Ransomware victim disclosure
← All victimsShabak (Israel Security Agency / Shin Bet) – Airport Security Systems
listed as Smile for the Camera – Handala Is Watching · Claimed by Handala · listed 9 months ago
Status timeline
- ListedNov 15, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThe Shabak (also known as Shin Bet or the Israel Security Agency) is Israel's internal security service, responsible for counter-terrorism, counter-espionage, and protective security including airport security operations. The group claims to have targeted Shabak's airport security systems specifically. It is a government agency operating under the Israeli Prime Minister's Office.
- Industry
- Government Intelligence & National Security
- Founded
- 1948
Attack summary
Severity: critical — The claimed target is a national intelligence and security agency's airport security infrastructure — a critical government and national-security asset. Any confirmed exfiltration of such data constitutes a critical-severity incident involving government/defence systems and potential mass public-safety implications.Handala (RedWanted) claims to have conducted an intrusion targeting Shabak's airport security systems, implying exfiltration of data related to those systems; the post frames this as an exposure of the regime's security apparatus and suggests sensitive operational or surveillance data was obtained.
Data the group says was taken
AI dossier — extracted from the leak post- Airport security system data
- Shabak operational records
- Surveillance/monitoring system information
What the group claims
This Saturday, Handala RedWanted decided to do things differently. We set our sights directly on the Shabak, your regime’s so-called security guardians. But do you truly feel safe? As long as we are here, that’s little more than an illusion. For years, Shabak’s airport security systems were said to exist solely for “protection.” Yet, their…
Sources
Source
Indexed 9 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

