Arabia Falcon Insurance Company SAOG Data Breach

Alleged

Ransomware claim involving Arabia Falcon Insurance Company SAOG.

Published: Jul 7, 2026 TheGentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Arabia Falcon Insurance Company SAOG
Industry
Finance
Threat Actor
TheGentlemen
Date of Incident
Jul 7, 2026

Executive Summary

SOCRadar has identified that Arabia Falcon Insurance Company SAOG, an insurance provider based in Oman, has been listed as a victim by the TheGentlemen ransomware group on their dark web portal as of July 7, 2026. This incident marks an expansion of TheGentlemen’s operations into the Gulf region, extending their recent targeting spree which has already impacted numerous companies globally. TheGentlemen ransomware group has been exceptionally active, claiming over 116 victims in the 60 days prior to this listing. Their typical targets include the business services, manufacturing, and healthcare sectors, with a geographical concentration in the United States, Germany, and India. While Arabia Falcon Insurance Company SAOG’s inclusion suggests the group is broadening its scope, other recent listings in the financial services sector, such as Ross Yerger Insurance and Amstel Securities, indicate a continued interest in this industry.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry has revealed a potential initial access vector for the afic.om domain. The data showed seven records, primarily non-corporate credentials on customer/agent portals, along with one corporate email credential exposed on a third-party service. This single corporate credential suggests a possible endpoint compromise and an administrative login exposure, indicating a blended risk profile that includes both customer-facing fraud and isolated corporate account compromise. The presence of exposed corporate credentials is a common initial access method for ransomware groups like TheGentlemen. They often source credentials from stolen data logs purchased on underground marketplaces to gain access to systems. While this specific finding does not confirm that these credentials were used by TheGentlemen, it aligns with the typical early stages of their attack kill chain. CTI teams are advised to treat the exposed corporate credential as a potential access path and to prioritize its rotation, invalidation of related sessions, and review of associated sign-in activity.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.