Ransomware victim disclosure
← All victimsHandala RedWanted
Claimed by Handala · listed 10 months ago
Status timeline
- ListedOct 7, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Listed on leak site
- Oct 7, 2025
About the victim
AI dossier — public-source company profileThe victim listed as 'Handala RedWanted' does not appear to be a conventional company. Based on the leak post context, this entry appears to be a self-promotional declaration by the Handala hacktivist group rather than an attack on an identifiable external organisation. No verifiable company details can be established.
Attack summary
Severity: medium — The post claims large-scale PII exfiltration affecting millions of individuals, which would ordinarily be critical; however, no verifiable proof files, specific target, or data inventory are provided in this truncated post, and the entry appears to be a broad declaratory statement rather than a discrete, evidenced attack disclosure.The group claims to have conducted cyberattacks over a two-year period against Israeli ('Zionist regime') digital infrastructure, asserting infiltration of secure databases and exfiltration of personal information belonging to millions of individuals. No specific target organisation, ransom demand, or data size is disclosed.
Data the group says was taken
AI dossier — extracted from the leak post- Personal information of individuals
- Database records
What the group claims
From the Depths of Cyberspace: Handala RedWanted Declaration For two relentless years, Handala’s cyber warriors have struck deep into the heart of the Zionist regime’s digital strongholds. We have bypassed their so-called “unbreakable” defenses, infiltrated their most secure databases, and extracted the personal information of millions who thought they were untouchable. Every byte, every record,…
Sources
Source
Indexed 10 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

