Ransomware victim disclosure
← All victimsi24NEWS
listed as Ignite Chaos at Your Own Risk: i24 Channel · Claimed by Handala · listed 5 months ago
Status timeline
- ListedJan 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- Israel
- Sector
- Telecommunication
- Listed on leak site
- Jan 21, 2026
About the victim
AI dossier — public-source company profilei24NEWS is an Israeli international 24-hour news television channel broadcasting in English, French, and Arabic, headquartered in Jaffa, Tel Aviv. It covers global and Middle Eastern news and is distributed across multiple continents via cable, satellite, and streaming platforms. The channel is known for its multilingual live news coverage targeting international audiences.
- Industry
- Television Broadcasting & News Media
- Founded
- 2013
Attack summary
Severity: medium — The group claims a deliberate breach of a media/broadcasting entity with no ransom demanded and no explicit enumeration of exfiltrated regulated data or confirmed data publication. The post is largely a narrative announcement with limited verifiable proof details, warranting medium severity.Handala claims to have deliberately breached i24NEWS as a calculated operation conducted several weeks prior to the post, framing it as intentional disruption rather than opportunistic. The post implies exfiltration or operational compromise but does not explicitly enumerate the data categories or confirm encryption.
Data the group says was taken
AI dossier — extracted from the leak post- Internal communications (implied)
- Broadcasting system access (implied)
- Operational data (implied)
What the group claims
Several weeks ago, the breach of the i24 channel was not a mere coincidence or an act of random disruption, it was a calculated operation executed by Handala. Unlike many who seek validation through constant announcements and empty proclamations, we operate from the shadows, letting our actions speak louder than words. Our silence is not…
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

