Skip to main content
← All threats
CRITICAL Published June 30, 2026

Sale of documents and access credentials from Dar.com SharePoint portal

A threat actor is offering for sale documents exfiltrated from the SharePoint portal of Dar Al-Handasah (dar.com), a global engineering and consultancy firm. The offering includes internal employee PDF files, project documents, access to the employee portal, Saudi Arabian government-related data, and attached cookie/session tokens. The seller requires contact via PM (TOXIM/Jabber) and accepts escrow.

A threat actor is offering for sale documents exfiltrated from the SharePoint portal of Dar Al-Handasah (dar.com), a global engineering and consultancy firm. The offering includes internal employee PDF files, project documents, access to the employee portal, Saudi Arabian government-related data, and attached cookie/session tokens. The seller requires contact via PM (TOXIM/Jabber) and accepts escrow.

MITRE ATT&CK

Tactics, Techniques & Procedures

TA0001 Initial Access tactic

Defensive mapping

Mapped controls

The audit will verify each of these controls is in place and effective.

No controls mapped yet. Map controls →