Ransomware victim disclosure
← All victimsIranWire
Claimed by Handala · listed 2 months ago
Status timeline
- ListedMar 31, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileIranWire is an independent online journalism outlet focused on Iran, publishing news, investigative reporting, and human-rights coverage in Farsi and English. It was founded by journalist Maziar Bahari and operates with a diaspora-focused editorial model. The group alleges it operates under CIA guidance, a claim IranWire has not acknowledged.
- Industry
- Independent Online News Media
- Employees
- 11-50
- Founded
- 2013
Attack summary
Severity: high — Confirmed exfiltration and full system compromise of a journalism outlet is high severity due to the risk of exposing journalist sources, confidential communications, and potentially endangering individuals inside Iran; no evidence of regulated medical or financial PII at scale precludes 'critical'.Handala claims to have fully compromised and taken control of IranWire's systems, describing it as a complex targeted operation resulting in exfiltration of a 'vast volume' of data; no ransom was demanded and the data is described as published.
Data the group says was taken
AI dossier — extracted from the leak post- Internal communications
- Editorial and source files
- User/subscriber data
- Backend system access
What the group claims
In line with its committed responsibility and dedication to the ideals of the Axis of Resistance, the Handala Cyber Group has successfully carried out a complex and targeted operation, fully hacking and taking control of the hostile outlet IranWire, which was allegedly operating under the direct guidance and support of the CIA. A vast volume…
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

