Ransomware victim disclosure
← All victimsAl Rawdah Springs (Al Rawdah Green Sweet Water L.L.C)
listed as rswater.ae · Claimed by Incransom · listed 4 months ago
Status timeline
- ListedFeb 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- Saudi Arabia
- Listed on leak site
- Feb 12, 2026
About the victim
AI dossier — public-source company profileAl Rawdah Springs is the consumer brand of Al Rawdah Green Sweet Water L.L.C, an Emirati company specialising in the production and bottling of natural mineral water in multiple sizes, from 150 ml cups to 5-gallon containers. Operating since 2003, the company is EQM- and ISO 22000-certified and delivers across all seven UAE emirates to homes, offices, and businesses. It has received the Superior Taste Award 2026 and markets itself as a low-sodium, award-winning UAE water brand.
- Industry
- Bottled Water Production & Distribution
- Address
- UAE (delivers across all 7 Emirates; specific street address not stated)
- Founded
- 2003
Attack summary
Severity: medium — Data has been published by the group, indicating confirmed exfiltration; however, no specific sensitive regulated data categories (e.g. medical, financial at scale, government) are described, and the company is a mid-sized consumer goods firm in the UAE, limiting the severity below critical.The Incransom group claims to have compromised Al Rawdah Springs and has published the data (disclosed status: data_published), asserting access to company data without specifying encryption or the precise volume exfiltrated.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal data
- Customer records (potential)
- Business operational data
What the group claims
Al Rawdah Springs is a brand affiliated to Al Rawdah Green Sweet Water L.L.C an Emirati firm with local management specializing in the production and bottling of water in various sizes.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

