Ransomware victim disclosure
← All victimsSaturday Reckoning
Claimed by Handala · listed 10 months ago
Status timeline
- ListedOct 18, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Listed on leak site
- Oct 18, 2025
About the victim
AI dossier — public-source company profileThe leak post does not identify a specific company; 'Saturday Reckoning' appears to be the name of a recurring disclosure series run by the hacktivist group Handala, not a corporate victim. The post describes a weekly campaign targeting Israeli government or affiliated entities, framed as political activism.
Attack summary
Severity: medium — Data is claimed to have been published (disclosed status: data_published) and involves personal identities, suggesting PII exposure; however, no specific victim organisation, data volume, or verifiable proof count is provided, preventing a higher severity classification.Handala claims to be releasing identities as part of a recurring 'Saturday' disclosure series targeting entities associated with the Israeli government. The post indicates data publication (exfiltration/exposure), though no specific organisation, ransom, or data size is stated.
Data the group says was taken
AI dossier — extracted from the leak post- Personal identities (claimed)
What the group claims
As part of our relentless campaign of truth and justice, every Saturday we unveil another layer of the Zionist regime’s hidden machinery. Today, we continue this tradition, one that now haunts the corridors of power in Tel Aviv and beyond. This week’s revelation is unprecedented. Today, for the first time, we are releasing the identities…
Sources
Source
Indexed 10 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

