Ransomware victim disclosure
← All victimsClockWorkAdmin
Claimed by Handala · listed 1 year ago
Status timeline
- ListedJun 29, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Listed on leak site
- Jun 29, 2025
About the victim
AI dossier — public-source company profileClockWorkAdmin appears to be a financial or cryptocurrency administration/management platform based on references to KYC archives, fund files, transaction trails, and compliance logs. No public site or additional identifying information is available.
- Industry
- Financial Services & Cryptocurrency
Attack summary
Severity: critical — Claimed exfiltration of KYC data (personal identification), financial transaction records, and investor documentation represents regulated financial/AML data at scale with high regulatory and privacy sensitivity.Handala claims full infrastructure compromise including backend databases, cloud storage, internal communications, and investor documentation. The group states exfiltration of fund files, KYC records, transaction data, compliance logs, and internal memos.
Data the group says was taken
AI dossier — extracted from the leak post- backend databases
- cloud storage contents
- internal communications
- investor documentation
- fund files
- KYC archives
- transaction records
- compliance logs
- internal memos
What the group claims
ClockWorkAdmin Hacked To the management of Clockwork Admin, This is not a test. This is not a drill. Your entire infrastructure has been compromised. From backend databases and cloud storage to internal communications and investor-related documentation , we are inside. Every fund file, KYC archive, transaction trail, compliance log, and internal memo has been accessed,…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

