Iran Internation WhatsApp and Internal Access Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Iran International disclosed a ransomware attack by the handala group on July 09, 2025, in which internal files were exfiltrated; the date of the intrusion is not established. Individuals should review any communications from the organisation and take recommended security steps if their information may have been involved.
On 9 July 2025 a ransomware group known as handala publicly listed Iran International, claiming it had obtained WhatsApp access and broader internal systems. The number of people affected remains unknown, and the precise contents of any stolen material have not been independently confirmed. For journalists, sources, staff and contacts whose details may sit inside those systems, the practical stakes are immediate: exposure of communications or internal files can create personal risk, especially for an organisation that reports on Iran from outside the country.
Public detail is limited to the group’s own leak-site claims and a short accompanying statement. What is known so far is that handala asserts long-term presence and the exfiltration of internal files. That claim alone is enough to warrant careful attention from anyone who has interacted with the organisation.
Inside the incident
According to the listing dated 9 July 2025, handala states that it compromised Iran International’s WhatsApp access and internal systems and exfiltrated internal files in a ransomware attack. The group’s own message asserts that access lasted 31 months and that early assumptions about a limited Telegram compromise were incorrect. No independent confirmation of the duration, the method of initial entry, or the full scope of systems reached has been published. The number of individuals whose data may be involved is listed as unknown. Beyond the group’s statements, technical indicators, ransom demands or proof-of-compromise samples have not been disclosed in the available record.
Inside handala
handala is a publicly documented threat actor that has repeatedly claimed ransomware and data-theft operations against media, government-linked and commercial targets, frequently framing its activity in political terms. The group typically posts victim names and sample claims on its leak site, often asserting prolonged network presence and the theft of internal documents. In this case the listing of Iran International is presented as a claim by the group; it has not been independently verified in the facts available. handala’s public messaging style commonly mixes technical assertions with political rhetoric, and its prior activity has included similar long-dwell-time claims against other organisations. No further specifics about tools, infrastructure or confirmed success against this particular victim are contained in the record.
Iran International and its sector
Iran International is a Persian-language news organisation that operates outside Iran and provides independent coverage of Iranian affairs. Media organisations of this type routinely hold staff directories, source contact lists, editorial planning documents, internal messaging archives and technical credentials for production and distribution systems. Because the outlet’s reporting frequently involves sensitive political subjects, the confidentiality of those materials is operationally important both for the safety of contributors and for the continuity of the news service. A claimed breach that includes messaging platforms and internal files therefore carries sector-specific consequences beyond ordinary corporate data loss.
The information in question
The facts name the exposed material only as “internal files exfiltrated in a ransomware attack,” together with the group’s assertion of WhatsApp and broader internal access. Exact data types, file volumes and whether personal identifiers, source lists or credentials were included remain undisclosed. Organisations in this sector typically store employee records, contact databases, editorial correspondence and system credentials; any of those categories could theoretically be present, yet none can be stated as confirmed fact. Public detail on the precise contents is therefore limited to the group’s unverified claims.
The real-world impact
For individuals whose information may have been taken, the concrete risks include unwanted contact, social-engineering attempts that reference genuine internal details, and, in high-risk reporting environments, potential physical or legal pressure. For the organisation itself, the claimed loss of messaging access and internal files can disrupt editorial workflows, force credential resets across multiple platforms, and require reassessment of source-protection practices. Because the scale of affected people is unknown and the exact data unconfirmed, the full extent of these effects cannot yet be measured; the prudent assumption is that any staff member, freelancer or regular contact should treat the possibility of exposure seriously until clearer information emerges.
If your data was in this claimed breach
If you have worked with, contributed to or regularly communicated with Iran International, treat the handala claims as a prompt for basic hygiene rather than confirmed personal compromise. Practical first steps include:
- Changing passwords and enabling multi-factor authentication on any accounts that may have been linked to the organisation’s systems or messaging apps.
- Reviewing recent login alerts and active sessions on email, cloud storage and messaging platforms for unfamiliar activity.
- Being alert to unexpected messages that reference internal projects or personal details, and verifying them through a second channel before responding.
- Considering a free exposure scan of your email address against known breach datasets to check whether your information has already appeared in public dumps.
These measures do not prove or disprove involvement in this specific incident, but they reduce the most common follow-on risks while further facts remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
099 ISP Listed by handala Ransomware GroupIgnite Chaos at Your Own Risk: i24 Channel Listed by handala Ransomware GroupBraverman Files Unleashed: Every Secret Now Exposed Listed by handala Ransomware GroupBibi Gate: The Gatekeeper’s Fall | Tzachi Braverman Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.