Ransomware victim disclosure
← All victimsGlobaLinks
Claimed by Handala · listed 1 year ago
Status timeline
- ListedJul 1, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Jul 1, 2025
About the victim
AI dossier — public-source company profileGlobaLinks is described by the threat actor as a major player in concrete and construction-related business operations. No public website or verifiable corporate information is currently available.
- Industry
- Concrete & Construction Materials
Attack summary
Severity: high — Confirmed data publication with exfiltration of multiple sensitive document types including resident records (potential PII), investor files, and operational blueprints/contracts. Scale and specific proof artifacts not quantified in available post excerpt.Handala claims to have breached GlobaLinks and exfiltrated blueprints, contracts, internal emails, private investor files, and resident records. The group has published data.
Data the group says was taken
AI dossier — extracted from the leak post- blueprints
- contracts
- internal emails
- investor files
- resident records
What the group claims
GlobaLinks Hacked This is Handala. I do not forget. I do not forgive. And I do not look away. Today, GlobaLinks, a giant in concrete and quiet deals, has been breached. Its foundations have cracked , not under an earthquake, but under truth. Blueprints. Contracts. Internal emails. Private investor files. Resident records. All of it…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

