Quick Summary
AllegedExecutive Summary
Al-Futtaim Group, a prominent retail and e-commerce organization headquartered in the United Arab Emirates, has been identified as a victim by the Everest ransomware group. The disclosure appeared on the ransomware group’s dark web portal on August 5, 2026, and was initially detected by SOCRadar’s Dark Web Monitoring service. Operating across various retail and commerce sectors, Al-Futtaim Group’s conglomerate structure is characteristic of major regional players. This incident marks the third listing of a UAE-based organization by Everest within a specific timeframe, with Al-Futtaim Group being the most significant entity among them. In the 60 days preceding this listing, the Everest ransomware group claimed responsibility for 18 other victims, primarily targeting the technology, professional services, and energy and utilities sectors. Their operations have predominantly impacted organizations in the United States, India, and the United Arab Emirates. Other recent victims from the UAE listed by Everest include Emirates Flight Catering, NIMR Oil, Keysight, and Stadler Rail. The inclusion of three UAE-based companies within a two-month period indicates a notable concentration of activity by Everest in the region, and Al-Futtaim Group’s substantial size positions it as a particularly high-profile target.
Technical Analysis
Analysis of SOCRadar’s stealer-log telemetry revealed a critical exposure associated with the alfuttaim.com domain. The query returned 11 credentials identified as employee credentials, all linked to organization-controlled systems. These credentials included corporate usernames and were used for authentication against identity, federation, and mail infrastructure, specifically targeting the group’s cloud identity provider and an internal ADFS endpoint. The log entries date back to early August 2026, just prior to the leak site listing. The concentration of exposure on federation endpoints is a significant concern, as a single validated credential at this level can potentially grant access to a wide array of downstream applications. For ransomware operations like Everest, credentials harvested via infostealers represent a well-established method for initial access. Threat actors or initial access brokers often procure recent logs from underground marketplaces, validate corporate credentials, and subsequently use them to infiltrate systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log data does not definitively confirm that these specific credentials were exploited by Everest, the observed pattern aligns closely with the typical intrusion kill chain for such incidents. Consequently, cybersecurity intelligence teams monitoring this listing should consider the exposed corporate identities a persistent risk. Given the observed credential exposure and its potential implications for initial access, it is recommended that Al-Futtaim Group prioritize proactive measures. These should include continuous monitoring of dark web and stealer-log feeds, thorough credential hygiene checks, immediate password rotation for affected accounts, and a review of multi-factor authentication configurations. Furthermore, monitoring of Microsoft 365, VPN, and remote-access portal activity for any suspicious login attempts or anomalous behavior is crucial. Organizations should also consider monitoring alternate corporate domains that may not have been included in the initial query.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.