Ransomware victim disclosure
← All victimsHaor Heavy Transport
Claimed by Handala · listed 1 year ago
Status timeline
- ListedJun 19, 2025
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Sector
- Transportation/Logistics
- Listed on leak site
- Jun 19, 2025
About the victim
AI dossier — public-source company profileHaor Heavy Transport is an overland transport and shipping company operating under the Israeli flag. The group's post suggests operations involving cargo logistics and convey management, though details are limited.
- Industry
- Transportation & Logistics
Attack summary
Severity: medium — Claimed access to operational logistics data and cargo records represents moderate business sensitivity, particularly given insinuation of sensitive/unregistered shipments. No explicit proof files or screenshots count provided; no confirmed exfiltration of regulated PII, financial, or classified data evident from excerpt.The Handala group claims to have hacked Haor Heavy Transport and accessed shipping manifests, logistics data, and records. The post insinuates access to sensitive cargo information and unregistered shipments, though specific exfiltration claims are not explicitly detailed in the excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- shipping manifests
- logistics data
- cargo records
- route information
What the group claims
Haor Heavy Transport Hacked Few outside the region have heard of Haor, an unassuming overland transport company operating under the Israeli flag. But beneath the surface of shipping manifests and logistics data lies something less routine. Convoys move at odd hours. Routes shift without notice. And some cargo,sealed, unregistered,never appears on official records. Those who…
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

