☑️ Weekly Darkweb – July Week 4, 2026
🔍 Saudi Intelligence Agency 'G' Data for Sale on Dark Web
• On July 22, confidential information from 'G', Saudi Arabia's foreign intelligence agency, was posted on the dark web hacking forum 'BreachForums'.
✓ Agency 'G': Saudi Arabia's core intelligence agency under the direct control of the King, responsible for foreign intelligence gathering and national security.
• Forum user '0cx00iq' claimed to possess data on approximately 52,000 employees, containing sensitive details such as ID/passport scans, ranks, salaries, and security clearance levels, releasing system screenshots and a Telegram contact for transactions.
➢ The threat actor stated the leak was in retaliation against the Saudi government's support for terrorist groups like ISIS, declaring the data will be sold to the highest bidder. Hacking intelligence agencies exposes agents' identities and risks triggering consecutive targeted attacks, posing a severe threat to national security.
🔍 Japanese Firm 'K's Singapore Subsidiary Targeted by Morpheus Ransomware
• On July 21, data from the Singapore subsidiary of 'K', a Japanese plastic plating company, was spotted on the leak site of Morpheus ransomware group.
✓ Company 'K': Founded in 1949, a Japanese manufacturer specializing in plastic plating for auto/appliance parts, with Singapore as its sole overseas production hub.
• The ransomware gang claimed to have exfiltrated 143GB of data, asserting the stolen files include client and internal HR data, quality tech specs, process workflows, and visa document data.
• The threat actors released 5 sample images as proof, including passport scans of Japanese and local employees, corporate financial transaction documents, purchase orders, and Work Pass application files.
🔍 Yemen Aviation and Meteorology Authority Targeted in Saudi Hacktivist
• On July 22, the General Authority for Civil Aviation and Meteorology (GACAM) under the Yemen Houthi rebel regime was hacked by Saudi hacktivist group 'S4uD1PWNZ,' which announced the leak on its official Telegram channel.
• The group claimed to have exfiltrated the agency's entire database, containing documents related to aviation controls and surveillance systems and employee personal information. The group also uploaded screenshots of GACAM's systems page to showcase their control for data deletion and tampering.
• The group claimed the attack was in retaliation against Houthi threats toward Saudi civilian facilities and criticized the agency for being exploited in illegal military activities tied to Iran.
*The full report is available upon request and for XARVIS subscribers.