IM Cannabis Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On October 30, 2024, IM Cannabis was listed by the handala ransomware group after internal files were exfiltrated in an attack. Individuals who may have had dealings with the company should review their accounts and monitor for suspicious activity.
Ransomware groups continue to list corporate victims on leak sites as a pressure tactic, often blending data-theft claims with unverified narratives. In this environment, a listing of IM Cannabis by the handala group, reported on 30 October 2024, fits a familiar pattern of supply-chain and internal-file claims that leave the public with limited confirmed detail.
Public information indicates only that the company was named on a handala leak site in connection with an alleged ransomware attack involving exfiltrated internal files. The number of people affected remains unknown, and independent verification of the full scope has not been published.
What happened
According to the available record, IM Cannabis was listed by the handala ransomware group on or around 30 October 2024. The listing asserts that internal files were exfiltrated during a ransomware attack. The group’s own summary further claims the incident involved a supply-chain attack and makes additional allegations about the company’s business practices; those allegations are presented here solely as the group’s statements and have not been independently confirmed in the public record.
No confirmed figures for the volume of data, the precise date of intrusion, or the technical method beyond the group’s supply-chain reference have been disclosed. The number of individuals whose information may have been involved is listed as unknown. Public detail on containment, notification to regulators, or any ransom demand remains limited.
The group behind it: handala
Handala is a ransomware and data-leak actor that has appeared on public leak sites in recent years. Like many such groups, it typically claims to have stolen files, posts samples or full archives if a ransom is unpaid, and sometimes appends political or reputational messaging to increase pressure. Public reporting has associated the name with operations that mix financial extortion and ideological framing, though attribution of any single campaign remains a matter for specialised investigators.
In this case the group claims IM Cannabis is “one of the main arms of the distribution of hallucinogenic and dangerous drugs in Europe and America,” alleges the use of “fake pharmaceutical bills of lading,” and names a security company in connection with the claimed supply-chain vector. These statements are the group’s own assertions on its listing; they are not established facts about the victim. No independent confirmation of the group’s broader narrative has been released in the material available for this report.
About IM Cannabis
IM Cannabis operates in the cannabis sector, a regulated industry that typically involves cultivation, processing, distribution and related pharmaceutical or wellness products across multiple jurisdictions. Companies of this type commonly hold commercial contracts, shipping and logistics records, employee and partner data, and regulatory filings. Because the sector intersects with controlled-substance rules, any compromise of internal files can raise both commercial and compliance concerns.
A breach listing therefore carries weight beyond ordinary corporate data theft: it can affect supply-chain partners, regulatory standing and public trust. The precise corporate structure and geographic footprint of IM Cannabis are not detailed in the breach record itself; only the organisation name and the group’s claims appear.
What data was at risk
The public record states that internal files were exfiltrated in a ransomware attack. No further breakdown of file categories, record counts or personal-data fields has been disclosed. Organisations in this sector typically maintain employee records, customer or patient-related information where licensed, supplier contracts, financial documents and operational logistics data. Whether any of those categories were among the files claimed by handala is unconfirmed.
Because the exact contents remain undisclosed, it is not possible to state with certainty what personal or commercial information, if any, left the organisation’s control. Readers should treat any specific data-type claims beyond “internal files” as unverified until corroborated by the company or competent authorities.
What's at stake
For individuals whose details may appear in internal files, the practical risks include targeted phishing, identity-related fraud or unwanted contact if contact information or identifiers were present. For the organisation, exposure of commercial documents can enable competitive harm, contractual disputes or regulatory scrutiny. The group’s additional narrative claims, even if unproven, can create reputational pressure that outlasts the technical incident.
Because the scale of affected people is unknown and the file contents unconfirmed, the concrete impact cannot yet be quantified. The absence of public confirmation does not eliminate risk; it simply means affected parties must proceed on the basis of limited information and standard protective steps.
Were you affected?
If you have had any relationship with IM Cannabis—as an employee, contractor, partner or customer—treat the listing as a prompt to review your exposure rather than as proof that your data was taken. Practical first steps include:
- Monitor financial and email accounts for unusual activity.
- Enable multi-factor authentication on important services.
- Be sceptical of unexpected messages that reference the company or the breach.
- Request a free exposure scan of your email address against known breach datasets to see whether your information has already appeared in public dumps.
Official confirmation from IM Cannabis or relevant authorities would provide clearer guidance; until then, these baseline measures remain the most reliable response available to individuals.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Ma’agan Michael Kibbutz Listed by handala Ransomware GroupNiflaot Hatzuna Ltd Listed by handala Ransomware GroupKibbutz Almog Listed by handala Ransomware GroupReutone Listed by handala Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the IM Cannabis Listed by handala Ransomware Group →
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.