Final Report of Cyber Incident
On 16th April 2026, a security incident affecting the IT infrastructure of all BELFOR entities in Asia was identified.
The group responsible for the security incident could be identified as the INC Ransom group announced the theft on its dark web blog, but there is no confirmed evidence that the exfiltrated data has been disseminated or misused.
The leaked dataset contains personally identifiable information (PII) and business-related information like damage documentation, site photographs, etc.
As soon as the compromise was confirmed, the affected systems were permanently shut down on the same day of the discovery and will not be returned to service.
The entire IT environment was rebuilt from scratch and will not reuse any compromised components. The new environment will be managed by BELFOR Europe GmbH, the parent company of BELFOR (Asia) Pte Ltd, which is ISO/IEC 27001 certified.
Business operations have continued, supported by the rapid restoration of key operational systems for ongoing and new projects.
BELFOR employees in Asia remain reachable via their existing email addresses.
BELFOR was supported by external cybersecurity experts as well as external legal advisers on data protection and regulatory reporting.
June 5, 2026