LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Israel Job Info Ltd Listed by handala Ransomware Group

HIGH severityUnverified claimHow we verify

Israel Job Info Ltd Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 23, 2025
Israel Job Info Ltd Listed by handala Ransomware Group

Reported June 23, 2025.

HIGH
Severity
June 23, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Israel Job Info Ltd was listed by the handala ransomware group on June 23, 2025, after internal files were exfiltrated in a ransomware attack affecting an undisclosed number of individuals. Anyone who has shared personal or professional information with the company should review their accounts and monitor for suspicious activity.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Israel Job Info Ltd, an employment-related firm, was listed by the handala ransomware group on or around June 23, 2025. Public reporting indicates the group claimed to have conducted a ransomware attack that involved the silent extraction of internal files. The number of people affected remains unknown, and independent confirmation of the full scope is limited. The listing matters because organisations of this type typically handle sensitive personal and professional records that, if exposed, can create lasting risks for individuals seeking work and for the firm itself.

What is known so far rests largely on the group’s own statements and the public notice of the listing. Exact technical details of how access was obtained, the precise timeline of the intrusion, and verified totals of compromised records have not been independently disclosed.

Inside the incident

According to the reported summary accompanying the listing, handala asserted that it had hacked Israel Job Info Ltd and extracted 419 gigabytes of data. The group described the material as including names, resumes, contracts and communications, characterising the firm as a key employment entity and claiming the files had been “archived elsewhere.” The facts identify the event as a ransomware attack involving exfiltration of internal files. No further public detail has been provided on the initial access method, whether encryption was deployed against operational systems, any ransom demand, or whether the organisation has acknowledged the incident. The number of individuals whose information may have been involved is listed as unknown. Timing beyond the June 23, 2025 reporting date is undisclosed.

The group behind it: handala

Handala is a publicly documented threat actor that has repeatedly targeted Israeli organisations and entities perceived as linked to the Israeli state or economy. The group typically combines ransomware-style data theft with politically charged messaging, often publishing claims on leak sites and framing operations as resistance rather than pure financial crime. Its known pattern includes silent exfiltration of large data volumes followed by public listings that emphasise ideological motives. Prior activity attributed to handala has focused on Israeli government-adjacent, commercial and infrastructure targets, with data dumps used both for pressure and for propaganda. In this case the group claims responsibility for the Israel Job Info Ltd listing and supplies the 419-gigabyte figure and the description of the files; those assertions remain the group’s claims rather than independently verified findings.

Who is Israel Job Info Ltd?

Israel Job Info Ltd operates in the employment and recruitment sector in Israel. Firms of this kind commonly serve as intermediaries between job seekers and employers, maintaining databases of candidate profiles, curricula vitae, contact details, employment contracts and internal correspondence. Such organisations frequently act as gateways to labour-market opportunities and therefore accumulate substantial volumes of personal and professional information over time. A breach involving an employment platform is consequential because the data held is both personally identifying and economically sensitive; it can reveal career histories, contact networks and contractual relationships that remain useful to malicious actors long after the initial incident.

What was likely exposed

The facts state that internal files were exfiltrated in a ransomware attack. The handala listing claims the extracted material comprised 419 gigabytes and specifically names resumes, contracts, communications and related records. Exact contents and the full inventory of data types have not been independently confirmed or itemised in public reporting. Organisations in the employment sector typically store names, contact information, work histories, educational details, contractual documents and internal messages. Whether any of those categories were present in the claimed archive, and in what volume, remains unconfirmed beyond the group’s statements. The number of affected individuals is unknown.

Why it matters

For individuals whose information may have been taken, the practical risks include targeted phishing, identity misuse, and social-engineering attempts that leverage accurate employment or contact details. Resumes and contracts can supply enough personal context for convincing fraud or for further reconnaissance. For the organisation, the incident raises operational, legal and reputational questions: potential regulatory notification duties, the need to assess residual access, and the longer-term challenge of restoring confidence among candidates and partner employers. Because the scale of personal impact is still unknown, the full extent of harm cannot yet be measured, but the combination of sensitive professional data and a politically motivated actor increases the likelihood that any exposed material will be examined and possibly redistributed.

Were you affected?

If you have ever submitted a resume, registered an account, or entered into a contract with Israel Job Info Ltd, treat the possibility of exposure seriously until more definitive information appears. Change passwords on any related accounts, enable multi-factor authentication where available, and remain alert for unsolicited messages that reference your employment history or personal details. Monitor financial and identity-protection services for unusual activity. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Official statements from the company or relevant authorities, when issued, should be followed for any further recommended steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyIsrael Job Info Ltd security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Israel Job Info Ltd’s full breach history →

More recent breaches

Ivri, Kerner & Co Listed by handala Ransomware GroupJuly 2, 2025Ben Horin & Alexandrovitz Ltd Listed by handala Ransomware GroupJune 22, 2025Bibi Gate: The Gatekeeper’s Fall | Tzachi Braverman Listed by handala Ransomware GroupDecember 28, 2025Operation Octopus: Naftali Bennett Listed by handala Ransomware GroupDecember 17, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Israel Job Info Ltd Listed by handala Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by handala — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram