Ransomware victim disclosure
← All victimsDelek Group / Delkol
listed as Israel’s fuel supply system · Claimed by Handala · listed 1 year ago
Status timeline
- ListedJun 14, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileDelek Group and its subsidiary Delkol are major operators of Israel's fuel supply infrastructure, including fuel station networks and distribution systems critical to the country's energy security and transportation sector.
- Industry
- Energy & Fuel Distribution
Attack summary
Severity: critical — Claimed compromise of Israel's critical fuel supply infrastructure with exfiltration of 2 TB of 'classified' data. Threat to national energy security and potential operational disruption to civilian and military transportation; aligns with critical infrastructure targeting.Handala claims to have compromised Delek Group and Delkol's systems, exfiltrating approximately 2 terabytes of data described as 'classified' and threatening fuel station vulnerability. The group claims access to fuel system infrastructure and operational secrets.
Data the group says was taken
AI dossier — extracted from the leak post- fuel system infrastructure data
- operational secrets
- classified information
- fuel station configuration/access data
What the group claims
Delkol and Delek have been compromised Your fuel systems are exposed. and so are your secrets. Over 2 terabytes of classified data are no longer in your hands. Your fuel stations are vulnerable. If you’re smart, you’ll act now. Fuel up immediately , before you’re left with nothing but empty roads and silent jets. Time…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

