Ransomware victim disclosure
← All victimsSEHA Organization (seha.org.sa)
listed as https://seha.org.sa · Claimed by Tengu · listed 5 months ago
Status timeline
- ListedJan 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Tengu
- Status
- Data leaked
- Country
- Saudi Arabia
- Sector
- Healthcare
- Listed on leak site
- Jan 14, 2026
About the victim
AI dossier — public-source company profileSEHA (seha.org.sa) appears to be a Saudi Arabian healthcare organization, based on its domain and country attribution. The sector is listed as Healthcare, suggesting it may be a hospital, health authority, or medical services provider operating in Saudi Arabia. No further details about its operations or scale are available from the leak post or public site excerpt.
- Industry
- Healthcare
Attack summary
Severity: high — The victim operates in the healthcare sector in Saudi Arabia and the disclosure status is 'data_published', indicating actual data release. Healthcare data typically contains sensitive PII and medical records; even without explicit inventory details, published healthcare data warrants a high severity rating.The Tengu ransomware group claims to have published data associated with the victim; the leak post is a multi-victim aggregate listing and does not provide specific encryption or exfiltration metrics for seha.org.sa individually. Data is listed as published (disclosed status: data_published).
Data the group says was taken
AI dossier — extracted from the leak post- Unknown — no specific data inventory listed for this victim in the post
What the group claims
https://seha.org.sa/ This is the official website of the Health Services Association in the Qassim region of Saudi Arabia. It is a non-profit/charitable organization that provides health and social services to those in need.
The leak post
captured from the group's siteCrown Security is a technology company specializing in information security and digital systems, offering advanced solutions to protect corporate networks and data from breaches and cyberattacks The company focuses on providing security consulting and implementing integrated protection systems tailored to each organization's needs Sileno Companies Inc. A US company primarily operating in the hospitality and real estate sectors, its activities include: Hotel operation Property management Management of hotels' restaurants and bars Hospitality project development 22.9TB was encrypted in 14 hours on 3/5/2026 More than 67.07 GB was extracted Eos Technology srl is a company with 15 years of experience in the ICT sector, initially starting as an assembly and repair laboratory for PCs and peripherals. Over time, it has developed expertise that has allowed it to become a partner of various international brands. The company offers a range of services including IT assistance, multimedia services, help desk support, corporate security systems, and the design of virtual switchboards and video surveillance systems. Eos Technology srl aims to provide consulting services to clients navigating th…
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

