Ransomware victim disclosure
← All victims099 Primo Telecommunications LTD
listed as 099 ISP · Claimed by Handala · listed 1 year ago
Status timeline
- ListedJun 14, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- Russia
- Sector
- Telecommunication
- Listed on leak site
- Jun 14, 2025
About the victim
AI dossier — public-source company profile099 Primo Telecommunications LTD (also known as 099 ISP) is an Israeli telecommunications and internet service provider. The company operates as a central infrastructure node in Israel's digital communications network.
- Industry
- Telecommunications
Attack summary
Severity: high — Confirmed unauthorized access to critical telecommunications infrastructure and email systems serving 150,000+ users represents significant operational disruption risk to critical national infrastructure and potential broad customer data exposure.Handala claims to have infiltrated 099 ISP's internal infrastructure and dispatched over 150,000 warning emails via the company's official mail servers, suggesting both unauthorized system access and potential email system compromise.
Data the group says was taken
AI dossier — extracted from the leak post- Internal infrastructure access
- Email server access
- Potentially customer communication records
What the group claims
Israel 099 ISP Hacked 099 Primo Telecomunications LTD Now, the Handala Hack has successfully infiltrated the internal infrastructure of 099 ISP , a central node in the digital grid. Over 150,000 public warning emails have been dispatched via their official mail servers! We could have severed access. We could have blacked the screens and silenced…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

