LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › solidere Listed by devman Ransomware Group

HIGH severity claimedUnverified claimHow we verify

solidere Listed by devman Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 6, 2025
solidere Listed by devman Ransomware Group

Reported December 6, 2025.

HIGH
Severity
December 6, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Solidere has been listed by the devman ransomware group, which claims to have stolen internal files. The incident was disclosed on December 06, 2025; the exact date of the intrusion is not established.

Severity & verification
HIGH severity claimedUnverified claim
Exposes financial data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On December 6, 2025, the ransomware group devman listed Solidere on its leak site and claimed to have exfiltrated internal files from the Lebanese company. Public records show no confirmed count of affected individuals and no verified details on the volume or contents of the material beyond the group’s assertion of a ransomware operation. The incident occurs amid a sustained pattern of ransomware activity targeting organizations that manage critical infrastructure and urban development records, where data exfiltration followed by public listing has become a common pressure tactic.

What happened

The listing appeared on the date noted above. No independent confirmation of the breach has been published, and the organization has not released a statement detailing the timeline, attack vector, or scope. The reported summary indicates only that internal files were claimed to have been taken during a ransomware attack. Scale, duration of access, and whether encryption was also deployed remain undisclosed.

The group behind it: devman

Devman is a ransomware operation that follows the established pattern of encrypting systems, exfiltrating data, and publishing samples or directories on a dedicated leak site when ransom demands are not met. Such groups typically gain initial access through phishing, compromised remote-access tools, or unpatched vulnerabilities, then move laterally to locate and copy files before deploying encryption. Prior public reporting on the actor has documented similar listings against entities in multiple sectors, with the leak-site post serving as the primary signal that negotiations have stalled.

Who is solidere?

Solidere, formally the Société Libanaise de Développement et Reconstruction, is a joint-stock company established in 1994 and tasked with the reconstruction, development, and management of Beirut’s Central District. It holds responsibility for restoring historical buildings, attracting investment, and supporting tourism initiatives while exercising certain governmental powers over urban planning. As a private entity with public-sector functions, it maintains records related to property ownership, development contracts, financial arrangements, and regulatory approvals.

What data was at risk

The only data category named in connection with the listing is internal files exfiltrated during the claimed ransomware attack. No further breakdown of file types, personal identifiers, or specific datasets has been released. Organizations of this type routinely hold correspondence, contract documentation, financial ledgers, and planning records; however, the precise contents of any exfiltrated material remain unconfirmed.

What's at stake

Exposure of internal files could reveal details of ongoing development projects, contractual obligations, and communications involving residents, investors, and public authorities. For individuals whose information appears in those records, potential consequences include targeted fraud or unwanted contact. For the organization, the incident may complicate project timelines, increase scrutiny from regulators, and require extended forensic and remediation work.

If your data was in this claimed breach

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companysolidere security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See solidere’s full breach history →

More recent breaches

www.shimaogroup.com Listed by devman Ransomware GroupSeptember 15, 2025China Harbour Engineering Company Listed by devman Ransomware GroupJuly 5, 2025China Harbour Engeneiring Company Listed by devman Ransomware GroupApril 20, 2025Texas Construction Firm Listed by devman Ransomware GroupApril 6, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the solidere Listed by devman Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by devman — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram