Ransomware victim disclosure
← All victims10 corpses
Claimed by Handala · listed 8 months ago
Status timeline
- ListedNov 22, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThe target does not appear to be a conventional company. Based on the leak post, Handala claims to be exposing 10 senior operatives allegedly linked to the Israeli aerospace sector or defence establishment. No corporate entity with verifiable registration or public presence has been identified.
- Industry
- Aerospace & Defence (Israeli Government/Military)
Attack summary
Severity: high — Confirmed publication of PII and identity data targeting named individuals in a defence/aerospace context constitutes a serious doxxing and potential physical safety risk, even though scale is limited to 10 persons and no corporate data breach is confirmed.Handala claims to have doxxed and published personal identifying information on 10 individuals described as senior operatives in Israel's aerospace sector, asserting this is a deliberate exposure of persons they accuse of concealed wrongdoing. No encryption or ransom demand is stated; the action is characterised as a targeted data publication.
Data the group says was taken
AI dossier — extracted from the leak post- Personal identities of named individuals
- Alleged operational affiliations
- Potentially sensitive personal/biographical data on 10 individuals
What the group claims
Today, Saturday, Handala RedWanted tears the mask off the Zionist regime’s aerospace elite. We are lifting the veil of secrecy from 10 senior operatives, exposing those who believed their crimes could remain hidden in the darkness. Your names are no longer whispers, we shout them into the world. This is not just an announcement. It…
Sources
Source
Indexed 8 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

