Quick Summary
AllegedExecutive Summary
Al – Saidi Factory, a manufacturing organization in Saudi Arabia, was listed on the DragonForce ransomware group’s dark web leak portal on July 12, 2026. SOCRadar’s Dark Web Monitoring service identified the listing. The group’s victim profile shows a focus on Business Services, Manufacturing, and Agriculture and Food Production sectors, with a geographical concentration in the United States, United Kingdom, and Germany. Al – Saidi Factory’s inclusion aligns with this pattern.
Technical Analysis
SOCRadar’s stealer-log telemetry revealed a credential exposure for the alsaidi.com domain, with a single employee credential pair found tied to a company host on a non-standard port (alsaidi.com:4228). This was classified as internal employee access and dated to July 2025, with no long-tail persistence detected. The exposure suggests a corporate intrusion risk. While not confirming DragonForce’s use of these specific credentials, the pattern aligns with typical initial access vectors for ransomware attacks, highlighting the importance of credential rotation and endpoint forensics for the affected accounts.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.