SAFI

Introduction

An anonymous group has leaked a highly sensitive database containing Saudi government cash voucher records alongside Firebase full read-write access credentials on a dark web forum – raising serious national security and citizen privacy concerns across Saudi Arabia.

The leak was first identified on a deep web forum and was quickly flagged by cybersecurity researchers and threat intelligence teams actively monitoring underground criminal activity. This incident is particularly alarming because the leaked Firebase read-write credentials potentially allow anyone with them to actively read, modify, delete, and manipulate live government data in real time.

The anonymous group claims to have obtained over Saudi government records containing sensitive citizen and government financial information. If confirmed, this incident could represent one of the most serious government data exposure events in Saudi Arabia’s cybersecurity history in 2026.

This development raises urgent questions about the security posture of government digital infrastructure across Saudi Arabia and the broader Gulf region at a time when the Kingdom is rapidly expanding its digital economy under Vision 2030.

What Was Leaked?

The anonymous group publicly posted the alleged dataset on the deep web forum actively monitored by global threat intelligence platforms.

Dataset Overview

SA01
  • Region: Saudi Arabia
  • Category: Government Cash Voucher Database and Firebase Credentials

Incident Overview

FieldDetails
Date of LeakAugust 2026
Dump Number3 of approximately 25 planned dumps
Target RegionSaudi Arabia primarily
Leak TypeFreely available – no payment required
Total Files32 files
Compressed Size18MB compressed / 245MB+ decompressed
FormatJSON dumps + Excel spreadsheets + Images
SA02

Affected Organizations

OrganizationDetails
HSE-KSASaudi government health and safety application

Enterprise Tenants (14+ confirmed):

CompanyOriginRevenue / Scale
Saint-GobainFrance€47 billion revenue – building materials multinational
LIDLGermany€125 billion revenue – 12,000+ stores worldwide
SPARNetherlands13,000+ stores globally
Energya El-SewedyEgypt / KenyaPart of El Sewedy Electrical Group
SA03

Exposed Data Statistics

Data TypeVolume
Total Log Entries3,109 Elasticsearch logs
JWT Tokens659 unique tokens
Phone Numbers20 total
Plaintext Passwords12 employee credentials
QR Cash Vouchers119 Saudi government vouchers
Saudi Governorates Mapped17 governorates
Saudi Districts Mapped714 districts with MongoDB ObjectIDs
Wallet Entries197 entries
API Endpoints Exposed142 endpoints
Feature Flags67 flags
Deployment Configs16 tenant configurations
Storage Files Indexed970 files across 26 prefixes
Saudi Governorates Exposed (17 Total)
الرياض (Riyadh)
جدة (Jeddah)
مكة (Makkah)
المدينه المنوره (Madinah)
الطائف (Taif)
بريدة (Buraidah)
تبوك (Tabuk)
ابها (Abha)
خميس مشيط (Khamis Mushait)
حائل (Hail)
جازان (Jazan)
سكاكا (Sakaka)
عرعر (Arar)
نجران (Najran)
الباحة (Al Bahah)
ينبع الصناعية (Yanbu Industrial)

Password Breakdown

SA04
PasswordCountAffected Accounts
1234567 accountsadmin, Dina, Mohamed.ezzzzz, laylaaaa.elsheeeeikh, bouleees, arwwwa.Safwtttat, basma.khalleed
123456784 accountssalamaa, rahaf.ElAbbassy, marrwwa.samir, salaamma
shedeed1 accountmahmoud.shedeedddddd
Qara_MP@20241 accountMarketplace account
Total Unique12 passwords100% unique — all plaintext

Live Access Status (Confirmed August 5, 2026)

SA05
SystemStatusDetails
Firebase RTDB WriteLiveNo authentication required
Firebase RTDB ReadLiveFully Accessible
Firebase AuthLiveadmin@qara.net:1234567891234
Elasticsearch ReadLiveAPI key from Flutter source still active
Elasticsearch WritePartial403 error – read-only key
DigitalOcean SpacesLiveIndividual files publicly accessible
Caprover APILiveRate limited after 5 wrong passwords
Docker APILiveTCP handshake confirmed — HTTP times out

Who Is Behind This Leak?

The group responsible for this leak identifies itself as an anonymous collective operating on dark web forums. Anonymous groups that freely publish government data without ransom demands typically operate with one of the following motivations:

  • Ideological or political activism – publicly embarrassing government institutions.
  • Demonstrating cybersecurity vulnerabilities in critical national infrastructure.
  • Destabilizing public trust in government digital services.
  • Enabling secondary criminal exploitation by making data freely available to all.

What Makes the Firebase Full Read-Write Access Especially Dangerous?

The exposure of Firebase full read-write credentials is what makes this particular incident significantly more dangerous than a standard data dump.

