Trojan Construction & Holding Group
bd_7866a55923c07605 · schema v1 · pii pii-v1
Full breach record for Trojan Construction & Holding Group →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Blacknevas on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Over 3 terabytes of project and financial reporting data for 2024–2025. https://gofile.io/d/4Uf42V For an example of what data we have and sell at a high price, please write to us if you are interested: Qualitydatarecovery@mail.comTrojan Holding is an Abu Dhabi-based construction company founded in 2012. It is a diversified group of companies engaged in a wide range of construction projects, including high-rise buildings, hospitals, schools, resorts, and residential complexes. The company is a leader in the construction sector in the UAE and the region, with a large project portfolio and is a subsidiary of Alpha Dhabi Holding.The Group currently has eight subsidiaries:Trojan General Contracting,National Projects & Construction,Royal Advance Electromechanical Works,Reem Emirates Aluminum,Hi-Tech Concrete Products,Al Maha Modular Industries,Phoenix Timber Factory andReem Readymix.
Source provenance
- Source URL
- https://www.ransomware.live/id/VHJvamFuIENvbnN0cnVjdGlvbiAmIEhvbGRpbmcgR3JvdXBAYmxhY2tuZXZhcw==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 21, 2025
- Raw hash
- ad41d206c638cb52c33409d023c12a87e887714d11935b662a6ec6c0a14d200a
Reporting entity
- Name
- blacknevas
Victim entity
- Name
- Trojan Construction & Holding Groupnorm: trojan construction
- Domain
- trojan.ae
- Industry
- Constructionllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· blacknevas
- Threat actor
- BlacknevasExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.