Ransomware victim disclosure
← All victimsRedWanted Alert
Claimed by Handala · listed 10 months ago
Status timeline
- ListedOct 11, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Listed on leak site
- Oct 11, 2025
About the victim
AI dossier — public-source company profileRedWanted Alert appears to be a threat-intelligence or monitoring platform operated by the Handala hacktivist group, used to publicly expose individuals allegedly linked to Israeli government or military organizations. It is not a conventional company but rather an activist doxing/publishing platform. No independent public site or organizational details are available to verify its nature or scale.
Attack summary
Severity: high — The post describes confirmed publication of PII (names, photos, personal details) for identified individuals linked to sensitive Israeli organizations, constituting targeted doxing of real persons at potential physical risk; this meets the threshold of regulated/sensitive personal data disclosure at meaningful human-safety impact, though limited in scale (15 individuals) rather than mass breach.Handala claims to have doxed and published personal identifying information (names, faces, and personal details) of 15 individuals described as operatives within sensitive Israeli organizations, continuing a stated weekly disclosure campaign via their 'RedWanted' platform. No ransomware encryption or corporate data exfiltration is claimed; this is a targeted doxing operation.
Data the group says was taken
AI dossier — extracted from the leak post- Full names of targeted individuals
- Photographs / facial images
- Personal identifying details
The group's post references roughly 15 proof files.
What the group claims
As promised, every Saturday, we unveil a new chapter in exposing those complicit in the machinery of the Zionist regime. Through our Handala RedWanted platform, the truth comes to light, relentlessly and without exception. This week, 15 more individuals, key operatives embedded within sensitive Israeli organizations, are revealed. Their names, faces, and personal details are…
Sources
Source
Indexed 10 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

