Ransomware victim disclosure
← All victimsKash Patel current director of the FBI
Claimed by Handala · listed 2 months ago
Status timeline
- Listed
Mar 27, 2026
- Data leaked
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Mar 27, 2026
- Ransom demanded
- $10M
About the victim
AI dossier — public-source company profileThe Federal Bureau of Investigation (FBI) is the principal federal law enforcement and domestic intelligence agency of the United States government, headquartered in Washington, D.C. It operates under the Department of Justice and employs tens of thousands of personnel across field offices nationwide. Kash Patel serves as its current Director.
- Industry
- Federal Law Enforcement
Attack summary
Severity: critical — The claimed target is the sitting Director of the primary US federal law enforcement and intelligence agency; any confirmed exfiltration of government/law-enforcement data at this level constitutes a critical national-security incident involving sensitive government and potentially classified or PII-rich records.Handala claims to have conducted a retaliatory hack against the FBI and/or its director Kash Patel following the FBI's seizure of Handala's domains and announcement of a $10 million reward for group members; the group alleges exfiltration of data, though the specific data types and volume are not detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Unspecified FBI or Kash Patel personal/official data
What the group claims
Today, once again, the world witnessed the collapse of America’s so-called security legends. While the FBI proudly seized our domains and immediately announced a $10 million reward for the heads of Handala Hack members, we decided to respond to this ridiculous show in a way that will be remembered forever. Kash Patel, the current head…
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
