Ransomware victim disclosure
← All victimsIsraeli Military Intelligence Unit 9900 (Aman)
listed as 50 Senior Unit 9900 Officers Exposed · Claimed by Handala · listed 2 months ago
Status timeline
- ListedApr 8, 2026
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- Israel
- Sector
- Public Sector
- Listed on leak site
- Apr 8, 2026
About the victim
AI dossier — public-source company profileUnit 9900 is a classified visual intelligence and geospatial unit within Aman (Israeli Military Intelligence Directorate), a branch of the Israel Defense Forces. It specialises in aerial and satellite imagery analysis and geographic intelligence. As a military unit, it has no public-facing commercial presence.
- Industry
- Military Intelligence / Defence
Attack summary
Severity: critical — Claimed exfiltration and public disclosure of personally identifying information on senior officers of a classified military intelligence unit constitutes a critical national-security-level exposure of regulated/sensitive government and defence personnel data.Handala claims to have conducted months of surveillance and cyber operations resulting in the exfiltration and public disclosure of personal details for 50 senior officers belonging to Unit 9900 of Israeli Military Intelligence.
Data the group says was taken
AI dossier — extracted from the leak post- Full personal details of 50 senior intelligence officers
- Military rank/role information
- Potentially identifying biographical data
What the group claims
Today, for the first time, the complete details of 50 senior officers from Unit 9900 of the Israeli military intelligence (Aman) have been made public. This historic exposure is the result of months of surveillance and complex cyber operations by Handala Hack, a move that has sent shockwaves through the very foundation of the Zionist…
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

