10 corpses Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On November 22, 2025, the Handala ransomware group disclosed that it had exfiltrated internal files from 10 corpses in a ransomware attack, but the date of the intrusion itself has not been established. Anyone connected to the organisation should check whether their data has been compromised and take steps to secure their accounts.
What happened
On November 22, 2025, the Handala group posted a listing titled “10 corpses” on its leak site. The post states that internal files were exfiltrated during a ransomware attack and claims the material identifies ten senior operatives within the aerospace sector. No confirmed count of records, no list of specific file types, and no verified timeline of the intrusion have been made public. The organization itself has not issued a statement confirming or denying the claims.
Inside handala
Handala is a ransomware operation that has conducted multiple campaigns against Israeli-linked targets. The group typically combines encryption of systems with the threat or actual publication of stolen data on a dedicated leak site. Its announcements frequently include political framing, and the November 22 post follows that pattern by describing the material as exposing individuals whose identities the group asserts were previously hidden. Independent confirmation that the listed files originated from the claimed source has not been established.
Who is 10 corpses Listed by handala Ransomware Group?
The listing refers to an entity described in the group’s statement as part of the aerospace sector. Organizations in this field routinely manage technical specifications, personnel records, supplier contracts, and regulatory compliance documents. A breach affecting such an organization can therefore touch both institutional operations and the personal details of employees or contractors.
What was likely exposed
The only detail released is that internal files were allegedly exfiltrated. The exact categories of data contained in those files have not been disclosed. Aerospace organizations commonly hold employee contact information, project documentation, access credentials, and communications with government or commercial partners; however, whether any of these categories are present in the published material remains unconfirmed.
Why it matters
Individuals referenced in the files face the possibility that their names, roles, or contact details are now accessible to anyone visiting the leak site. For the organization, the incident adds to the operational burden of assessing what was taken and whether any systems remain compromised. Because the scale of exposure is unknown, the incident’s full consequences for affected people cannot yet be measured.
What to do if you're exposed
Anyone who works in or with the aerospace sector should monitor official communications from their employer and consider changing passwords for any accounts that may share credentials with the affected environment. Enabling multi-factor authentication on personal and professional accounts provides an immediate layer of protection. Readers can also run a free exposure scan of their email address against known breach data to check for prior appearances in public leaks.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
No Place to Hide: Unmasking the Masterminds Behind War Drones Listed by handala Ransomware GroupThe Day of Reckoning Awaits the Child-Killers Listed by handala Ransomware GroupThe 200,000 Message Bombshell: Bennett’s Game is Over Listed by handala Ransomware GroupCaught by the Octopus: Bennett’s Darkest Hour Listed by handala Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the 10 corpses Listed by handala Ransomware Group →
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.