Ransomware victim disclosure
← All victimsAWJ Holding
Claimed by Thegentlemen · listed 4 hours ago
Status timeline
- ListedAug 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- United Arab Emirates
- Listed on leak site
- Aug 21, 2026
About the victim
AI dossier — public-source company profileAWJ Holding is a Saudi-based single-family office and investment firm headquartered in Riyadh, established in 2016. The company specializes in real estate development and property management with operations across retail, hospitality, and infrastructure sectors, managing approximately 32 billion Saudi Riyals in assets under management.
- Industry
- Real Estate Development, Property Management & Strategic Investment
- Address
- 7586 King Fahd Branch Road – Ar Rahmaniyah, Riyadh, Kingdom of Saudi Arabia
- Founded
- 2016
Attack summary
Severity: medium — Data published status with no operational disruption claimed, but lack of detail on data type/volume and absence of proof artifacts listed prevents higher confidence. Company handles significant financial and real estate assets, suggesting moderate sensitivity if breached.The threat actor claims to have accessed and exfiltrated data from AWJ Holding but does not specify the nature, volume, or sensitivity of the data compromised in the available post excerpt.
What the group claims
awjholding.com zoominfo.com/c/awj-holding-co/448239448 AWJ Holding Company is a prominent Saudi-based single-family office and investment firm established in 2016. Headquartered in Riyadh, the company specializes in real estate development, property management, and strategic investment management. It focuses on high-impact developments and operates dynamic subsidiaries across retail, hospitality, and infrastructure sectors.
Sources
- Victim siteawjholding.com
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

