On November 26, 2023, Qatari general contractor AlJaber Engineering (JEC) appeared on the leak site operated by the ransomware group known as RansomEXX. The listing states that internal files were exfiltrated during a ransomware attack on the company, which serves as a leading construction and engineering firm based in Qatar. Anyone whose personal or employment records were stored in those systems may now face long-term exposure.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch AlJaber Engineering
Get alerted the next time AlJaber Engineering files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about AlJaber Engineering’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The RansomEXX leak site entry, still accessible via its onion address as of the initial publication, claims that internal files were exfiltrated after the group deployed ransomware against AlJaber Engineering. The disclosure does not quantify how many records were taken, list specific data types such as names, addresses, financial details or employee identification numbers, or provide a ransom demand figure. It simply states that data was stolen and is now held by the attackers. The exact date of initial compromise also remains undisclosed in the listing.
Why This Matters for You and Your Family
If you or a family member have ever worked at AlJaber Engineering, supplied services to the company, or had personal information stored in its contractor or HR systems, your data could be in the hands of extortionists. Internal files from a construction firm of this scale frequently contain employee records, subcontractor agreements, banking coordinates, passport copies, and family contact details. Once such material leaves the victim’s control, it rarely stays private. Families in Qatar and across the Gulf region who rely on contracts with large engineering firms should treat this claimed breach as a direct personal risk rather than a distant corporate event.
Doxxing and Identity-Chain Implications
Stolen internal files create durable doxxing material that links professional identities to home addresses, phone numbers, relatives’ names, and sometimes photographs. Attackers or opportunistic criminals can chain this information with credential leaks from other breaches to take over email accounts, social-media profiles, or even children’s gaming accounts that reuse the same passwords or recovery phone numbers. A single exposed work email can lead to SIM-swapping attempts or targeted phishing campaigns against your household. The longer the data sits on a ransomware leak site, the more likely it is to be downloaded, repackaged, and sold on underground forums.