Skip to main content
← All threats
CRITICAL Published July 1, 2026

Sale of internal documents and access from Dar (Dar Al-Handasah) SharePoint portal

A threat actor is selling internal documents and access obtained from the SharePoint portal of Dar (formerly Dar Al-Handasah), a global engineering and consultancy firm. Offered materials include employee PDF files, internal project documents, access to the employee portal, data purportedly linked to Saudi Arabian government projects, and associated cookie sessions. Contact is via PM with escrow available.

A threat actor is selling internal documents and access obtained from the SharePoint portal of Dar (formerly Dar Al-Handasah), a global engineering and consultancy firm. Offered materials include employee PDF files, internal project documents, access to the employee portal, data purportedly linked to Saudi Arabian government projects, and associated cookie sessions. Contact is via PM with escrow available.

MITRE ATT&CK

Tactics, Techniques & Procedures

TA0001 Initial Access tactic

Defensive mapping

Mapped controls

The audit will verify each of these controls is in place and effective.

No controls mapped yet. Map controls →