Ransomware victim disclosure
← All victimsIran International
listed as Leaked Documents Reveal Identities of Iran International Staff · Claimed by Handala · listed 1 year ago
Status timeline
- ListedJul 9, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- United Kingdom
- Listed on leak site
- Jul 9, 2025
About the victim
AI dossier — public-source company profileIran International is a news network that covers Iranian affairs and publishes content on LGBTQ+ issues and human rights within Iran. The organization operates with journalists and editorial staff focused on reporting on Iran.
- Industry
- Media & News Broadcasting
Attack summary
Severity: critical — Targeted doxing of journalists and human rights advocates working on sensitive Iran-related issues and LGBTQ+ rights; publication of personally identifying information creates direct physical safety risks in a hostile geopolitical context.The Handala group claims to have obtained and is publishing personal identifying information about Iran International staff members, including journalists. The disclosure includes names, roles, and identifies individuals involved in editorial decision-making and LGBTQ+ advocacy work.
Data the group says was taken
AI dossier — extracted from the leak post- Staff names and identities
- Job titles and roles
- Editorial responsibilities
What the group claims
Arghavan ShamsArghavan Shams is a journalist and the person responsible for promoting LGBTQ-related issues inside Iran, currently working with Iran International network. Nadia Tariqi Nadia, You’ve operated behind the curtain long enough. For years, your fingerprints have been on the editorial pulse of Iran International. The headlines, the angles, the frames , many…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

