Ransomware victim disclosure
← All victimsSaturday Spotlight
Claimed by Handala · listed 9 months ago
Status timeline
- ListedNov 8, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Listed on leak site
- Nov 8, 2025
About the victim
AI dossier — public-source company profileBased on the leak post, 'Saturday Spotlight' appears to be a recurring publication or disclosure series operated by the Handala group, not a company. It is a named segment in which the group claims to expose individuals they designate as targets. No verifiable company entity could be identified.
Attack summary
Severity: medium — The post claims publication of PII on named individuals (doxing), which constitutes data exposure of personal/sensitive information, but there is no identified corporate victim, no stated data volume, and no evidence of financial or medical records being involved.Handala claims to have doxed eight named individuals, describing them as 'Zionist criminals' and architects of unspecified operations. The disclosure appears to involve personal identifying information rather than a corporate network intrusion.
Data the group says was taken
AI dossier — extracted from the leak post- Personal identifying information (dox)
- Names of targeted individuals
- Alleged personal backgrounds or roles
What the group claims
As per our unbreakable tradition, every Saturday, the world awaits the chilling revelation from Handala RedWanted. This week, we pull back the mask on eight more Zionist criminals, names that strike terror in the hearts of those who believe they can commit atrocities from the shadows. Among our revelations are chief architects of the infamous…
Sources
Source
Indexed 9 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

