Wallstreet ransomware actors claim they compromised the Saudi network of the China Railway Construction Corporation Saudi Branch / Sama Construction consortium, targeting the main contractor work for the Jeddah Central Stadium for FIFA World Cup 2034 in Saudi Arabia. They report exfiltrating 17 TB and 1.5M files, including contract, dispute/suspension documentation, IFC design files, supplier bid data, and personal data for 150,000+ employees. #SaudiArabia
Incident Details
- Victim: World Cup 2034
- Sector: Other
- Country: SA
- Actor: Wallstreet
- Source:
- Discovered: 2026-10-03T11:54:05.389560+00:00
- Published: 2026-10-03T11:25:00+00:00
Information
- Compromised the network of the China Railway Construction Corporation Saudi Branch / Sama Construction consortium, the main contractor building the Jeddah Central Stadium for the FIFA World Cup 2034.
- 17 TB across 1.5M files were exfiltrated.
- Main contract documents, interim payment certificates, and claims against the owner were taken.
- Active dispute and suspension claim records were exfiltrated.
- Personal data of more than 150,000 employees, including Saudi employees, was accessed.
- IFC design documentation for the stadium was stolen.
- Supplier and subcontractor commercial data, including bid tabulations, was also taken.
Disclaimer: This post is based on public claims made by the ransomware group "Wallstreet". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.