Ransomware victim disclosure
← All victimsAl Khaja Holding
Claimed by Thegentlemen · listed 5 hours ago
Status timeline
- ListedJun 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- United Arab Emirates
- Sector
- Business Services
- Listed on leak site
- Jun 20, 2026
About the victim
AI dossier — public-source company profileAl Khaja Holding is a prominent multi-business conglomerate based in Abu Dhabi, UAE, originally established in 1969 as the Abu Dhabi Tyre Company. The group operates a diverse portfolio across oil and gas, healthcare, pharmaceuticals, and retail distribution sectors through multiple subsidiary enterprises.
- Industry
- Diversified Conglomerate (Oil & Gas, Healthcare, Pharmaceuticals, Retail Distribution)
- Address
- Abu Dhabi, United Arab Emirates
- Founded
- 1969
Attack summary
Severity: low — Post contains only announcement and company background information with no proof files, screenshots, data samples, or explicit claims of data exfiltration or operational disruption.The group claims to have compromised Al Khaja Holding but provides no details on the nature of the attack (encryption vs. exfiltration) or specific data accessed in the truncated leak post.
What the group claims
***.com rocketreach.co/al-khaja-holding-profile_b451cc56fc778622 Al Khaja Holding is a prominent multi-business conglomerate based in the United Arab Emirates, originally established in 1969 as the Abu Dhabi Tyre Company.The group manages a diverse portfolio of investments across various sectors, including oil and gas, healthcare, pharmaceuticals, and retail distribution.Operating from its headquarters in Abu Dhabi, the holding company plays a significant role in the region's commercial landscape by overseeing its wide variety of subsidiary enterprises
Sources
- Victim sitealkhajaholding.com
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

