Ransomware victim disclosure
← All victimsKibbutz Almog
Claimed by Handala · listed 1 year ago
Status timeline
- ListedJun 20, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileKibbutz Almog is a kibbutz (collective agricultural settlement) in Israel operating in agriculture and food production. No public website or detailed corporate information is available.
- Industry
- Agriculture and Food Production
Attack summary
Severity: high — Confirmed exfiltration of sensitive data including financial records, personnel files (PII), security system data, and surveillance footage at significant scale (60K+ documents). Exposure of security infrastructure data poses additional operational risk.Handala claims to have infiltrated Kibbutz Almog's digital infrastructure and exfiltrated internal emails, confidential documents, financial and personnel records, surveillance footage, security system data, and backup archives. The group advertises approximately 60,000 documents as proof of compromise.
Data the group says was taken
AI dossier — extracted from the leak post- Internal and external email communications
- Confidential documents and administrative records
- Financial records
- Personnel files
- Surveillance camera footage
- Security system data
- Backup archives and cloud storage contents
The group's post references roughly 60000 proof files.
What the group claims
We have successfully infiltrated the digital infrastructure of Kibbutz Almog. Our operation has resulted in the full extraction of the following sensitive materials: Internal and external email communications Confidential documents and administrative records Financial and personnel files Surveillance camera footage and security system data Backup archives and cloud storage contents +60K Docs As PoC The…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

