Israel’s fuel supply system Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Israel’s fuel supply system was listed by the Handala ransomware group on 14 June 2025, with internal files reported to have been exfiltrated. Individuals connected to the organisation are advised to verify whether their information has been exposed and to take appropriate protective steps.
When a country’s fuel supply infrastructure appears on a ransomware group’s leak site, the stakes are immediate and practical. People who work at stations, depots, logistics firms or related offices may find personal or work-related records circulating. Drivers, suppliers and even households that rely on those networks can face secondary risks if operational details or contact data are among the material claimed to have been taken. Public detail remains limited, yet the listing itself is enough to warrant careful attention from anyone connected to Israel’s fuel sector.
On 14 June 2025 the group known as handala publicly listed “Israel’s fuel supply system,” asserting that Delkol and Delek had been compromised and that more than two terabytes of internal material had been removed. The number of people affected is unknown, and independent confirmation of the claim has not been published. What follows is a factual account of what is known, what remains unverified, and what practical steps matter most for those who may be involved.
What happened
According to the listing posted by handala, the group claims to have conducted a ransomware attack against entities it identifies as Delkol and Delek, part of Israel’s fuel supply system. The group states that internal files were exfiltrated and that “over 2 terabytes of classified data are no longer in your hands.” It further asserts that fuel stations are vulnerable and urges immediate action. The reported date of the listing is 14 June 2025. No independent verification of the intrusion, the volume of data, or the precise systems affected has been released in the available record. The number of individuals whose information may be involved is listed as unknown. Method of initial access, encryption status of systems, and any ransom demand details are undisclosed.
Inside handala
Handala is a pro-Palestinian hacktivist collective that has operated publicly since at least 2023–2024. The group typically claims responsibility for cyber operations against Israeli government, military and commercial targets, often publishing stolen data on dedicated leak sites or messaging channels. Its tactics commonly combine data theft with public pressure campaigns; ransomware-style encryption is sometimes asserted alongside pure data-leak threats. Prior activity has included claims against Israeli infrastructure, technology firms and public institutions. The group’s statements are frequently framed in political terms and are presented as claims rather than independently audited findings. In this case, the listing of Israel’s fuel supply system and the accompanying language about Delkol, Delek and two terabytes of data should be treated as handala’s unverified assertion until corroborated by the organisations themselves or by forensic reporting.
Who is Israel’s fuel supply system?
Israel’s fuel supply system encompasses the network of companies, depots, pipelines, retail stations and logistics operators that import, refine, store and distribute petroleum products across the country. Delek is a well-known Israeli energy conglomerate with interests in fuel retail, refining and related infrastructure; Delkol appears in the group’s claim as a related or affiliated entity. Organisations of this type routinely hold operational data (inventory levels, station locations, delivery schedules), employee and contractor records, supplier contracts, and sometimes security or contingency plans. Because fuel distribution underpins transport, emergency services and military logistics, any confirmed compromise of such systems carries wider national-security and economic implications beyond ordinary commercial data loss. The precise corporate structure and the exact entities involved in the claimed incident remain as described only in the handala listing.
What was likely exposed
The available facts state that internal files were exfiltrated in a ransomware attack. Handala further claims that more than two terabytes of “classified data” were taken and that fuel-system secrets and station details are exposed. Exact file names, data categories and whether personal identifiers of employees, customers or contractors are included have not been independently confirmed. Organisations operating national fuel infrastructure typically maintain employee directories, access credentials, maintenance logs, supplier invoices, geospatial data on depots and stations, and internal communications. Any of these could theoretically appear in an exfiltration, yet the precise contents of the claimed two-terabyte set remain unconfirmed. Readers should therefore treat specific assertions about “classified” material or operational vulnerability as the group’s claim rather than established fact.
The real-world impact
If the claimed data set includes personal or contact information, affected individuals face the ordinary risks of phishing, identity misuse or targeted social engineering. Employees and contractors may receive fraudulent messages that reference internal systems or fuel-station operations. For the organisations themselves, exposure of operational schedules or station details could, in theory, assist physical or further cyber reconnaissance, though no public evidence of such follow-on activity has been reported. National fuel continuity is a strategic concern; even temporary disruption or loss of confidence in supply logistics can affect transport, aviation and emergency response. Because the scale of personal data involvement is unknown, the most immediate risk for ordinary people is opportunistic fraud rather than confirmed mass identity theft. The organisations named in the claim have not publicly detailed remediation steps or confirmed the breach in the available record.
Were you affected?
If you work for, contract with, or regularly interact with Israel’s fuel distribution companies, treat any unexpected email, call or message that references internal systems or urgent “fuel security” matters with caution. Change passwords on work and personal accounts that may have been used on corporate devices, enable multi-factor authentication where available, and monitor financial and email accounts for unusual activity. Because the number of people affected remains unknown and the exact data types are unconfirmed, there is no public notification list to consult. As a practical next step, you can run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; such a scan will not confirm or deny involvement in this specific incident, but it can surface other exposures that require attention. Stay alert for official statements from the companies themselves rather than relying solely on the group’s claims.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Israel Fuel System Listed by handala Ransomware GroupIsrael’s fuel supply system Data Listed by handala Ransomware GroupIsrael Opportunity Energy Listed by handala Ransomware GroupBibi Gate: The Gatekeeper’s Fall | Tzachi Braverman Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.