Ransomware victim disclosure
← All victimsDubai in Shock: Unprecedented Handala Cyberattack Shakes UAE Infrastructure!
Claimed by Handala · listed 2 months ago
Status timeline
- ListedApr 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- United Arab Emirates
- Sector
- Public Sector
- Listed on leak site
- Apr 15, 2026
About the victim
AI dossier — public-source company profileThe target is described as UAE critical infrastructure broadly, with no single named company identified. The attack is framed as a nation-state-level hacktivist operation against the United Arab Emirates' public-sector and infrastructure systems. No specific organisation name or domain is provided.
- Industry
- Government & Critical Infrastructure
Attack summary
Severity: critical — Claimed destruction of 6 petabytes of data targeting a nation's critical infrastructure constitutes a critical-severity event involving potential large-scale operational disruption to government and public-sector systems, even absent confirmed regulated PII exfiltration.Handala claims to have destroyed 6 petabytes of data across UAE critical infrastructure in a destructive cyberattack; no ransom was demanded and the operation is characterised as politically motivated sabotage rather than extortion.
Data the group says was taken
AI dossier — extracted from the leak post- Destroyed infrastructure data (6 PB claimed)
What the group claims
In response to the blatant betrayal of the Resistance Axis by the Epsteinist leaders of the UAE, and as a serious, preemptive warning to all treacherous governments in the region, Handala has launched one of its most powerful cyberattacks against the country’s critical infrastructure. During this operation, 6 petabytes of data have been completely destroyed…
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

