Ransomware victim disclosure
← All victimsIran International
Claimed by Handala · listed 1 year ago
Status timeline
- ListedJul 8, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileIran International is a Persian-language news network that reports on Iran and related geopolitical topics. The organization operates as an independent media outlet with international reach.
- Industry
- News & Media
Attack summary
Severity: critical — Confirmed exfiltration of sensitive data including employee PII, security details, and financial records from a media organization; operational compromise of all network systems and infrastructure.Handala claims to have fully compromised Iran International's network infrastructure, encrypted systems, and exfiltrated a complete internal data dump including confidential communications, employee personal and security details, media contact logs, and financial records.
Data the group says was taken
AI dossier — extracted from the leak post- Internal communications
- External communications
- Employee personal details
- Employee security details
- Media liaison contact logs
- Bank records
- Financial contracts
What the group claims
Iran International has been successfully hacked. All of the network’s systems, servers, and communication infrastructure have been fully compromised and infected. A complete internal data dump has been extracted. This includes: Confidential internal and external communications Personal and security details of staff members Identities and contact logs of media liaisons Bank records, financial contracts, and…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

