Ransomware victim disclosure
← All victimsJerusalem Water Supply Facilities
Claimed by Handala · listed 3 months ago
Status timeline
- Listed
Mar 7, 2026
- Data leaked
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- Israel
- Sector
- Public Sector
- Listed on leak site
- Mar 7, 2026
- Data size
- 423 GB
About the victim
AI dossier — public-source company profileJerusalem Water Supply Facilities refers to the municipal water infrastructure serving Jerusalem, Israel. The entity is responsible for the supply, treatment, and distribution of water to residents and institutions across the city. No public website was available to confirm the precise operating authority or organisational structure.
- Industry
- Water Supply & Utilities
- Address
- Jerusalem, Israel
Attack summary
Severity: critical — Claimed attack targets critical public water infrastructure serving a major city, with 423 GB of sensitive/classified data exfiltrated and reported complete operational disruption — combining large-scale data exposure with critical infrastructure impact affecting public safety.Handala claims to have exfiltrated 423 GB of classified and sensitive data from Jerusalem's water infrastructure systems and to have completely disrupted ('crippled') the core operational infrastructure, indicating both exfiltration and destructive/disruptive impact.
Data the group says was taken
AI dossier — extracted from the leak post- Classified operational infrastructure data
- Water system configuration files
- Sensitive internal documents
What the group claims
In response to the blatant aggression against the Qeshm desalination plant, Handala Hack has executed an unprecedented and sophisticated cyber operation, targeting the water infrastructure of Jerusalem. In this assault, 423 gigabytes of highly classified and sensitive data were exfiltrated, and the core infrastructure was completely crippled. This was not merely a cyberattack, it was…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
