Ransomware victim disclosure
← All victimsIslamic Republic of Iran Navy (IRIN) — Senior Officer Roster
listed as No Place to Hide: Senior Navy Officers’ Identities Now Public · Claimed by Handala · listed 3 months ago
Status timeline
- Listed
Mar 14, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileThe target appears to be the naval forces of a nation-state described as an 'oppressive regime' by Handala Hack, with specific reference to the Strait of Hormuz — strongly indicative of the Islamic Republic of Iran Navy (IRIN) or a regional adversary navy operating near the Strait of Hormuz. The leak claims to expose the personal identities of senior naval officers. No corporate or civilian entity is involved.
- Industry
- Government / Military — Naval Forces
Attack summary
Severity: critical — Disclosed status is 'data_published', meaning PII of senior military/government personnel has been publicly released. Exposure of named senior naval officers constitutes a serious national-security-level data breach involving regulated and sensitive government/defence personal information, posing direct physical risk to identified individuals.Handala Hack claims to have exfiltrated and publicly disclosed the identities and personal details of senior naval officers, framing the release as a warning tied to the geopolitical context of the Strait of Hormuz. The post indicates data has already been published ('data_published') with no ransom demand.
Data the group says was taken
AI dossier — extracted from the leak post- Senior naval officer identities
- Personally identifiable information (PII) of military personnel
- Potential service records or rank information
What the group claims
In unwavering obedience to the command to keep the Strait of Hormuz closed, we, the warriors of Handala Hack, deliver this warning to the naval forces of the oppressive regime: While you tremble in fear, unable to even approach our powerful waters, know that none of your secrets remain hidden anymore. For years, you hid…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
