Ransomware victim disclosure
← All victimsWeizmann Institute of Science
listed as Weizmann New Leak · Claimed by Handala · listed 1 year ago
Status timeline
- ListedJun 27, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThe Weizmann Institute of Science is a major Israeli public research institution conducting fundamental and applied research across mathematics, physics, chemistry, biology, and computer science. Based in Rehovot, it employs thousands of scientists and produces significant academic output and intellectual property.
- Industry
- Scientific Research & Development
- Address
- Rehovot, Israel
- Employees
- 3000-4000
- Founded
- 1934
Attack summary
Severity: critical — Alleged exfiltration of sensitive scientific research, unpublished manuscripts, and proprietary models from a major research institution. Data affects national scientific assets and researchers' intellectual property. Operational disruption to critical research infrastructure claimed.The Handala group claims to have encrypted Weizmann's data center infrastructure, destroyed backups, and exfiltrated research data including unpublished manuscripts and research models. The group claims comprehensive data retention.
Data the group says was taken
AI dossier — extracted from the leak post- unpublished research manuscripts
- research models and datasets
- institutional data center contents
- cloud-stored materials
What the group claims
Dear Weizmann, Boom. That’s the sound your data center made. We hear the servers didn’t make it. The backups? Vaporized. The cloud? Rained fire. Your brilliant decades of research? Gone. Well , not entirely. We saved it for you. Every byte. Every model. Every unpublished manuscript. While your walls burned, our vaults stayed cold and…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

