Ransomware victim disclosure
← All victimsIran Internation
listed as Iran Internation WhatsApp and Internal Access · Claimed by Handala · listed 1 year ago
Status timeline
- ListedJul 9, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- Iran
- Sector
- Telecommunication
- Listed on leak site
- Jul 9, 2025
About the victim
AI dossier — public-source company profileIran Internation is a telecommunications company operating in Iran. Limited public information is available; the victim name suggests internal communication infrastructure and messaging services were targeted.
- Industry
- Telecommunication
Attack summary
Severity: high — Long-term (31-month) internal access to a telecommunications company combined with claimed exfiltration of internal communications and WhatsApp data represents significant operational compromise and potential exposure of sensitive business/user data. The duration and depth of access elevates severity despite no formal proof count visible in truncated post.Handala claims extended access to Iran Internation's internal systems over 31 months, compromising WhatsApp and internal communication infrastructure. The group implies exfiltration of sensitive internal data alongside system compromise.
Data the group says was taken
AI dossier — extracted from the leak post- WhatsApp data
- Internal communications
- System access credentials
What the group claims
You only saw the tip of the iceberg… When you first assumed that only your Telegram had been compromised, we smiled , a bitter smile. Because while you drifted in illusions of safety, we had already made a home beneath your skin. 31 months. Not a night. Not a season. For over two and a…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