Firebase is a widely used cloud-based application development platform owned by Google. Organizations use Firebase to store and manage live application data, user records, and backend infrastructure in real time.

Full read-write access means that anyone with these credentials:

  • Read all data stored within the connected Firebase database.
  • Write and modify existing records – including altering government financial data.
  • Delete critical records permanently without authorization.
  • Inject malicious data into live government application systems.
  • Access connected services that rely on the same Firebase infrastructure.

Who Is Affected?

This alleged breach directly impacts Internal deployment configurations, Android and iOS version control data, feature flags and application settings, tenant logos and brand assets, supplier relationship data, permission roles and access levels, build numbers and app configurations across Saudi Arabia.

The exposure of government cash voucher records is particularly sensitive because these programs typically serve citizens and residents who depend on government financial assistance programs.

Stolen government cash voucher data enables multiple forms of fraud, including:

  • Identity fraud using verified national ID information.
  • Financial benefit fraud fraudulently claiming government assistance using stolen citizen credentials.
  • Targeted phishing campaigns crafted using personal citizen details.
  • Social engineering attacks exploiting knowledge of government program enrollment.
  • Synthetic identity creation combining real and fabricated data for large-scale financial fraud.

Regulatory and National Security Implications

This alleged breach carries serious implications under Saudi Arabia’s national cybersecurity and data protection framework.

Affected organizations and authorities should be aware of:

  • Saudi Personal Data Protection Law (PDPL) – Saudi Arabia’s Personal Data Protection Law requires organizations to implement appropriate technical and organizational measures to protect personal data. A breach of this scale may trigger mandatory notification and investigation obligations.
  • National Cybersecurity Authority (NCA) Obligations – The Saudi National Cybersecurity Authority maintains strict cybersecurity frameworks for government entities. Organizations linked to this breach must immediately notify the NCA and cooperate fully with any investigation that follows.
  • Critical National Infrastructure Protection – Government financial systems are classified as critical national infrastructure under Saudi cybersecurity regulations. Any breach affecting these systems carries the highest level of regulatory scrutiny and national security response.

What Should Affected Citizens and Organizations Do Right Now?

If you believe your information may have been compromised in this breach.

Take these Immediate Steps:

  • Monitor your government financial accounts for any unauthorized activity or changes.
  • Contact the relevant government authority to report potential compromise of your records.
  • Be extremely cautious of unsolicited calls, messages, or emails referencing your government program enrollment.
  • Verify any communication claiming to be from government financial assistance programs through official channels only.
  • Report suspicious activity immediately to the Saudi National Cybersecurity Authority (NCA).
  • Avoid clicking links in any messages claiming to relate to your cash voucher or government benefit status.
  • Check your national ID for any signs of unauthorized use or fraudulent applications made in your name.

For Government Organizations:

  • Immediately revoke all exposed Firebase credentials and rotate access keys.
  • Audit all connected systems for signs of unauthorized access or data manipulation.
  • Engage forensic cybersecurity teams to assess the full scope of the breach.
  • Notify the NCA and relevant Saudi government cybersecurity authorities immediately.
  • Conduct a full security audit of Firebase configuration and access control policies.

What Do Cybersecurity Experts Say?

Cybersecurity professionals consistently stress that anonymous group data leak postings must be treated as serious threats – even before official government confirmation arrives. Researchers note that the combination of static data exposure and live Firebase read-write access makes this incident uniquely dangerous.

Most data breaches expose historical records. This incident potentially exposes live, actively managed government data to unrestricted criminal access. Organizations and government agencies in Saudi Arabia and the Gulf region that discover their data appearing on dark web forums should immediately:

  • Activate their national incident response protocols.
  • Engage the Saudi National Cybersecurity Authority.
  • Deploy forensic investigation teams without delay.
  • Issue transparent public communications to affected citizens.

Conclusion

The anonymous group leak of Saudi government cash voucher records and Firebase full read-write access credentials represents one of the most serious and multidimensional cybersecurity incidents to emerge from Saudi Arabia in 2026.

This is not simply a historical data dump. The exposure of live Firebase credentials means this incident carries the potential for ongoing, real-time damage to government digital infrastructure unless immediate containment action is taken.

At a time when Saudi Arabia’s Vision 2030 is driving rapid digital transformation across every sector of the national economy, incidents like this serve as a powerful reminder that cybersecurity investment must keep pace with digital ambition.

Every citizen, government organization, and private sector partner across Saudi Arabia and the Gulf region must treat this development as an urgent call to strengthen their cybersecurity posture – before the next breach occurs.

By Raghav Bansal

Raghav Bansal has been working as a cybersecurity researcher for the past 8 years. He possesses strong research skills and specializes in crafting information related to cybersecurity and information security, covering almost all topics in the field. With a keen eye for detail and a dedication to staying updated with the latest trends and threats,