Ransomware victim disclosure
← All victimsSt. Joseph County
Claimed by Handala · listed 2 months ago
Status timeline
- ListedApr 8, 2026
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Apr 8, 2026
About the victim
AI dossier — public-source company profileSt. Joseph County is a county government entity located in Indiana, USA, with its county seat in South Bend. As a local government body, it administers public services including law enforcement, courts, health, taxation, and infrastructure for residents of St. Joseph County. It operates centralized IT infrastructure supporting multiple county departments.
- Industry
- County Government / Public Administration
- Address
- South Bend, Indiana, United States
Attack summary
Severity: critical — A county government breach involving over 2 terabytes of exfiltrated data from centralized IT infrastructure almost certainly contains regulated PII, law enforcement records, tax and financial records, health data, and other sensitive government data at scale; data has been published.Handala Hack claims to have taken full control of St. Joseph County's centralized IT infrastructure following months of reconnaissance, exfiltrating over 2 terabytes of data. The group states the operation was targeted and deliberate, and the disclosure status indicates data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- County government IT infrastructure data
- Potentially sensitive resident/citizen records
- Internal administrative documents
- Exfiltrated data (2+ terabytes)
What the group claims
We, the members of Handala Hack, proudly announce that through a targeted and intelligent operation, we have completely taken control of the centralized IT infrastructure of St. Joseph County in the state of Indiana. This operation was successfully executed after months of monitoring, reconnaissance, and meticulous planning. During this attack, over 2 terabytes of the…
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

