099 ISP Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
099 Primo Telecomunications LTD was listed by the handala ransomware group on June 14, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may be affected; check the company’s notices and change any passwords or security details you hold with the provider.
On June 14, 2025, 099 Primo Telecomunications LTD, an Israeli internet service provider also referred to as 099 ISP, was listed by the handala ransomware group. Public reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. The number of people affected remains unknown, and many operational details have not been independently confirmed.
The listing matters because an ISP sits at a central point in communications infrastructure. Any compromise of internal systems can raise questions about the security of customer data, network operations, and related services, even when the precise scope of exposure is still unclear.
Breaking down the breach
According to available reporting, handala claims to have successfully infiltrated the internal infrastructure of 099 Primo Telecomunications LTD. The group asserts that internal files were taken as part of a ransomware attack. Public detail on the exact timing of the intrusion, the technical method used, the volume of data removed, or any ransom demand is limited. The reported summary attributes to the group statements that more than 150,000 public warning emails were dispatched via the company’s official mail servers and that the attackers could have severed access or disrupted screens; these remain unverified claims made on the group’s leak-site listing rather than independently confirmed findings.
No official confirmation of the full extent of the compromise has been detailed in the provided facts. The number of individuals or accounts potentially affected is listed as unknown. What is established is the public listing itself, the characterization of the event as a ransomware incident involving exfiltration of internal files, and the June 14, 2025 reporting date.
Inside handala
Handala is a known threat actor that has operated in the public eye primarily through leak-site postings and claims of attacks against organizations, frequently those linked to Israel. The group typically combines data theft with public messaging, often framing its activity in political terms and using leak sites to pressure victims by threatening or releasing stolen material. Its tactics commonly include network intrusion, exfiltration of internal documents, and announcements that exaggerate impact for attention. Prior activity associated with the name has involved claims against government, commercial, and infrastructure-related targets, though each listing must be treated as an assertion until corroborated.
In this case the group claims it infiltrated 099 ISP’s internal systems and moved internal files. No further verified statements from the group about this specific victim appear in the facts beyond the leak-site listing and the summarized assertions about email volume and potential disruption. Attribution rests on the group’s own claim rather than independent forensic confirmation disclosed in the record.
About 099 Primo Telecomunications LTD
099 Primo Telecomunications LTD operates as an internet service provider in Israel, providing connectivity and related digital services. Organizations of this type typically manage customer account records, billing information, network configuration data, employee credentials, internal operational documents, and systems that support email and internet access for subscribers. As a node in the national digital infrastructure, an ISP holds both commercial data and technical information that can affect service continuity for individuals and businesses.
A breach involving such an entity is consequential because compromise of internal systems can expose operational details, customer-related information, or authentication material. Even when the precise contents of stolen files are not fully public, the role of an ISP means that any confirmed or claimed intrusion draws attention from customers, regulators, and security observers concerned about secondary risks such as credential misuse or service interference.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file categories, customer records, financial data, or personal identifiers is provided, and the number of people affected is unknown. Exact contents therefore remain unconfirmed.
Organizations of this kind commonly hold customer contact and billing details, service-provision records, employee information, network diagrams, configuration files, and internal correspondence. It is possible that some combination of these categories was among the internal files taken, but that possibility is not established as fact. Readers should treat any specific claim about particular data types as unverified until official disclosure or independent analysis appears.
The real-world impact
For individuals whose information may have been present in the internal files, risks include potential misuse of contact details, account identifiers, or any credentials that could enable phishing or account takeover. Because the scale is unknown, the practical exposure for any single person cannot yet be quantified. Customers of the ISP may face heightened phishing attempts that reference the company or recent service interactions.
For the organization itself, the incident creates operational, reputational, and regulatory pressures. Restoration of secure systems, investigation of the intrusion path, and communication with affected parties typically follow such events. The group’s claim of having used official mail servers to send large volumes of messages, if accurate, would indicate a period of control over outbound email infrastructure, which itself can amplify secondary fraud risks. No dollar figures, confirmed customer counts, or verified service outages are stated in the facts.
What to do if you're exposed
If you are a customer or employee of 099 Primo Telecomunications LTD, monitor account statements and login activity for unusual behavior. Change passwords on any related services, enable multi-factor authentication where available, and treat unsolicited emails or messages that reference the company with caution. Be alert for phishing that may exploit knowledge of the incident. Consider placing fraud alerts with credit bureaus if financial identifiers could have been involved, though such involvement is not confirmed here. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Official updates from the company or relevant authorities remain the most reliable source for further guidance as more details become public.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Iran Internation WhatsApp and Internal Access Listed by handala Ransomware GroupIgnite Chaos at Your Own Risk: i24 Channel Listed by handala Ransomware GroupBraverman Files Unleashed: Every Secret Now Exposed Listed by handala Ransomware GroupBibi Gate: The Gatekeeper’s Fall | Tzachi Braverman Listed by handala Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the 099 ISP Listed by handala Ransomware Group →
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.