Laura Gilinski Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Laura Gilinski was listed by the handala ransomware group on March 15, 2026, after internal files were exfiltrated in a ransomware attack. The number of individuals affected remains undisclosed; anyone who may have had dealings with the organisation is advised to monitor their accounts and change passwords where appropriate.
Breaking down the breach
The listing was reported on March 15, 2026. The only confirmed detail is that internal files were allegedly exfiltrated during a ransomware attack. No figure has been released for the number of records or individuals involved, and the method of initial access remains undisclosed.
The group behind it: handala
Handala is a ransomware operator known for targeting organizations it associates with Israeli interests. The group maintains a leak site where it posts claims of successful intrusions and sometimes releases sample data to pressure victims. In this case the group claims it has taken down “one of Mossad’s most critical intelligence figures, Laura Gilinski,” describing the action as shattering “the iron walls of secrecy” within the “Zionist regime.” Such statements are standard for the actor and serve to publicize the listing; independent verification of the underlying access has not been provided.
Laura Gilinski and its sector
Laura Gilinski is identified publicly as a former Deputy Head of Planning & Strategy at Mossad and current Deputy Director of the Institute for National Security Studies (INSS). Organizations and individuals in this sector routinely hold strategic assessments, correspondence with government bodies, personnel records, and research materials on security policy. A breach at this level is consequential because the material can intersect with the records of colleagues, external partners, and administrative staff even when the primary target is one person.
What was likely exposed
The facts state only that internal files were exfiltrated. The precise contents, file counts, and any personal data categories have not been disclosed. Entities of this type commonly maintain documents that reference names, contact details, project timelines, and internal communications; however, whether any of those categories are present in the exfiltrated material remains unconfirmed.
What's at stake
For individuals whose information appears in the files, the main risks are secondary misuse of contact data, impersonation attempts, or targeted follow-on activity. For the organization, the exposure of internal planning or correspondence can complicate ongoing work and require resource-intensive review of what was taken. Because the number of affected people is unknown, the full scope of these consequences cannot yet be measured.
What to do if you're exposed
Begin by monitoring official communications from any organization with which you have professional ties to Laura Gilinski or INSS. Enable or strengthen multi-factor authentication on all accounts that use the same email or password patterns that might appear in internal directories. Review recent financial and login activity for anomalies. Readers can run a free exposure scan of their email address against known breach data to check whether their information has already appeared in public listings from this or other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Handala Hack Strikes 27 Companies for Minab’s Innocents Listed by handala Ransomware GroupExposing Israel’s Drone Queen: The Fall of Colonel Haimovich Listed by handala Ransomware GroupRaz Zimmt’s Chats Leaked to the World Listed by handala Ransomware GroupPassover Wiped Clean: 22TB of Data Gone from 14 Companies Listed by handala Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Laura Gilinski Listed by handala Ransomware Group →
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.