Mecca High Feed Factory Data Breach

Alleged

Ransomware claim involving Mecca High Feed Factory.

Published: Sep 1, 2026 Krybit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Mecca High Feed Factory
Industry
Agriculture and Food Production
Threat Actor
Krybit
Date of Incident
Sep 1, 2026

Executive Summary

Krybit ransomware has claimed Mecca High Feed Factory as a victim, listing the company on its dark web portal on September 1, 2026. This listing was flagged by SOCRadar’s Dark Web Monitoring service. Mecca High Feed Factory is a Saudi Arabian enterprise operating within the agricultural feed manufacturing sector, specializing in the production of animal feed for the regional market. Its operation within a critical industry such as food production may make it an attractive target for cybercriminals seeking to leverage disruption for financial gain. Over the preceding 60 days, Krybit has asserted claims against 58 other entities. While the group predominantly targets organizations in Professional Services, Other, and Technology sectors, its recent activity includes victims in the Agriculture and Food Production industry, such as the current case. Krybit’s primary geographic targets have historically been India, Thailand, and Brazil, making Saudi Arabia an unusual location for its operations. Notable previous victims in the Agriculture and Food Production sector listed by Krybit include Alphaplantes, Mima Foods, Lemon Farm Co., Ltd., and Ferretornillos S.A.

Technical Analysis

A query for stealer-log records associated with the domain meccahighfeed[.]blogspot.com yielded no results. It is crucial to note that the queried domain is a subdomain of Blogspot, which offers limited coverage compared to dedicated corporate domains. Consequently, any credentials potentially compromised through infostealer malware would most likely be associated with a corporate email domain or an alternative online presence not encompassed by this specific search. Therefore, the absence of records in this query should not be interpreted as definitive proof that no credential exposure has occurred. Continued monitoring is recommended for Mecca High Feed Factory’s primary corporate email domain and any related business systems. The null result from the Blogspot subdomain query is largely expected and does not preclude the possibility of credential compromise through other avenues. Understanding the scope of potential data exposure is critical, especially considering how harvested credentials can be leveraged by threat actors for initial access, leading to ransomware deployment or further malicious activities. It is advisable to proactively review password hygiene and consider implementing multi-factor authentication across all critical systems.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.