its strategic footprint, notably operating duty-free shops in Saudi international airports through high-profile joint ventures. Driven by a commitment to sustainable growth, APH continues to develop local and global brands, delivering exceptional value to businesses and consumers alike
Sources
- Victim siteaph.com.sa
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
