Ransomware victim disclosure
← All victimsThe Saturday Files
Claimed by Handala · listed 9 months ago
Status timeline
- ListedNov 1, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Listed on leak site
- Nov 1, 2025
About the victim
AI dossier — public-source company profileThe Saturday Files appears to be a recurring leak series published by the Handala threat actor group, in which sets of named individuals or entities are exposed on a weekly basis. Based on the leak post, it does not appear to represent a single discrete company but rather an episodic disclosure campaign. Insufficient public information is available to characterise it further.
Attack summary
Severity: medium — Data is stated as published (disclosed status: data_published) and involves personal identification of named individuals, which carries PII exposure risk, but the scale, nature of data, and whether regulated data is involved cannot be confirmed from the available information.The Handala group claims to have identified and is publishing the identities of seven individuals or entities as part of a recurring Saturday disclosure series; the post implies doxing or exposure of personal/organisational data rather than a traditional ransomware encryption event.
Data the group says was taken
AI dossier — extracted from the leak post- Named individuals' identities
- Potentially associated personal or organisational records
What the group claims
Saturdays may be ordinary on your calendar, but for us, they mark a day of revelation, a day when we shake the foundations of your artificial calm with the tremor of truth. Today, once again, we bring seven more names from your ranks out of the darkness and into the light, seven faces from the…
Sources
Source
Indexed 9 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

