Ransomware victim disclosure
← All victimsHarel Insurance (Shirbit Server)
listed as Harel Insurance ( Shirbit Server ) · Claimed by Handala · listed 2 years ago
Status timeline
- ListedDec 3, 2024
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileHarel Insurance is a major Israeli insurance provider. Shirbit, formerly one of Israel's largest insurance companies offering auto and government employee coverage, was acquired by Harel in 2021 and integrated into Harel's network infrastructure.
- Industry
- Insurance
Attack summary
Severity: high — Confirmed breach of a major Israeli insurance company with likely access to sensitive government and military employee records. Exfiltration is claimed and data has been published. The victim serves government and military personnel, elevating sensitivity despite lack of granular proof details in the excerpt.Handala claims to have compromised a Shirbit proxy server within Harel's post-acquisition network. The group alleges exfiltration of data from this server, though specific data types and scope are not detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- insurance records
- government employee data
- military personnel information
What the group claims
Shirbit was one of the largest insurance companies in the Zionist regime, which provided all cars and insurance for government employees and the Zionist military! This company was purchased by Harel in 2021 and its infrastructure was transferred to the Harel network in an interface-oriented manner! However, the Shirbit proxy server was hacked by Handala…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

