Evidence of cooperation between the Mossad and Mojtaba Pourmohsen Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Evidence of Mossad-Mojtaba Pourmohsen cooperation was listed by the Handala ransomware group on July 9, 2025, after internal files were exfiltrated in an attack whose timing has not been established. Individuals who may have been exposed are advised to review the published material and take appropriate protective steps.
On July 09, 2025, the handala ransomware group listed material under the heading “Evidence of cooperation between the Mossad and Mojtaba Pourmohsen.” Public reporting states that internal files were exfiltrated in a ransomware attack, yet the number of people affected remains unknown and no independent confirmation of the claim has been released. The listing includes a direct message addressed to an individual named Mojtaba that asserts recordings of a private meeting and references a purported Mossad handler, but these statements are presented solely as the group’s unverified assertions.
Because the listing names both a foreign intelligence service and a private individual, the incident has drawn attention beyond ordinary ransomware disclosures. At present the only concrete details available are the date of the listing, the claim of internal-file exfiltration, and the text of the group’s message; everything else is undisclosed.
Breaking down the breach
According to the available record, handala published the listing on July 09, 2025. The sole description of the compromised material is “Internal files exfiltrated in ransomware attack.” No figure for the volume of data, no list of specific file types, and no timeline of the intrusion itself have been supplied. The accompanying summary consists of a taunting statement that begins “Mojtaba, Are you still under the illusion that the Stables Rectory Farm meeting in Halstead was private?” and continues with claims about multi-channel recordings, a named handler, and a staged intelligence trap. These assertions originate exclusively from the group’s leak-site post and have not been corroborated by any other source. The number of individuals whose data may be involved is listed as unknown.
Inside handala
Handala is a ransomware operation that has appeared on public leak sites in recent years. Like other groups of its type, it typically gains access to networks, encrypts systems, exfiltrates data, and then posts samples or full archives on a dedicated site to pressure victims. Public reporting has associated the group with politically themed targeting, often focused on entities linked to Israel or Western interests, though its precise affiliations remain unconfirmed by independent investigators. The group’s standard practice is to present its listings as factual disclosures while offering no verifiable chain of custody for the material. In this case the listing is therefore treated as an unverified claim rather than established fact.
About Evidence of cooperation between the Mossad and Mojtaba Pourmohsen Listed by handala Ransomware Group
The title under which the material appears is itself the designation used by handala: “Evidence of cooperation between the Mossad and Mojtaba Pourmohsen.” No separate corporate or governmental entity of that exact name is known to exist in public records. The listing therefore functions as an allegation that an individual named Mojtaba Pourmohsen has cooperated with Israel’s Mossad intelligence service. Organisations or individuals connected to intelligence or security work commonly hold sensitive operational notes, correspondence, travel records, and contact lists. A breach that claims to expose such material raises questions about the integrity of private meetings and personal security, even when the underlying claim remains unproven. Because the listing mixes a private name with a state intelligence service, the potential reputational and personal consequences extend beyond ordinary corporate data loss.
The information in question
The only data category named in the record is “Internal files exfiltrated in ransomware attack.” No further breakdown—such as emails, audio recordings, financial documents, or personal identifiers—has been provided. Organisations or individuals involved in sensitive meetings typically retain calendars, notes, correspondence, and sometimes audio or video files; however, whether any of those categories are present here is unconfirmed. The group’s own message asserts the existence of high-fidelity multi-channel recordings of a meeting at Stables Rectory Farm in Halstead, yet that assertion stands solely as the group’s claim. Exact contents of the exfiltrated files therefore remain undisclosed.
What's at stake
If the files contain genuine personal or operational material, individuals named in them could face reputational harm, unwanted scrutiny, or attempts at further social engineering. For any organisation whose internal records were taken, the risk includes loss of confidentiality around meetings, contacts, and planning documents. Because the number of people affected is unknown, the practical scale of exposure cannot yet be measured. Even unverified claims of intelligence cooperation can generate lasting personal and professional complications for those named, regardless of whether the underlying allegation is accurate. The absence of Reported Details means that both the individuals referenced and any associated parties must treat the situation as a potential rather than proven compromise until more information surfaces.
If your data was in this claimed breach
Anyone who believes their information may have been involved should begin by changing passwords on critical accounts, enabling multi-factor authentication where available, and monitoring financial and communication channels for unusual activity. Because the precise contents remain unconfirmed, a cautious approach is warranted. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a scan provides an additional, independent indicator of prior exposure and can help prioritise further protective steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
No Place to Hide: Unmasking the Masterminds Behind War Drones Listed by handala Ransomware GroupThe Day of Reckoning Awaits the Child-Killers Listed by handala Ransomware GroupThe 200,000 Message Bombshell: Bennett’s Game is Over Listed by handala Ransomware GroupCaught by the Octopus: Bennett’s Darkest Hour Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.