Ransomware victim disclosure
← All victimsElad municipality
Claimed by Handala · listed 2 years ago
Status timeline
- ListedNov 3, 2024
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- Israel
- Sector
- Government
- Listed on leak site
- Nov 3, 2024
- Data size
- 3 TB
About the victim
AI dossier — public-source company profileElad is a municipality in Israel responsible for local government administration, public services, and civic records management for its jurisdiction.
- Industry
- Government / Local Administration
Attack summary
Severity: critical — Confirmed exfiltration of government data at scale (3 TB) including PII, operational disruption to municipal services, and breach of air-gapped infrastructure demonstrates severe compromise of sensitive civic records.Handala claims to have compromised Elad Municipality's air-gapped network, encrypting main file and database servers and employee systems, and exfiltrating approximately 3 TB of confidential municipal data including the primary database, employee identity records, geographic coordinates, and contracts.
Data the group says was taken
AI dossier — extracted from the leak post- municipal database
- employee identity records
- geographic coordinates
- contracts
- confidential files
What the group claims
Handala hacked the airgap network of Elad Municipality! The municipality is closed today, don’t visit! All main file and database servers as well as the systems of all employees were wiped! More than 3TB of confidential data, including the main database of the municipality, all files, identity specifications and geographic coordinates, contracts, etc., were dumped!…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

