Ransomware victim disclosure
← All victimsNetanyahu’s Cabinet Awaits Handala’s Next Move
Claimed by Handala · listed 7 months ago
Status timeline
- ListedDec 27, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThe post does not describe a conventional company but rather references Netanyahu's Cabinet, the executive governing body of the State of Israel. The target appears to be senior Israeli government officials or their associated data. No corporate entity is identifiable from the leak post.
- Industry
- Government & Politics
Attack summary
Severity: high — The post indicates ongoing targeted exfiltration of data linked to senior government officials with threatened further publication; however, no confirmed volume or specific regulated data type is verifiable from the truncated post, preventing a critical rating.Handala claims to have exfiltrated data related to specific named individuals associated with Netanyahu's Cabinet and is threatening further releases, having previously solicited public input on which individuals' data to publish next.
Data the group says was taken
AI dossier — extracted from the leak post- Personal data of named government officials
- Potentially sensitive political/personal records
What the group claims
Handala Command acknowledges with gratitude the messages from Jews who oppose the killing of children. We remain steadfast in our commitment to liberate both Palestinians and Jews from the grip of the extremist Kahani sect leaders. While Handala Command previously invited feedback regarding four specific individuals for data release, the overwhelming volume of messages requesting…
Sources
Source
Indexed 7 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

