Ben Horin & Alexandrovitz Ltd Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Ben Horin & Alexandrovitz Ltd was listed by the handala ransomware group on 22 June 2025, with internal files reported to have been exfiltrated. Individuals are advised to check whether their information was among the undisclosed number of records involved and to take appropriate protective steps.
When a company appears on a ransomware group's leak site, the people connected to it face a practical problem: their personal details, work records or other private information may now sit outside the organisation's control. On 22 June 2025 the firm Ben Horin & Alexandrovitz Ltd was listed by the group known as handala, which claims to have taken internal files. The number of individuals affected has not been disclosed, so anyone who has dealt with the company—employees, clients, partners or contractors—has reason to treat the claim seriously and check whether their own data has been exposed.
Public information about the incident remains limited to the group's own statements. No independent confirmation of the scale or exact contents of the material has been released, yet the mere listing is enough to create lasting uncertainty for those whose information may be involved.
Breaking down the breach
According to the listing published by handala on 22 June 2025, Ben Horin & Alexandrovitz Ltd was the target of a ransomware attack in which internal files were exfiltrated. The group has not published a precise date for the intrusion itself, nor has it released verified figures for the volume of data taken or the number of people whose records appear in it. The only concrete detail supplied is that internal files were removed. No technical description of the entry method, the malware used, or any ransom demand has been made public. The listing therefore stands as an unverified claim by the threat actor rather than a confirmed forensic report.
Who is handala?
Handala is a ransomware group that has operated publicly for several years, typically posting victim names and sample data on its leak site when organisations refuse to pay. The group is known for selecting targets it frames in political terms, frequently Israeli or Israel-linked entities, and for combining data theft with public messaging that mixes technical claims and ideological statements. Its usual pattern is to exfiltrate files first, then threaten publication if a ransom is not paid. Prior activity has included listings of companies in technology, defence-adjacent and professional-services sectors. In the present case the group claims Ben Horin & Alexandrovitz Ltd functions as “the psychological operations hub of the occupation” and a strategic partner of Unit 8200 and Mossad; those characterisations are the group's own assertions and have not been independently verified in connection with this incident.
About Ben Horin & Alexandrovitz Ltd
Ben Horin & Alexandrovitz Ltd is an Israeli firm whose precise commercial activities are not detailed in the public breach record. Organisations of this type commonly handle internal strategy documents, client communications, personnel records and project materials. Because the handala listing portrays the company as engaged in psychological operations and intelligence-adjacent work, any compromise of its systems would be consequential for both the firm and the individuals whose data it holds. Public detail beyond the group's claims remains limited; the company has not issued a statement confirming or denying the listing in the material available for this report.
The information in question
The only data type named in the available facts is “internal files” said to have been exfiltrated during a ransomware attack. No further breakdown—such as whether the files contain employee identities, client lists, financial records, emails or operational documents—has been disclosed. Firms that perform consulting, communications or security-related work typically store a mixture of personal identifiers, correspondence and proprietary material. Until the exact contents are confirmed or independently examined, it is not possible to state what specific categories of information were taken. The claim of exfiltration therefore remains unquantified and unverified beyond the group's assertion.
What's at stake
For individuals whose details may appear in the files, the immediate risks include identity misuse, targeted phishing, or the unwanted public exposure of private or professional information. Even if the data are never published, the fact that they have left the organisation's custody creates a lasting vulnerability. For the company itself, the consequences can include operational disruption, loss of client trust, regulatory scrutiny and potential legal exposure if personal data were involved. Because the number of people affected is unknown and the precise data types unconfirmed, the full scope of harm cannot yet be measured; the uncertainty itself is a material cost for everyone connected to the firm.
What to do if you're exposed
Anyone who has worked with, contracted for or supplied personal information to Ben Horin & Alexandrovitz Ltd should treat the claim as a prompt for basic protective steps. Change passwords on any accounts that may have been linked to the company, enable multi-factor authentication wherever possible, and monitor bank and credit statements for unusual activity. Be alert to unexpected emails or messages that reference the firm or request sensitive details. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. If you believe your data are involved, consider placing a fraud alert with credit agencies and retaining records of any suspicious contact for future reference.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Ivri, Kerner & Co Listed by handala Ransomware GroupIsrael Job Info Ltd Listed by handala Ransomware GroupBibi Gate: The Gatekeeper’s Fall | Tzachi Braverman Listed by handala Ransomware GroupOperation Octopus: Naftali Bennett Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.