LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › World Cup 2034 Listed by Wallstreet Ransomware Group

HIGH severityUnverified claimHow we verify

World Cup 2034 Listed by Wallstreet Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 3, 2026
World Cup 2034 Listed by Wallstreet Ransomware Group

Reported October 3, 2026.

HIGH
Severity
October 3, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

World Cup 2034 was listed by the Wallstreet ransomware group on October 03, 2026. An undisclosed number of people may be affected; anyone who shared personal data with the organisation should review their accounts and monitor for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On October 03, 2026, the ransomware group known as Wallstreet listed an entry tied to World Cup 2034 on its leak site. The listing asserts that the group compromised systems connected to the main contractor building Jeddah Central Stadium for the FIFA World Cup 2034. Public detail beyond that claim is limited, and neither the named organisations nor any regulator has publicly confirmed the incident as of writing.

Because the material comes only from an extortion-site posting, it remains an unverified accusation. Readers should treat scale, file counts, and data categories described by the group as claims, not as an established inventory of what—if anything—left any network.

What is being claimed

According to the Wallstreet listing, the group says it compromised the network of the China Railway Construction Corporation Saudi Branch / Sama Construction consortium, described in the post as the main contractor building the Jeddah Central Stadium for the FIFA World Cup 2034. The group claims roughly 17 TB and about 1.5 million files were exfiltrated. The listing’s own description of material allegedly taken includes main contract documents, interim payment certificates, and claims against the owner (named in the post as Jeddah Central Development Company, PIF); active dispute and suspension claim records; personal data said to cover 150,000 or more employees, including Saudi employees; IFC design documentation for the stadium; and supplier and subcontractor commercial data such as bid tabulations.

The number of people actually affected is unknown in any independent sense. Timing of any intrusion, initial access method, and whether any files were published beyond the listing itself are not established in public reporting tied to confirmation by the organisations named. World Cup 2034-related entities have not publicly confirmed the incident as of writing. The listing is therefore best read as an extortion narrative: what Wallstreet asserts, not what has been independently verified.

Who is Wallstreet?

Wallstreet is known publicly as a ransomware and data-extortion actor that operates in the familiar double-extortion pattern used by many such crews: encrypt or lock systems where possible, copy data, then pressure victims by threatening or staging leaks on a dedicated site. Groups in this category typically post victim names, countdown-style pressure, and selective file samples to increase leverage. Their leak-site entries are marketing and coercion tools; they are not audited breach reports.

Well-documented public reporting on actors of this type emphasises that claimed volumes, file lists, and victim impact are chosen to maximise urgency and payment pressure. Nothing in that general pattern proves that every named file type in a given post was taken, that counts are accurate, or that the named organisation’s full environment was reached. For this incident, only the group’s own listing text is available in the record summarised here; no separate confirmation is included in those facts.

Who is World Cup 2034?

World Cup 2034 refers to the FIFA men’s World Cup scheduled for 2034, with hosting arrangements that place major stadium and infrastructure work in Saudi Arabia, including high-profile venues such as projects associated with Jeddah. Delivery of such events depends on large construction consortia, owners, public investment vehicles, designers, and long chains of suppliers and subcontractors. The Wallstreet post specifically names a contractor consortium and stadium-related documentation rather than FIFA itself as the sole focus of the claim.

Organisations in this sector typically handle commercially sensitive contracts, payment and claims records, design packages, workforce administration, and vendor commercial data. A leak-site listing that ties a major stadium contractor to a global sporting event is consequential because of the visibility of the tournament, the volume of people and firms that touch a mega-project, and the sensitivity of both personal workforce data and competitive commercial material—if any of what is claimed were accurate. A listing alone does not establish that those systems were in fact breached.

What data was at risk

The facts do not provide an independently verified inventory of exposed data types. Wallstreet’s listing claims categories such as main contract documents, interim payment certificates, claims against the owner, dispute and suspension records, personal data of a large employee population, IFC stadium design documentation, and supplier and subcontractor commercial data including bid tabulations. Those descriptions are the group’s assertions.

If files of the kinds construction consortia and stadium projects ordinarily hold were copied, organisations in this sector typically retain identity and employment records, contact details, payroll-related information, contract and payment files, design and engineering packages, and commercially sensitive bid and subcontract material. Exact contents in this case remain unconfirmed. No public confirmation establishes which, if any, of the claimed categories left any network or whether the stated volume of about 17 TB and 1.5 million files is accurate.

The real-world impact

Impact must be framed conditionally. If personal employee data were involved, affected individuals could face phishing, social engineering, identity misuse, or unwanted contact that references employment or project details. If commercial contract, claims, dispute, or bid material were involved, counterparties could see competitive or negotiation-sensitive information used in fraud attempts or unfair commercial pressure. If design documentation were involved, project parties might need to assess integrity and confidentiality of technical packages—again, only if such material was actually taken.

For the organisations named in the claim, a public extortion listing can create reputational strain, contractual questions among owners and subcontractors, and operational distraction even when the underlying allegation is disputed or unproven. None of that converts the listing into confirmed theft. What a leak-site post establishes is that a named group chose to associate these entities with a pressure campaign on a given date; it does not by itself prove negligence, successful exfiltration, or the completeness of the file list advertised.

If your data was involved

If you believe you may be connected to the contractor workforce, suppliers, or project parties named in the claim, practical steps stay precautionary rather than assuming your information is already public:

Until the organisations involved publish a confirmed account, the responsible stance is caution without treating Wallstreet’s file list or headcount claims as settled fact. Public detail remains limited to the group’s October 03, 2026 listing and the unverified narrative it contains.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyWorld Cup 2034 security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See World Cup 2034’s full breach history →

More recent breaches

St. Francis Healthcare Systems of Hawaii Listed by Wallstreet Ransomware GroupOctober 3, 2026Tronex A/S Listed by Wallstreet Ransomware GroupOctober 2, 2026Gibson Area Hospital & Health Services Listed by Wallstreet Ransomware GroupSeptember 29, 2026Gtfm Listed by Wallstreet Ransomware GroupSeptember 25, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the World Cup 2034 Listed by Wallstreet Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by wallstreet — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram