Ransomware victim disclosure
← All victimsTamir Hayman
Claimed by Handala · listed 3 months ago
Status timeline
- Listed
Mar 13, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileTamir Hayman is a former head of Aman (Israeli Military Intelligence Directorate) and current Executive Director of Israel's Institute for National Security Studies (INSS), a leading think tank focused on national security and strategic affairs. In this role he oversees research and policy advisory activities related to Israeli and regional security. He is a high-profile individual target rather than a conventional corporate entity.
- Industry
- National Security & Intelligence Research
Attack summary
Severity: critical — The claimed exfiltration of 50,000 emails from a former intelligence chief and current national security institute director represents potential exposure of classified, government, and defence-related communications at significant scale, meeting the threshold for critical severity.The Handala group claims to have exfiltrated approximately 50,000 emails from Tamir Hayman's personal or institutional mailbox, asserting the correspondence contains top-secret content; no encryption of systems is mentioned, only data theft and publication.
Data the group says was taken
AI dossier — extracted from the leak post- 50,000 emails
- Classified/top-secret correspondence
- Personal mailbox contents
What the group claims
Hey Tamir, Still feeling safe behind those fancy titles? Former chief of Aman, and now the proud executive director of Israel’s national security institutes, yet you couldn’t even secure your own mailbox! What a joke. Tonight, reality hit you harder than any intelligence briefing ever could. Consider all your “top secret” correspondence exposed: 50,000 emails,…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
