ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Ransomware gang claims theft of 1TB of data from Burj Khalifa fire-safety contractor NAFFCO

A major ransomware group claimed it had stolen a terabyte of internal data from NAFFCO FZCO, the Dubai fire-safety engineering firm responsible for the fire protection systems at the Burj Khalifa, placing the company under heightened scrutiny as investigators examined the scope and potential impact of the breach.


The claim appeared on November 17 on a dark-web leak portal operated by the INC ransomware gang. The post asserted that attackers had taken 1TB of data from NAFFCO, a global manufacturer of firefighting equipment, fire protection systems, alarms, and other security engineering solutions. The company generated $4.4 billion in annual revenue and served government agencies, civil defense authorities, emergency-response organizations, and major energy companies, including ADNOC, ADCO, and ZADCO. Beyond the Burj Khalifa, the firm had designed fire-safety systems for other high-profile projects, including the Louvre Abu Dhabi and the Oman Convention and Exhibition Centre.


The gang published a statement mocking NAFFCO’s public commitment to safety and issued threats aimed at pressuring the company to negotiate. The post reflected a pattern of coercion used routinely by ransomware groups seeking ransom payments to prevent the release or sale of stolen material.


Attackers also published 47 screenshots that appeared to show samples of data taken from NAFFCO’s systems. The images displayed documents outlining the company’s organizational structure, employee names, job titles, email addresses, phone numbers, and financial information tied to projects. Other screenshots appeared to show annual contract lists, individual client agreements, and employee identification details, including visa information and photographs of ID documents.


The data, if authentic, placed employees at heightened risk of identity theft and social-engineering attempts. The materials also suggested potential reputational exposure for the company by revealing sensitive operational and business information. NAFFCO had not issued a response at the time the claim surfaced.


INC Ransom, identified by analysts as a Russia-linked cybercrime group, had operated a multi-extortion model since emerging in July 2023. The gang claimed 453 victims and routinely targeted institutions across sectors, including hospitals, schools, municipal governments, corporations, and cultural organizations. Recent claims included breaches involving Summit Golf Brands, the defense contractor Stark AeroSpace, the San Francisco Ballet, the City of Leicester in England, NHS Dumfries and Galloway in Scotland, Xerox Corporation, and the global retailer Ahold Delhaize. Other alleged victims included Mount Rogers Community Services, The Catholic Cemeteries of the Diocese of Hamilton in Canada, Thomasville in North Carolina, and CNN Indonesia.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543