Ransomware group payload hits Zara Investment Holding
Zara Investment Holding — a financial services target operating in JO has been listed by the payload ransomware group on 2026-08-13. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Zara Investment Holding |
|---|---|
| Threat Group | payload |
| Summary | Zara Investment Holding (zaraholding.com) is a leading Jordanian investment group established in 1994. The company specializes in the tourism and hospitality sector, serving as the largest owner of five-star hotels and luxury resorts in key destinations across the country, including Amman, Petra, and the Dead Sea. Playing a vital role in Jordan's economy, the holding provides approximately 30% of the nation's total five-star hotel capacity. |
| Date of Breach | 2026-08-13 |
| Discovery Date | 2026-08-13 |
| Region | JO |
| Target Domain | zaraholding.com |
| Business Sector | Financial Services |
| Severity | MEDIUM |
Claim by payload
Zara Investment Holding (zaraholding.com) is a leading Jordanian investment group established in 1994. The company specializes in the tourism and hospitality sector, serving as the largest owner of five-star hotels and luxury resorts in key destinations across the country, including Amman, Petra, and the Dead Sea. Playing a vital role in Jordan's economy, the holding provides approximately 30% of the nation's total five-star hotel capacity.
Posted by the payload threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
zaraholding.com
Leak post (onion / Tor)
http://payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd.onion/posts/d137bbd6-880d-4822-9520-80f60c037465
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

