ransomware Credible Egypt (EG) conglomerate

Arabia Holding listed by the Qilin ransomware group

Arabia Holding

📅 26 November 2025
CompanyArabia Holding
CountryEgypt (EG)
Sectorconglomerate
Breach date2025-11-26
People affectedNot disclosed
Ransomware groupqilin
Data typescorporate records, financial data, employee information

Overview

The Qilin ransomware group has listed Arabia Holding, an Egyptian conglomerate, on its leak site. The listing appeared on 26 November 2025. At the time of analysis, the group's leak page was not reachable.

What was published

The group claims to have exfiltrated corporate data from the conglomerate. The archive is expected to include business records, financial documents and employee files.

Risks for affected individuals

  • Employees' personal records may be exposed.
  • Commercial data could be of value to competitors.
  • Financial information may enable fraud attempts.

What remains unknown

  • The volume of data stolen.
  • The exact contents of the leak.
  • Whether the data has been published elsewhere.

What affected people should do

Employees should update credentials and watch for phishing referencing the company. Arabia Holding should notify staff and partners, engage cybersecurity experts, and coordinate with Egyptian authorities on the response.

Sources

  • http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/view?uuid=cbc0010b-7bfd-3df0-a55a-002cdeff0a20