Ransomware victim disclosure
← All victimsIsrael Ministry of National Security
Claimed by Handala · listed 1 year ago
Status timeline
- ListedJan 29, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- Israel
- Sector
- Public Sector
- Listed on leak site
- Jan 29, 2025
About the victim
AI dossier — public-source company profileIsrael's Ministry of National Security is a government agency responsible for national security operations and civil defense infrastructure, including management of emergency shelter systems.
- Industry
- Public Sector - National Security
Attack summary
Severity: critical — Claimed compromise of critical national security infrastructure (civil defense shelter network) affecting public safety at scale. Alleged operational control over emergency systems represents direct threat to civilian protection during conflicts.Handala claims to have compromised the integrated management system controlling Israel's civil defense shelter network. The group claims operational control over shelter access and system functions, accompanied by calls to emergency services.
Data the group says was taken
AI dossier — extracted from the leak post- Shelter management system access
- Civil defense infrastructure controls
- Emergency response protocols
What the group claims
Ministry of National Security Hacked Happening now: 1- Hacking the comprehensive integrated management system of the regime’s shelters by Handala 2- Sound the red alert by Handala 3- People Go to shelters 4- Handala Close the Doors 5- Handala Play Kheybar Kheybar for Them 6- Handala Wipe the System 7- Plz Call 101 for saving…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

