Ransomware victim disclosure
← All victimsAvraham Hayyim ( Mehrdad Rahimi ) – Mossad Agent
Claimed by Handala · listed 5 months ago
Status timeline
- ListedJan 18, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThis leak post does not concern a company. The subject is identified as an individual — Mehrdad Rahimi (also named Avraham Hayyim) — alleged by the Handala group to be a Mossad officer serving as a guiding officer for Iranian agents on Mossad's Iran Desk. There is no corporate entity involved.
Attack summary
Severity: high — The disclosure constitutes a targeted dox of an alleged intelligence officer, exposing personal identity and alleged covert operational details. If accurate, this poses serious personal safety and national security implications, though it targets an individual rather than an organisation and no verified regulated data corpus is confirmed.The Handala group claims to have exposed the personal identity, alias, and alleged operational role of an individual they identify as a Mossad intelligence officer. The post appears to be a doxing/personal data disclosure rather than a ransomware attack on a corporate target.
Data the group says was taken
AI dossier — extracted from the leak post- Full name and alias
- Alleged intelligence role and affiliation
- Alleged operational activities
What the group claims
Avraham Hayyim ( Mehrdad Rahimi ) | (Guiding Officer of Iranian Agents in Mossad’s Iran Desk) Mehrdad Rahimi, serving as the guiding officer for Iranian agents within Mossad’s Iran Desk, attempted to play a major role in organizing and directing networks behind the unrest inside Iran. By managing and directing Iranian operatives, he sought to…
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

