Ransomware victim disclosure
← All victimsIM Cannabis
Claimed by Handala · listed 2 years ago
Status timeline
- ListedOct 30, 2024
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileIM Cannabis (IMC) is an Israeli company approved by the Ministry of Health that cultivates and distributes medical cannabis strains. The company operates in agriculture and medicine, focusing on strain development, quality control, and matching appropriate cannabis products to patients' medical needs.
- Industry
- Medical Cannabis
Attack summary
Severity: medium — Data has been published by the threat actor, but the post contains inflammatory accusations rather than technical evidence of exfiltration. No specific sensitive data categories (PII, financial records, etc.) are detailed. The company operates in a legally regulated medical cannabis sector in Israel.The Handala group claims to have conducted a supply chain attack against IM Cannabis, alleging the company distributes cannabis shipments in Europe using fraudulent pharmaceutical documentation in cooperation with a security firm (ndn-security). The group has published data but makes unsubstantiated accusations of illegal drug distribution.
Data the group says was taken
AI dossier — extracted from the leak post- Supply chain records
- Shipping documentation
- Business communications
What the group claims
IM Cannabis is one of the main arms of the distribution of hallucinogenic and dangerous drugs in Europe and America. This company distributes drug shipments in Europe through fake pharmaceutical bills of lading and in cooperation with the security company ndn-security! Are European organizations aware of these measures? Through a supply chain attack by…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

