On July 8, 2025, the ransomware group Incransom added TBC to its leak site and began publishing what it claims are the company’s internal files. TBC is a fully PIF-owned governmental project management company in Saudi Arabia responsible for building and maintaining educational facilities as well as delivering services in operations, construction, facility management, investment, asset management, and Vision 2030 initiatives. Although the exact number of individuals whose records appear in the files remains unknown, anyone whose personal, employment, or family information was stored in TBC’s systems could now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch TBC
Get alerted the next time TBC files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about TBC’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Incransom exfiltrated internal documents during a ransomware attack on TBC before encrypting systems or disrupting operations. The leak site lists the victim under the entry dated July 08, 2025. Available details describe the exposed material as internal files; specific categories of personal data have not been independently verified by third parties. No confirmed count of affected records or named individuals has been released. The incident follows the group’s standard pattern of posting samples and threatening full publication or sale of the archive if demands are not met.
Why This Matters for You and Your Family
When a government-linked contractor like TBC suffers a breach, ordinary citizens and their families are often the ones placed at risk. Educational project records can contain names, addresses, phone numbers, national ID equivalents, student information, employee payroll data, and vendor contracts. Once these details surface on a ransomware leak site, they rarely disappear. Children’s schooling records, parent contact details, and household addresses become permanently available to identity thieves, stalkers, and fraudsters. Even if you have never heard of TBC, your family’s information may have been collected during routine interactions with Saudi educational infrastructure projects.
The Doxxing and Identity-Chain Implications
A single leak rarely stops at one dataset. Credential leaks and internal spreadsheets frequently cascade into account takeovers across email, banking, and social media. Attackers use automated tools to link an exposed email address to usernames on gaming platforms, then pivot to those children’s accounts for further personal details or extortion material. Public reporting on similar incidents shows that doxxing chains often begin with government-contractor data and expand to family members within days. Gaming accounts belonging to teenagers are especially vulnerable because kids reuse passwords and rarely enable strong authentication. This incident therefore carries direct risk for both adult and children’s online identities.