Ransomware victim disclosure
← All victimsExposing Israel’s Drone Queen: The Fall of Colonel Haimovich
Claimed by Handala · listed 2 months ago
Status timeline
- ListedApr 8, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThe subject of this leak post is not a company but an individual: Colonel Vered Haimovich, a retired Israeli Air Force officer described as having been appointed by IDF Chief of Staff Eyal Zamir to lead Squadron 166, an allegedly clandestine drone operations unit. No corporate entity is identified in the post.
- Industry
- Military / Defence — Unmanned Aerial Systems
Attack summary
Severity: high — The post targets a named active military/defence individual with claimed exposure of sensitive operational and personal data linked to classified military drone units; while no corporate PII at scale is involved, the defence/national-security context and personal doxing of a senior officer elevates severity to high.The hacktivist group Handala claims to have obtained and is publishing personal and operational information about Colonel Vered Haimovich, alleging she directs drone operations; the post frames the disclosure as a personal exposure ('doxing') of a named military officer rather than a ransomware attack on an organisation.
Data the group says was taken
AI dossier — extracted from the leak post- Personal identifying information of named military officer
- Alleged operational details of IDF Squadron 166
- Drone operation planning information
What the group claims
Ms. Vered Haimovich, Tonight, there’s nowhere left to hide; The shadows see everything, and it’s time for the truth to be revealed. You, a retired Air Force Colonel, now handpicked by Eyal Zamir, the IDF Chief of Staff, to lead the ultra-secret Squadron 166, are directly responsible for planning, directing, and executing drone operations against…
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

