// RESEARCH

The Largest Data Breach in Saudi History Is Still Live

Adnan Ahmad · · Security Research

⚠️ ACTIVE SECURITY INCIDENT

This article documents a live, unremediated vulnerability exposing Saudi national and business records at scale. The issue remains exploitable as of publication.

Right now, as you read this sentence, the personal data of every Saudi citizen and every registered business on a major Saudi platform is exposed to the open internet.

National IDs. Iqama numbers. Full legal names. Home addresses. Billing records. Invoices. The complete identity package for millions of people, accessible to anyone who knows where to look.

This has been the case for over ten months.

The company responsible knows. The regulators know. Nobody has lifted a finger.

What Is Exposed

An array of vulnerabilities in a major Saudi platform grant unrestricted access to the personal data of its entire user base, individuals and businesses alike. This is not a theoretical weakness or an edge case requiring sophisticated exploitation. It is a live, trivially exploitable data leak.

The exposed data includes:

  • National ID card numbers
  • Iqama (residency permit) numbers
  • Full legal names
  • Residential addresses
  • Business registration records
  • Billing histories and invoicing data

This is everything required to steal an identity, open fraudulent accounts, file false claims, or conduct targeted social engineering at a national scale. It is not a breach that happened and was contained. It is happening now, continuously, to everyone on the platform.

Status

Live and exploitable. No remediation observed.

Disclosure

Reported privately in September 2025. Ignored by all parties for 10+ months.

Ten Months of Silence

What follows is not speculation. It is a documented timeline of responsible disclosure met with institutional indifference.

September 2025

Vulnerability discovered. Reported directly to the company through proper channels.

October – December 2025

Follow-ups sent. The company responds, not with a fix, but with compliance paperwork. Forms. Frameworks. Process theater. The appearance of action without the substance of it. The vulnerability remains unchanged.

January – April 2026

A meeting is held. The issue is acknowledged verbally. Communications slow, then cease entirely. Emails go unanswered. Follow-ups ignored. The company has made a deliberate choice: silence over accountability. The vulnerability remains unchanged.

May – July 2026

Escalation to national regulators - SDAIA, NCA, and NIC. Formal notifications sent to each. Response from all three: nothing. Not a rejection. Not an acknowledgment. Absolute silence. The vulnerability remains unchanged.

July 29, 2026, Today

Publication. The vulnerability remains live. Fully exploitable. Unremediated.

ℹ️ On Responsible Disclosure

Every reasonable avenue was exhausted before publication. The company was given 10 months. Three national authorities were formally notified. At no point was this information shared publicly, sold, or disclosed to any third party. This article contains no technical details, no exploitation methods, and no information that would enable reproduction of the vulnerability.

The Company's Response: Theater

The company's initial engagement followed a pattern familiar to anyone who has reported vulnerabilities to organizations that treat security as a compliance checkbox rather than a technical obligation.

There were meetings. There were forms. There were references to internal frameworks and governance structures. There was every indication that the report had entered a process and every indication that the process was designed to produce paperwork rather than results.

Then the paperwork stopped too.

What replaced it was not a fix, not a timeline, not even a denial. It was silence. The kind of silence that is itself a decision, a calculated bet that the problem would go away if ignored long enough.

Ten months later, the problem has not gone away. The data is still leaking. The bet was wrong.

The Regulators Who Didn't Regulate

Three organizations exist in Saudi Arabia with explicit mandates to prevent exactly this scenario:

SDAIA - the Saudi Data & Artificial Intelligence Authority. Custodian of the Personal Data Protection Law. The body citizens are told will safeguard their information.

NCA - the National Cybersecurity Authority. Responsible for the Kingdom's cybersecurity posture. The entity meant to respond when critical infrastructure is compromised.

NIC - the National Information Center. The technical backbone of government digital services.

All three were formally notified. All three were provided with sufficient detail to understand the severity. All three were given time to respond.

None did.

This raises a question that deserves a public answer: What is the function of a data protection authority that does not respond to reports of data exposure? What is the purpose of a cybersecurity authority that ignores evidence of active compromise? These are not rhetorical questions. They are questions about whether the regulatory infrastructure of an entire nation is operational or decorative.

Billions have been invested in these institutions. Mandates have been written into law. Job titles have been created. Offices have been staffed. And when confronted with documented proof of the largest data exposure in Saudi history - the system produced nothing. Not action. Not even a reply.

Who This Affects

This is not an abstract infrastructure problem. Every record exposed belongs to a real person.

A father whose national ID is now available to any fraud ring that finds it. A business owner whose billing records reveal their clients, their revenue, their address. A resident whose Iqama number - the key to their legal existence in the Kingdom - sits in the open for anyone to harvest.

These people were never told. They have no idea their data is exposed. They cannot take protective action because no one has informed them there is anything to protect against. The company didn't notify them. The regulators didn't notify them. No one did.

They are exposed, and they don't know it.

A Question for Vision 2030

The Kingdom has staked its future on digital transformation. Smart cities. AI governance. A knowledge economy built on data. The ambition is real and the investment is enormous.

But ambition without fundamentals is architecture without a foundation. You cannot build NEOM on top of systems that leak national IDs. You cannot lead in AI governance while your data protection authority does not respond to breach reports. You cannot ask citizens to trust digital services while their personal data sits exposed for nearly a year with no remediation.

The gap between the vision and the reality is not a matter of capability. The Kingdom has the resources, the talent, and the infrastructure to be a global leader in data protection. The failure here is not technical. It is institutional. It is a failure of will, of accountability, of basic responsiveness.

Digital transformation requires digital trust. Trust requires that when something goes wrong, someone answers. Someone acts. Someone is accountable.

Today, no one is accountable. That is the story.

A Note on Disclosure

This article names no company. It discloses no technical details. It provides no information that would enable exploitation. It is a factual account of a systemic failure, published in the public interest after every private avenue was exhausted.

The data is still leaking. The clock is running.