Hackers exfiltrate 1.5 million files from Saudi World Cup stadium contractor
A cyberattack on the China Railway Railway Construction Corporation/Sama Construction consortium stole over 1.5 million files, including stadium designs and employee data.
Hackers accessed the network of the China Railway Railway Construction Corporation/Sama Construction consortium, extracting more than 1.5 million files amounting to about 17 terabytes. The data set includes contracts, payment details, design plans for the Jeddah Central Stadium—a key venue for the 2034 FIFA World Cup—and personal records of roughly 150,000 employees. UAE cybersecurity firm Hackmanac attributed the attack to the WallStreet ransomware gang, noting its use of double-extortion to force victims into compliance.
SOCRadar, another security analyst, said WallStreet has claimed responsibility for at least 32 attacks worldwide, operating in the United States and Ecuador among other regions. The consortium serves as the main contractor for the stadium, while Saudi authorities and the construction company have not issued comments. The breach highlights vulnerabilities in critical infrastructure linked to the upcoming World Cup.
Why it matters
The leak exposes sensitive construction and personal data tied to a major World Cup project, raising security concerns for the event and its workers.
In this story
