Table of Contents
Introduction
An anonymous group has leaked a highly sensitive database containing Saudi government cash voucher records alongside Firebase full read-write access credentials on a dark web forum – raising serious national security and citizen privacy concerns across Saudi Arabia.
The leak was first identified on a deep web forum and was quickly flagged by cybersecurity researchers and threat intelligence teams actively monitoring underground criminal activity. This incident is particularly alarming because the leaked Firebase read-write credentials potentially allow anyone with them to actively read, modify, delete, and manipulate live government data in real time.
The anonymous group claims to have obtained over Saudi government records containing sensitive citizen and government financial information. If confirmed, this incident could represent one of the most serious government data exposure events in Saudi Arabia’s cybersecurity history in 2026.
This development raises urgent questions about the security posture of government digital infrastructure across Saudi Arabia and the broader Gulf region at a time when the Kingdom is rapidly expanding its digital economy under Vision 2030.
What Was Leaked?
The anonymous group publicly posted the alleged dataset on the deep web forum actively monitored by global threat intelligence platforms.
Dataset Overview

- Region: Saudi Arabia
- Category: Government Cash Voucher Database and Firebase Credentials
Incident Overview
| Field | Details |
| Date of Leak | August 2026 |
| Dump Number | 3 of approximately 25 planned dumps |
| Target Region | Saudi Arabia primarily |
| Leak Type | Freely available – no payment required |
| Total Files | 32 files |
| Compressed Size | 18MB compressed / 245MB+ decompressed |
| Format | JSON dumps + Excel spreadsheets + Images |

Affected Organizations
| Organization | Details |
| HSE-KSA | Saudi government health and safety application |
Enterprise Tenants (14+ confirmed):
| Company | Origin | Revenue / Scale |
| Saint-Gobain | France | €47 billion revenue – building materials multinational |
| LIDL | Germany | €125 billion revenue – 12,000+ stores worldwide |
| SPAR | Netherlands | 13,000+ stores globally |
| Energya El-Sewedy | Egypt / Kenya | Part of El Sewedy Electrical Group |

Exposed Data Statistics
| Data Type | Volume |
| Total Log Entries | 3,109 Elasticsearch logs |
| JWT Tokens | 659 unique tokens |
| Phone Numbers | 20 total |
| Plaintext Passwords | 12 employee credentials |
| QR Cash Vouchers | 119 Saudi government vouchers |
| Saudi Governorates Mapped | 17 governorates |
| Saudi Districts Mapped | 714 districts with MongoDB ObjectIDs |
| Wallet Entries | 197 entries |
| API Endpoints Exposed | 142 endpoints |
| Feature Flags | 67 flags |
| Deployment Configs | 16 tenant configurations |
| Storage Files Indexed | 970 files across 26 prefixes |
| Saudi Governorates Exposed (17 Total) |
| الرياض (Riyadh) |
| جدة (Jeddah) |
| مكة (Makkah) |
| المدينه المنوره (Madinah) |
| الطائف (Taif) |
| بريدة (Buraidah) |
| تبوك (Tabuk) |
| ابها (Abha) |
| خميس مشيط (Khamis Mushait) |
| حائل (Hail) |
| جازان (Jazan) |
| سكاكا (Sakaka) |
| عرعر (Arar) |
| نجران (Najran) |
| الباحة (Al Bahah) |
| ينبع الصناعية (Yanbu Industrial) |
Password Breakdown

| Password | Count | Affected Accounts |
| 123456 | 7 accounts | admin, Dina, Mohamed.ezzzzz, laylaaaa.elsheeeeikh, bouleees, arwwwa.Safwtttat, basma.khalleed |
| 12345678 | 4 accounts | salamaa, rahaf.ElAbbassy, marrwwa.samir, salaamma |
| shedeed | 1 account | mahmoud.shedeedddddd |
| Qara_MP@2024 | 1 account | Marketplace account |
| Total Unique | 12 passwords | 100% unique — all plaintext |
Live Access Status (Confirmed August 5, 2026)

