Ransomware victim disclosure
← All victims15 SIGINT Agents Exposed — $50,000 Reward
Claimed by Handala · listed 7 months ago
Status timeline
- ListedJan 3, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThe target is described as part of the Israeli state intelligence apparatus, specifically Signal Intelligence (SIGINT) operations. No named civilian company is identified; the victim is a governmental/military intelligence unit. The post claims exposure of 15 SIGINT officers by name.
- Industry
- Military Intelligence / Government Security
Attack summary
Severity: critical — Confirmed public disclosure of personal identities of named government intelligence officers constitutes a critical severity event: it exposes individuals to physical harm, compromises active intelligence operations, and involves highly sensitive government/defence personnel data.Handala claims to have exfiltrated identity information on 15 Israeli SIGINT officers and published it publicly, offering a $50,000 reward in connection with the disclosure. No encryption of systems is mentioned; the operation is characterised as a targeted intelligence exposure.
Data the group says was taken
AI dossier — extracted from the leak post- SIGINT officer identities
- Personal identifying information of intelligence personnel
- Operational security details
What the group claims
For the first time, Handala RedWanted delivers a decisive blow to the Zionist regime’s intelligence apparatus by exposing the identities of 15 Signal Intelligence (SIGINT) officers. With operational precision and unwavering resolve, we have breached their layers of secrecy and penetrated to the core of their intelligence network. This strategic disclosure is intended to shake…
Sources
Source
Indexed 7 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

