Ransomware victim disclosure
← All victimsLockheed Martin
listed as Lockheed Martin Employees Given 48 Hours to Respond: A Tight Deadline Looms · Claimed by Handala · listed 3 months ago
Status timeline
- Listed
Mar 26, 2026
- Data leaked
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Mar 26, 2026
About the victim
AI dossier — public-source company profileLockheed Martin is a major American defense, aerospace, and security company headquartered in Bethesda, Maryland. It is one of the world's largest defense contractors, producing military aircraft, missile systems, and advanced technology solutions for government and military customers globally. The company employs over 100,000 people and generates revenues exceeding $60 billion annually.
- Industry
- Defense & Aerospace Manufacturing
- Employees
- 100000+
- Founded
- 1995
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII (passports, ID numbers, home addresses) belonging to defense-sector engineers involved in military projects, posing severe personal safety, national security, and counterintelligence risks.Handala Hack claims to have exfiltrated complete personal and professional data on 28 senior American engineers allegedly based in Israeli-occupied territories and involved in military projects, issuing a 48-hour ultimatum to Lockheed Martin employees to respond as part of their stated 'Operation Lockheed Martin.'
Data the group says was taken
AI dossier — extracted from the leak post- Full names
- National identification numbers
- Passport details
- Home addresses / places of residence
- Military project affiliations
What the group claims
Lockheed Martin Employees Given 48 Hours to Respond: A Tight Deadline Looms We, the Handala Hack , have today initiated a new phase of Operation Lockheed Martin. We now possess the complete data of 28 senior American engineers based in the occupied territories and involved in military projects—including names, identification numbers, passports, places of residence,…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
