Ransomware victim disclosure
← All victimsVerifone
Claimed by Handala · listed 3 months ago
Status timeline
- Listed
Mar 11, 2026
- Data leaked
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Mar 11, 2026
About the victim
AI dossier — public-source company profileVerifone is a global leader in payment technology, providing point-of-sale terminals, payment software, and transaction processing solutions to merchants, financial institutions, and governments worldwide. The company operates across numerous countries, supporting billions of payment transactions annually. Verifone serves industries including retail, hospitality, healthcare, and fuel/convenience.
- Industry
- Payment Technology & Point-of-Sale Solutions
- Address
- 88 West Plumeria Drive, San Jose, CA 95134, United States
- Employees
- 10000+
- Founded
- 1981
Attack summary
Severity: critical — Claimed exfiltration of transaction and financial data at scale from a global payment infrastructure provider affects potentially millions of end-users and merchants, constituting regulated financial PII at critical scale; operational disruption to payment systems compounds the impact.Handala Hack claims to have breached Verifone and exfiltrated all transaction and financial data associated with its payment systems and terminals, while also causing widespread operational disruption to payment infrastructure globally.
Data the group says was taken
AI dossier — extracted from the leak post- Transaction records
- Financial data
- Payment system data
- Point-of-sale terminal data
What the group claims
Today, Handala Hack has successfully breached the Israeli company Verifone, a leading provider of payment solutions and point-of-sale terminals to countries across the globe. This sophisticated operation has caused widespread disruption in payment systems and terminals, and all related transaction and financial data have been extracted. This attack is a decisive and direct response to…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
