Xlab Group listed by the Fog ransomware group
Xlab Group
Overview
Xlab Group, an Egypt-based technology and advertising company, was listed by the Fog ransomware group on 3 February 2025. The group published extracts from GitLab repositories as evidence, naming Xlab Group among the affected projects. Xlab operates digital and marketing services across the Middle East and North Africa.
What was published
The Fog disclosure includes a GitLab extract covering Xlab Group and other projects. This indicates source code and development assets were accessed during the intrusion. The group advertised the stolen material on its leak site, which has since gone offline.
Risks for affected individuals
Exposed repositories can contain credentials, API keys, and client integration details. If customer data or employee records are part of the archive, affected people could face phishing and account fraud.
What remains unknown
The size of the exfiltration is not disclosed. Whether production databases or client data were captured alongside source code is unclear, and no official confirmation from the company has been published.
What affected people should do
Clients should monitor communications and rotate any credentials shared with Xlab. The company should revoke exposed secrets, review repository access, and inform customers if their data was part of the leak.
Sources
- http://xbkv2qey6u3gd3qxcojynrt4h5sgrhkar6whuo74wo63hijnn677jnyd.onion/posts/67a101aa03e546ad96cc22ec/