Ransomware victim disclosure
← All victimsIranWire
listed as Publication of Photos and Personal Details of IranWire’s Traitorous Members · Claimed by Handala · listed 2 months ago
Status timeline
- ListedApr 8, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileIranWire is an independent online news outlet that covers Iran-related news and human rights issues, operating with journalists and contributors both inside and outside Iran. The group Handala characterises its members as traitors, suggesting the outlet publishes content critical of the Iranian government. It has no confirmed physical headquarters stated in the leak post.
- Industry
- Independent Online Journalism & Media
Attack summary
Severity: critical — This is a targeted doxxing operation publishing the identities and photographs of named journalists working on Iran coverage. Publishing PII and photos of individuals who report on a repressive government constitutes a severe threat to personal safety and physical security, meeting the critical threshold for regulated/sensitive personal data disclosure with direct risk to life.The group Handala claims to have obtained and publicly released the full personal details and clear photographs of 20 named IranWire staff members or contributors, framing the disclosure as an exposure of individuals they label as traitors.
Data the group says was taken
AI dossier — extracted from the leak post- Full names of 20 individuals
- Personal photographs (clear/identified)
- Personal details (nature unspecified)
What the group claims
We inform the honorable and resilient people that the complete details along with clear photos of 20 members of IranWire who have betrayed the homeland are now available to the public. The names of these individuals are as follows: Maryam Dehkordi Sina Ghanbarpour Maziar Bahari Mojtaba Hosseini Solmaz Elkder Samaneh Ghadarkhani Roghieh Rezaei Payam Younesi…
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

