A threat actor has allegedly breached Kalad, a company described as a mining and logistics contractor in Saudi Arabia. In a post on a cybercrime forum, the hacker claimed to have not only exfiltrated the company’s entire database but also defaced its official website, kalad.com.sa. The post included a screenshot of the defaced homepage as proof of the intrusion.
Kalad is allegedly a contractor in Saudi Arabia’s vital mining and logistics sector. Companies in this industry play a significant role in the Kingdom’s supply chain and economic infrastructure, making them potentially high-value targets for cyberattacks. The successful breach of such an entity could expose sensitive operational and commercial data, impacting its clients and business continuity.
The threat actor advertised a full database dump for download, which allegedly contains a wide range of sensitive information. The attacker also claimed the breach was accomplished using a “Zero-Day exploit.” The compromised data allegedly includes:
- Full client records
- Internal emails
- Employee credentials
- Contract files and more…