
The Saudi Ministry of Industry and Mineral Resources (MIM) faced a critical security lapse, exposing an environment file to the public for an alarming 15 months. The Cybernews research team uncovered this breach, emphasizing the severity of the situation due to the sensitivity of the leaked data.
This environment (env.) file, serving as a crucial instruction set for computer programs, contained highly sensitive information that could enable threat actors to infiltrate the ministry’s systems. Such access could escalate from account takeovers to severe threats like ransomware attacks.
Established in 2019 to diversify Saudi Arabia’s economy away from oil and gas, MIM is pivotal in the nation’s industry and mineral resource operations. The leaked env. file included a range of critical data, from database credentials and mail access details to data encryption keys. Exposed SMTP credentials could allow attackers to impersonate government officials, potentially leading to social engineering attacks and data breaches.
Moreover, the compromised Laravel APP_Key, used for encryption purposes, poses a significant risk to data confidentiality if misused by threat actors. The exposure of MySQL and Redis database credentials further intensifies the threat, potentially granting access to sensitive government information and personally identifiable data (PII).
The repercussions of this breach are substantial. The leaked credentials create opportunities for account takeovers, unauthorized access to government systems, and manipulation of data or communications. The compromised data could also lead to identity theft, blackmail, or be sold on the black market, raising concerns about citizen privacy and security.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543