Ransomware Gang Claims Attack on Oman's Port Giant Asyad
A little-known ransomware group called Spirals has listed Asyad Group, Oman's state-owned logistics and ports operator, as a victim, the third such claim against a major Omani organisation in three months.
A ransomware group calling itself Spirals added Asyad Group, the sultanate's state-owned ports and logistics conglomerate, to its dark-web leak site on September 23, 2026, according to ransomware.live, the threat-intelligence platform that first flagged the posting. Asyad has not confirmed or denied an intrusion, and independent researchers say the claim should be treated with caution, but the listing lands Oman's strategic ports operator in the middle of a fast-growing pattern of ransomware claims against the country's largest companies.
📌 Key Takeaways
- Asyad Group, the Oman Investment Authority-owned operator of Salalah, Sohar and Duqm ports, was named on a ransomware leak site on September 23, 2026, per independent threat-tracking site Hendry Adrian.
- The group, known as Spirals, is a newly identified ransomware family; researchers say its claims should be independently verified before being treated as confirmed.
- Asyad has issued no public statement as of publication, and no data samples or screenshots accompanied the listing.
- This is the third major ransomware claim against an Omani organisation in roughly three months, following Arabia Falcon Insurance in July and OTE Group (Saad Bahwan Holding) in August, according to threat-intelligence firm BeamSec.
- Under Oman's amended Personal Data Protection Law, organisations must notify the Ministry of Transport, Communications and Information Technology (MTCIT) of a risky breach within 72 hours, with fines for serious violations now reaching RO 10,000 under Royal Decree 68/2026, per BeamSec's analysis of enforcement data.
🕵️ What Actually Happened
Ransomware.live, which monitors leak sites operated by extortion gangs, logged the Asyad Group entry at 15:53 UTC on September 23, describing Asyad as "Oman's global integrated logistics provider, ranked 4th on Forbes' 10 Biggest Logistics Companies in MENA list." The platform's own listing carries a caveat that Spirals is an "emerging group, so this claim should be treated with caution until independently verified," language echoed by the independent tracker Hendry Adrian, which noted that the post is "based on public claims made by the ransomware group 'Spirals'" and that accuracy cannot be confirmed from the outside.
Security researchers who have tracked Spirals since it first surfaced in mid-2026 describe it as a Rust-based ransomware family capable of compromising a victim's network, exfiltrating data and deploying encryption in under 24 hours by exploiting exposed internet-facing servers. Its only previously documented victim was an IT services firm in South Asia, meaning the group's track record is thin and its claims against a much larger target like Asyad have not yet been technically substantiated.
🚢 Why Asyad Is a High-Value Target
Asyad Group is not an ordinary company. It is wholly owned by the Oman Investment Authority, the sultanate's sovereign wealth fund, and controls the ports of Salalah, Sohar and Duqm along with Asyad Drydock, two free zones and Oman's rail and logistics assets, positioning the group as, in its own words, central to reinforcing "the Sultanate of Oman's position as a global logistics hub," as described in a recent Oman Observer report on the company's autonomous-freight and green-shipping partnerships. Its shipping subsidiary alone was valued at roughly $1.66 billion during a 2025 IPO, according to a report on the listing, underlining the scale of assets and operational data that any intrusion into the parent group could touch.
A confirmed breach at Asyad would be materially different from an attack on a mid-sized private firm: ports handle customs, trade and, increasingly, automated logistics systems, several of which Asyad has been actively expanding this year, including autonomous freight trials at Sohar and Salalah.
📈 A Pattern, Not an Isolated Claim
Asyad's listing is the third time in three months that a ransomware gang has named a major Omani organisation on a leak site:
- July 6, 2026: TheGentlemen claimed an attack on Arabia Falcon Insurance Company SAOG, a Muscat Stock Exchange-listed insurer. The company initially said it had detected and contained an unauthorised access attempt with no evidence of data compromise, but by July 19 it disclosed to the exchange that the claims appeared "credible" with a forensic investigation still ongoing, according to The Arabian Stories.
- August 7, 2026: Black Nevas, a ransomware family derived from the earlier Trigona strain, listed OTE Group, part of Saad Bahwan Holding, one of Oman's oldest and largest family conglomerates spanning automotive, electronics and industrial sectors. As of BeamSec's reporting, OTE Group had not publicly confirmed the claim.
- September 23, 2026: Spirals lists Asyad Group.
BeamSec's analysis, published on August 9, 2026, counted five significant cyber incidents affecting Oman between June and August alone and noted that the number of local cybersecurity firms has grown from 16 to 48 since 2020, a sign that both the threat and the response capacity are scaling up together. The firm's blunt conclusion, that "Oman is no longer under the radar" for international ransomware crews, reads as prescient given the Asyad listing that followed weeks later.
⚖️ What Oman's Data Law Requires Next
Whether or not Asyad confirms an intrusion, Oman's regulatory clock is already relevant. Since the transition period for the Personal Data Protection Law ended on February 5, 2026, data controllers operating in Oman must notify MTCIT within 72 hours of any breach that could pose a risk to individuals, and notify affected individuals directly if the risk is high. Royal Decree 68/2026 raised the maximum administrative fine for serious violations from RO 2,000 to RO 10,000, a fivefold increase intended to close exactly the kind of disclosure gap seen in the Arabia Falcon case, where 72 days passed between the initial ransomware claim and a credible confirmation to the market, according to BeamSec's review of MTCIT enforcement data, which recorded 22 breach notifications and 20 complaints logged by May 2026, with banking, healthcare and telecom the leading sectors reporting incidents.
Asyad has not made any public statement about the Spirals listing, and there is no indication yet of whether the group's claim will follow the same slow-confirmation path as Arabia Falcon's, fade away unverified like many extortion-site postings do, or trigger a formal MTCIT disclosure inside the legal window.
🇴🇲 Why This Matters for Oman
Vision 2040 leans heavily on Asyad and its ports as the backbone of Oman's ambition to become a regional logistics and trade hub, and on institutions like the Oman Investment Authority to modernise state assets through automation and cloud-connected systems, which is exactly the kind of digital footprint ransomware crews now hunt for. Three ransomware claims against major Omani employers inside three months, spanning insurance, industrial conglomerates and now state-owned logistics, suggest the country's rapid cloud and digitisation push, detailed in Oman's growing cybersecurity workforce and market build-out, is running in a race against an equally fast-growing set of threat actors. Regardless of whether the Spirals claim against Asyad is ultimately verified, it reinforces the case for treating the PDPL's 72-hour notification clock, and the RO 10,000 fines behind it, as a floor rather than a formality for organisations that sit at the centre of Oman's economy.
Tags
Related Articles
Back to School 2025: How Oman's EdTech Revolution is Transforming Every Classroom
As 700,000 students return to school this August, they're walking into AI-powered classrooms, VR labs, and personalized learning systems. Inside Oman's $400 million education technology transformation.
Oman Unveils National AI Strategy 2025-2030: A Blueprint for Digital Sovereignty
The Ministry of Transport, Communications & IT launches Oman's comprehensive AI strategy, targeting 30,000 AI jobs, $5B economic impact, and positioning the Sultanate as the Gulf's AI innovation hub by 2030.
Oman–India Tech Partnership: Driving Innovation Beyond Borders
Discover how growing technology ties between Oman and India are creating new opportunities, from joint AI projects to IT talent exchange and beyond.