EPS Tech confidential source code ( military ) Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
EPS Tech confirmed on August 22, 2024 that the Handala ransomware group had posted internal source code and military-related files stolen in a ransomware attack. Anyone who has done business with EPS Tech or may have been mentioned in those files should review their accounts and security posture immediately.
When a group claims to have taken confidential military source code, the immediate concern is not abstract national security talk but the concrete possibility that people who work with, depend on, or are protected by those systems could face elevated risk. On 22 August 2024 a listing appeared that named EPS Tech confidential source code (military) as the victim of an alleged ransomware-related exfiltration. Public detail remains limited, yet the claim itself is enough to put anyone connected to the organisation or its systems on notice that sensitive material may have left its intended environment.
The number of people affected is unknown. What is known is that the listing describes internal files taken in a ransomware attack and asserts possession of large volumes of source code. Until independent confirmation or official statements appear, the practical stakes for individuals rest on the possibility that proprietary military-related code and supporting files have been copied and could be misused, sold, or further leaked.
Breaking down the breach
According to the public listing dated 22 August 2024, the handala ransomware group claimed responsibility for an incident involving EPS Tech confidential source code (military). The group stated that internal files had been exfiltrated during a ransomware attack. It further claimed to hold approximately 10 GB of EPS Tech confidential source code as a proof of concept and asserted possession of about 800 GB of source code belonging to sensitive military systems. The listing included the statement that handala and associated resistance groups were present inside secret military systems and called for an immediate announcement from Aman to update those systems, adding that more surprises would follow.
No independent confirmation of the intrusion method, the exact date of any compromise, the full volume of data taken, or the authenticity of the claimed files has been supplied in the available record. The number of people affected remains unknown. Public reporting is limited to the group’s own leak-site listing; therefore the incident is treated here as an unverified claim rather than an established fact.
The group behind it: handala
Handala is a publicly documented pro-Palestinian hacktivist and ransomware-linked group that has repeatedly targeted Israeli government, military, and technology entities. The group typically operates by claiming network intrusions, exfiltrating data, and posting samples or full archives on leak sites while issuing political statements. Its tactics commonly include ransomware deployment combined with data theft for leverage and publicity. Prior public activity has focused on organisations perceived as linked to Israeli defence or critical infrastructure, often accompanied by claims of deep access into sensitive systems.
In this case the group’s listing of EPS Tech confidential source code (military) is presented as its own claim. No additional statements or evidence beyond the 22 August 2024 listing are part of the available facts, so nothing further is attributed to handala regarding this specific victim.
About EPS Tech confidential source code ( military )
EPS Tech confidential source code (military) is identified in the listing as an organisation holding confidential source code related to military systems. Organisations of this type typically develop, maintain, or supply software components used in defence applications. Such entities routinely handle proprietary source code, design documents, configuration data, and related technical materials that are classified or commercially sensitive because they underpin operational military capabilities.
A breach involving this category of material is consequential because source code can reveal system architecture, vulnerabilities, authentication methods, and integration points. Even without confirmed compromise of live systems, the mere possibility that such code has left controlled environments raises concerns about reverse-engineering, the development of countermeasures, or the reuse of the code in unauthorised contexts. Public detail on the precise role or ownership of EPS Tech is limited to the description given in the listing itself.
The information in question
The facts name the exposed material as internal files exfiltrated in a ransomware attack. The group’s claim specifically refers to 10 GB of EPS Tech confidential source code offered as a proof of concept and asserts possession of roughly 800 GB of source code from sensitive military systems. No further inventory of file types, personal data, credentials, or other categories has been disclosed in the available record.
Organisations that develop military-related software typically hold source-code repositories, build scripts, documentation, test data, and sometimes configuration or deployment information. Whether any of those additional categories were taken remains unconfirmed. The exact contents of the claimed archive are therefore unknown; only the group’s description of “confidential source code” and “internal files” is on record.
Why it matters
For people whose work or security depends on the systems in question, the primary risk is that proprietary code could be analysed for weaknesses or used to craft more effective attacks against related platforms. Even if personal identity data is not involved, exposure of source code can erode the integrity of systems that protect personnel, infrastructure, or classified operations. For the organisation itself, the claim creates operational uncertainty: it must determine whether the intrusion occurred, assess the authenticity of any leaked material, and decide whether systems require urgent review or patching.
Because the number of affected individuals is unknown and the precise data set is unconfirmed, the practical impact cannot yet be quantified. The claim alone, however, is sufficient to warrant careful monitoring by anyone who interacts with the organisation’s products or services, as well as by the organisation’s own security and legal teams.
Were you affected?
If you have any connection to EPS Tech confidential source code (military) or to systems that may rely on its software, treat the claim as a prompt for caution rather than confirmed personal exposure. Monitor official statements from the organisation or relevant authorities. Change passwords and enable multi-factor authentication on any accounts that could be linked to the environment. Review devices and networks for unusual activity. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a scan will not confirm or deny involvement in this specific incident but can surface prior exposures that merit attention.
Public information remains limited to the 22 August 2024 listing. Until further verified details emerge, the prudent course is to assume the claim may be accurate and to take basic protective steps while awaiting official clarification.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Handala’s attack on Israeli organizations Listed by handala Ransomware GroupShock for Israeli Intelligence: 100,000 Classified Emails of Mossad’s Ex-Deputy Director S... Listed by handala Ransomware GroupUnprecedented Disclosure of 50 Senior Israeli Air Force Officers’ Information Listed by handala Ransomware GroupIsrael Institute for National Security Studies (INSS) Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.