Ransomware victim disclosure
← All victimsAl-Futtaim Group
Claimed by Everest · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Everest
- Status
- Data leaked
- Country
- United Arab Emirates
- Sector
- Retail & E-Commerce
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profileAl-Futtaim Group is one of the Middle East's largest family-owned diversified conglomerates headquartered in Dubai, UAE, with 40,000+ employees across 20+ countries. Operating since the 1930s, it represents 200+ global brands including IKEA, Toyota, and Marks & Spencer, spanning automotive, retail, real estate, financial services, healthcare, and education sectors.
- Industry
- Diversified Conglomerate (Automotive, Retail, Real Estate, Financial Services, Healthcare, Education)
- Address
- Dubai, United Arab Emirates
- Employees
- 40000
- Founded
- 1930
Attack summary
Severity: medium — Large multinational conglomerate with significant operational footprint and employee base; however, no proof files, data samples, or specific exfiltration details are disclosed in the available post. Severity elevated from 'low' due to company scale and data sensitivity risk inherent to financial services and healthcare divisions.The Everest ransomware group claims to have attacked Al-Futtaim Group. No specific details regarding encryption, exfiltration, or data compromise are provided in the available leak post excerpt.
Original description
AI-summarised, not from the leak postAl-Futtaim Group is a diversified conglomerate headquartered in Dubai, United Arab Emirates. Founded in the 1930s, it operates across retail, automotive, real estate, and financial services sectors. The group represents major global brands including IKEA, Toyota, and Marks & Spencer across the Middle East, Africa, and Asia. It is one of the region's most prominent privately held business enterprises.
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

