HackerFeeds
All ransomware incidents
zaraholding.com

Ransomware group payload hits Zara Investment Holding

MEDIUM
·Financial Services·JO·2026-08-13

Zara Investment Holding — a financial services target operating in JO has been listed by the payload ransomware group on 2026-08-13. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationZara Investment Holding
Threat Group
payload
SummaryZara Investment Holding (zaraholding.com) is a leading Jordanian investment group established in 1994. The company specializes in the tourism and hospitality sector, serving as the largest owner of five-star hotels and luxury resorts in key destinations across the country, including Amman, Petra, and the Dead Sea. Playing a vital role in Jordan's economy, the holding provides approximately 30% of the nation's total five-star hotel capacity.
Date of Breach2026-08-13
Discovery Date2026-08-13
RegionJO
Target Domainzaraholding.com
Business SectorFinancial Services
Severity
MEDIUM

Claim by payload

Zara Investment Holding (zaraholding.com) is a leading Jordanian investment group established in 1994. The company specializes in the tourism and hospitality sector, serving as the largest owner of five-star hotels and luxury resorts in key destinations across the country, including Amman, Petra, and the Dead Sea. Playing a vital role in Jordan's economy, the holding provides approximately 30% of the nation's total five-star hotel capacity.

Posted by the payload threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Victim website

zaraholding.com

Leak post (onion / Tor)

tor

http://payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd.onion/posts/d137bbd6-880d-4822-9520-80f60c037465

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.