Ransomware victim disclosure
← All victimsFoulath and SULB (Gulf Industrial Investment Co. / Steel companies)
listed as Handala Strikes Back: Steel Giants Foulath and SULB Crippled in Retaliation Cyberattack · Claimed by Handala · listed 2 months ago
Status timeline
- ListedApr 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- United Arab Emirates
- Sector
- Manufacturing
- Listed on leak site
- Apr 15, 2026
About the victim
AI dossier — public-source company profileFoulath (Gulf Industrial Investment Company) and SULB (The Steel Products Company) are two major steel manufacturing companies based in the Arabian Gulf region, described by the threat actor as 'unrivaled steel giants of the region.' They are associated with industrial steel production and are linked to the Gulf Cooperation Council industrial sector.
- Industry
- Steel Manufacturing
Attack summary
Severity: high — The attack targets critical industrial infrastructure (major regional steel manufacturers), the group claims an 'unprecedented' wide-scale cyber operation, and the disclosed status is 'data_published,' indicating some level of confirmed exfiltration or impact; however, specifics on data type and scale are absent from the truncated post.Handala claims to have conducted a wide-scale cyberattack against both Foulath and SULB steel companies, framing it as retaliatory action against attacks on 'Resistance Axis' steel factories; the post implies operational disruption and/or data exfiltration but specific details are truncated.
What the group claims
In the wake of the organized crimes and targeted attacks on the steel factories of the Resistance Axis last week, Handala once again proves that any assault on the Resistance will be met with a severe and unforgettable response. In a wide-scale and unprecedented cyber operation, the two unrivaled steel giants of the region, Foulath…
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

