Ransomware victim disclosure
← All victimsRaz Zimmt (head of the Iran Desk at Israeli security institutes)
Claimed by Handala · listed 3 months ago
Status timeline
- Listed
Mar 12, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileRaz Zimmt is an individual analyst identified as the head of the Iran Desk at Israeli security and research institutes, specializing in Iranian affairs. He is not a company but rather a named individual targeted personally. No organizational public site was available to confirm institutional affiliation details.
- Industry
- Intelligence & Security Research / Think Tank
Attack summary
Severity: high — The target is a named individual working in national-security-adjacent intelligence research; claimed exfiltration of his full inbox and 'entire world' of data likely encompasses sensitive geopolitical analysis, source communications, and personal PII, representing significant personal and potentially national-security risk.The group Handala claims to have gained unauthorized access to the target's email inbox and broader personal digital accounts, implying exfiltration of personal and professional communications and data, framed as retaliation for the target's public commentary on Iran.
Data the group says was taken
AI dossier — extracted from the leak post- Email inbox contents
- Personal communications
- Professional correspondence
- Potentially sensitive research or analytical material
What the group claims
Mr. Raz Zimmt, Do you still think you can comment on Iran? Today, you learned the hard way what happens when you play with fire, you get burned. The so-called head of the Iran Desk at Israeli security institutes has now become the hunted. We didn’t just access your inbox, we unlocked your entire world.…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