| System | Status | Details |
| Firebase RTDB Write | Live | No authentication required |
| Firebase RTDB Read | Live | Fully Accessible |
| Firebase Auth | Live | admin@qara.net:1234567891234 |
| Elasticsearch Read | Live | API key from Flutter source still active |
| Elasticsearch Write | Partial | 403 error – read-only key |
| DigitalOcean Spaces | Live | Individual files publicly accessible |
| Caprover API | Live | Rate limited after 5 wrong passwords |
| Docker API | Live | TCP handshake confirmed — HTTP times out |
Who Is Behind This Leak?
The group responsible for this leak identifies itself as an anonymous collective operating on dark web forums. Anonymous groups that freely publish government data without ransom demands typically operate with one of the following motivations:
- Ideological or political activism – publicly embarrassing government institutions.
- Demonstrating cybersecurity vulnerabilities in critical national infrastructure.
- Destabilizing public trust in government digital services.
- Enabling secondary criminal exploitation by making data freely available to all.
What Makes the Firebase Full Read-Write Access Especially Dangerous?
The exposure of Firebase full read-write credentials is what makes this particular incident significantly more dangerous than a standard data dump.
Firebase is a widely used cloud-based application development platform owned by Google. Organizations use Firebase to store and manage live application data, user records, and backend infrastructure in real time.
Full read-write access means that anyone with these credentials:
- Read all data stored within the connected Firebase database.
- Write and modify existing records – including altering government financial data.
- Delete critical records permanently without authorization.
- Inject malicious data into live government application systems.
- Access connected services that rely on the same Firebase infrastructure.
Who Is Affected?
This alleged breach directly impacts Internal deployment configurations, Android and iOS version control data, feature flags and application settings, tenant logos and brand assets, supplier relationship data, permission roles and access levels, build numbers and app configurations across Saudi Arabia.
The exposure of government cash voucher records is particularly sensitive because these programs typically serve citizens and residents who depend on government financial assistance programs.
Stolen government cash voucher data enables multiple forms of fraud, including:
- Identity fraud using verified national ID information.
- Financial benefit fraud fraudulently claiming government assistance using stolen citizen credentials.
- Targeted phishing campaigns crafted using personal citizen details.
- Social engineering attacks exploiting knowledge of government program enrollment.
- Synthetic identity creation combining real and fabricated data for large-scale financial fraud.
Regulatory and National Security Implications
This alleged breach carries serious implications under Saudi Arabia’s national cybersecurity and data protection framework.
Affected organizations and authorities should be aware of:
- Saudi Personal Data Protection Law (PDPL) – Saudi Arabia’s Personal Data Protection Law requires organizations to implement appropriate technical and organizational measures to protect personal data. A breach of this scale may trigger mandatory notification and investigation obligations.
- National Cybersecurity Authority (NCA) Obligations – The Saudi National Cybersecurity Authority maintains strict cybersecurity frameworks for government entities. Organizations linked to this breach must immediately notify the NCA and cooperate fully with any investigation that follows.
- Critical National Infrastructure Protection – Government financial systems are classified as critical national infrastructure under Saudi cybersecurity regulations. Any breach affecting these systems carries the highest level of regulatory scrutiny and national security response.
What Should Affected Citizens and Organizations Do Right Now?
If you believe your information may have been compromised in this breach.
Take these Immediate Steps:
- Monitor your government financial accounts for any unauthorized activity or changes.
- Contact the relevant government authority to report potential compromise of your records.
- Be extremely cautious of unsolicited calls, messages, or emails referencing your government program enrollment.
- Verify any communication claiming to be from government financial assistance programs through official channels only.
- Report suspicious activity immediately to the Saudi National Cybersecurity Authority (NCA).
- Avoid clicking links in any messages claiming to relate to your cash voucher or government benefit status.
- Check your national ID for any signs of unauthorized use or fraudulent applications made in your name.
For Government Organizations:
- Immediately revoke all exposed Firebase credentials and rotate access keys.
- Audit all connected systems for signs of unauthorized access or data manipulation.
- Engage forensic cybersecurity teams to assess the full scope of the breach.
- Notify the NCA and relevant Saudi government cybersecurity authorities immediately.
- Conduct a full security audit of Firebase configuration and access control policies.
What Do Cybersecurity Experts Say?
Cybersecurity professionals consistently stress that anonymous group data leak postings must be treated as serious threats – even before official government confirmation arrives. Researchers note that the combination of static data exposure and live Firebase read-write access makes this incident uniquely dangerous.
Most data breaches expose historical records. This incident potentially exposes live, actively managed government data to unrestricted criminal access. Organizations and government agencies in Saudi Arabia and the Gulf region that discover their data appearing on dark web forums should immediately:
- Activate their national incident response protocols.
- Engage the Saudi National Cybersecurity Authority.
- Deploy forensic investigation teams without delay.
- Issue transparent public communications to affected citizens.
Conclusion
The anonymous group leak of Saudi government cash voucher records and Firebase full read-write access credentials represents one of the most serious and multidimensional cybersecurity incidents to emerge from Saudi Arabia in 2026.
This is not simply a historical data dump. The exposure of live Firebase credentials means this incident carries the potential for ongoing, real-time damage to government digital infrastructure unless immediate containment action is taken.
At a time when Saudi Arabia’s Vision 2030 is driving rapid digital transformation across every sector of the national economy, incidents like this serve as a powerful reminder that cybersecurity investment must keep pace with digital ambition.
Every citizen, government organization, and private sector partner across Saudi Arabia and the Gulf region must treat this development as an urgent call to strengthen their cybersecurity posture – before the next breach occurs.