RANSOMWARE VICTIMFINANCIAL SERVICES

arc-reins.com + fidelityunited.ae UPDATE-FULL DATA DUMP

fidelityunited.ae
stormous📍 UAE (AE)📅 May 11, 2026
8
same group

Attack Intelligence

arc-reins.com + fidelityunited.ae UPDATE-FULL DATA DUMP was compromised in a ransomware attack attributed to stormous in May 2026. The organization, operating in the Financial Services sector in UAE, was added to the group's data leak site as part of an extortion campaign.

stormous operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

We have gained full control over 700 GB of data, which includes: meticulous compliance audit data, complete Bank details for ARC, legal licenses, tax documents, and official contracts, as well as KYC and KYC TOBA files for all partners.Additionally, personal data for all employees has been extracted, including passports, ID cards, emails, career details, personal documents, and contracts for managers and internal communications. The breach also covers the marine insurance archive with all its deals in the Middle East, property insurance, civil liability, and risk insurance, in addition to monthly and annual quality control reports and collective agreements with major international partners.We have full control over administrative data, business travel logs, passwords, and DC client lists, along with all internal correspondence, digital identities, and official company signatures. The data also includes a list of major clients and thousands of personal information records for Fidelity and ARC brokers, including their full personal details. All of this and more, totaling 600 GB of secrets.

Other Victims — stormous (8)

Quick Facts

CountryUAE (AE)
SectorFinancial Services
Attack DateMay 11, 2026
Domainfidelityunited.ae
Intel Sourceransomware.live

Threat Group

stormous
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.