RANSOMWARE VICTIMDUPLICATE CLAIM

Behind the Curtain: Full Details of Shin Bet’s Iran Desk Officers Released

handala📍 IL (IL)📅 March 23, 2026
8
same group

Attack Intelligence

Behind the Curtain: Full Details of Shin Bet’s Iran Desk Officers Released was compromised in a ransomware attack attributed to handala in March 2026. The organization, operating in an undisclosed sector in IL, was added to the group's data leak site as part of an extortion campaign.

handala operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

In the silence of the night, the communication lines of the Zionist regime are no longer calm. You don’t hear the sound of our footsteps, but you feel our presence; just as now, the names of 50 senior officers from your Iran desk are on our list: numbers that are no longer just for work…

Additional Details

Other Victims — handala (8)

Quick Facts

CountryIL (IL)
Attack DateMar 23, 2026
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

handala
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.