Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Handala is a pro-Palestinian, pro-Iran hacktivist group that emerged after October 2023, known for phishing-delivered custom wiper malware, data leaks and DDoS against Israeli targets, with multiple vendors assessing links to Iran's MOIS (overlapping with Void Manticore / BANISHED KITTEN).
Handala surfaced in December 2023, shortly after the 7 October 2023 attacks and the ensuing conflict, branding itself as a pro-Palestinian hacktivist collective. Its core tradecraft centers on destructive operations: phishing emails deliver malicious attachments that deploy custom wiper malware which overwrites files with random data and renders systems unbootable, complemented by data-theft-and-leak extortion and DDoS. Trellix and others have documented Handala's wiper targeting Israeli organizations.
Multiple security firms and intelligence assessments associate Handala with Iranian state interests and specifically Iran's Ministry of Intelligence and Security (MOIS), noting operational overlaps with the Void Manticore / BANISHED KITTEN cluster and positioning the group within Iran's asymmetric cyber strategy. These are analytic assessments rather than confirmed admissions.
In 2025 Handala escalated: reporting describes a January 2025 incident abusing public-address systems in Israeli kindergartens to broadcast alerts and propaganda (later acknowledged by Israel's National Cyber Directorate), plus multi-wave DDoS against Israeli telecom and energy providers. Its targeting is overwhelmingly Israel, with additional MENA-relevant claims including the UAE. Individual victim and breach claims are self-reported and should be treated as unverified unless confirmed by a reputable source.
Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →
| Date | Victim | Country | Sector |
|---|---|---|---|
| 2026-04-07 | Exposing Israel’s Drone Queen: The Fall of Colonel Haimovich | — | — |
| 2026-04-06 | Raz Zimmt’s Chats Leaked to the World | — | — |
| 2026-04-05 | Handala Hack Strikes 27 Companies for Minab’s Innocents | — | — |
| 2026-04-04 | 50 Senior Unit 9900 Officers Exposed | — | Government & Defense |
| 2026-04-03 | Publication of Photos and Personal Details of IranWire’s Traitorous Members | — | Other |
| 2026-04-02 | Passover Wiped Clean: 22TB of Data Gone from 14 Companies | — | — |
| 2026-04-02 | PSK WIND’s Defense Networks Fall to Handala Hack | — | Energy & Utilities |
| 2026-04-01 | St. Joseph County | US | Government & Defense |
| 2026-03-31 | IranWire | IR | Technology |
| 2026-03-29 | Listen Closely, Gallant: Handala’s Eyes and Ears Are Everywhere | — | — |
| 2026-03-28 | 4 Terabytes Wiped—Good Food Store Shut Down After Major Cyberattack | US | Retail & E-Commerce |
| 2026-03-28 | North Country Business Products Breached: 2,680 POS Terminals Disabled Nationwide | US | Technology |