Ransomware victim disclosure
← All victimsMax Shop
Claimed by Handala · listed 2 years ago
Status timeline
- ListedOct 8, 2024
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- Israel
- Sector
- Business Services
- Listed on leak site
- Oct 8, 2024
- Data size
- 1.5 TB
About the victim
AI dossier — public-source company profileMax Shop is a cloud-based store terminal and POS software platform used by over 9,000 retail locations across Israel. The company provides point-of-sale management and kiosk solutions for retail operations.
- Industry
- Point-of-Sale (POS) Software & Services
Attack summary
Severity: critical — Confirmed exfiltration of 1.5 TB of data affecting 9,000+ retail locations and 250,000+ customers; direct operational disruption via kiosk defacement; widespread PII exposure at scale across retail infrastructure.Handala claims to have exfiltrated 1.5 TB of data from Max Shop, defaced in-store kiosk monitor screens, and sent threatening text messages to over 250,000 customers. The attack targeted a widely-deployed retail infrastructure platform.
Data the group says was taken
AI dossier — extracted from the leak post- customer PII and contact information
- store transaction records
- business operational data
- kiosk system access credentials
What the group claims
Israel Max Shop Hacked Max Shop is one of the store terminal cloud software that is used in more than 9 thousand stores all over the occupied territories! Handala was able to dump more than 1.5 TB of data, deface the monitor screen of store kiosks, send threatening text messages to more than 250K Zionists…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

