Ransomware victim disclosure
← All victimsDemirtaş Organize Sanayi Bölgesi (DOSAB)
listed as Dosab · Claimed by Nova · listed 5 hours ago
Status timeline
- ListedJun 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Nova
- Status
- Data leaked
- Country
- Saudi Arabia
- Sector
- Manufacturing
- Listed on leak site
- Jun 20, 2026
About the victim
AI dossier — public-source company profileDOSAB is an organized industrial zone in Turkey hosting over 573 active companies and approximately 44,000 employees. It provides infrastructure and services including wastewater treatment, energy supply, and social facilities to support industrial clients across sectors such as automotive and textile.
- Industry
- Industrial Park / Manufacturing & Logistics Hub
- Employees
- 44000
Attack summary
Severity: high — Data exfiltration confirmed (group claims possession of stolen data samples); significant operational impact potential given DOSAB's critical role as an industrial zone serving 44,000+ employees and 500+ companies. Infrastructure and administrative data compromise poses supply chain and operational risk.Nova claims to have exfiltrated data from DOSAB. The group states it possesses samples and trees from the stolen dataset and offers to provide proof upon contact with the support department.
Data the group says was taken
AI dossier — extracted from the leak post- operational records
- company databases
- administrative files
What the group claims
Demirtaş Organize Sanayi Bölgesi (DOSAB) provides a range of services including waste water treatment, energy supply, and social facilities to support its industrial clients. The region hosts over 573 active companies and employs around 44,000 people, focusing on sectors such as automotive and textile. DOSAB is committed to sustainability and offers various online services and resources for its members. The organization also emphasizes social responsibility through community engagement and educational initiatives - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

