2026 Saudi GIP — 0cx00iq employee-system exfiltration claim (unverified)
Data compromised
Actor-claimed PII, military ranks/clearances, salaries, government emails, phone numbers, ID scans, passport scans, and active system credentials for 52,000+ officials/agents — unverified
Technical writeup
Unverified national-security leak claim — July 21, 2026. VECERTRadar reported threat actor 0cx00iq publicly announced alleged exfiltration from the General Intelligence Presidency (GIP) Employee Data Management System (Riasat Al-Istikhbarat Al-Amah), claiming control of files for more than 52,000 officials and agents including biographical PII, military assignment data, security clearance levels, salaries, contact details, scanned government IDs and passports, and active platform credentials, offered via private encrypted auction. No independent sample verification or Saudi government confirmation was available in English open sources at catalog time. BreachHistory indexes 52,000 per the actor file-count marketing claim, labeled unverified.
Root cause
Unverified underground claim by actor 0cx00iq alleging compromise of GIP Employee Data Management System and private auction of 52,000+ official files — Saudi authorities had not confirmed at indexing time