LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Laura Gilinski Listed by handala Ransomware Group

HIGH severityUnverified claimHow we verify

Laura Gilinski Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 15, 2026
Laura Gilinski Listed by handala Ransomware Group

Reported March 15, 2026.

HIGH
Severity
March 15, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Laura Gilinski was listed by the handala ransomware group on March 15, 2026, after internal files were exfiltrated in a ransomware attack. The number of individuals affected remains undisclosed; anyone who may have had dealings with the organisation is advised to monitor their accounts and change passwords where appropriate.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

The incident involving Laura Gilinski centers on a claim by the handala ransomware group that it has accessed and listed internal files from the target. With the number of people affected still unknown and no Reported Details on the volume or sensitivity of the material, individuals connected to the organization or its networks face uncertainty about whether their information has been copied or could surface later. This type of listing matters because internal files from a national-security figure can contain references to staff, contacts, planning documents, or operational details that extend beyond the named individual. Even without public confirmation of wider distribution, the event places anyone whose records appear in those files at potential risk of follow-on misuse.

Breaking down the breach

The listing was reported on March 15, 2026. The only confirmed detail is that internal files were allegedly exfiltrated during a ransomware attack. No figure has been released for the number of records or individuals involved, and the method of initial access remains undisclosed.

The group behind it: handala

Handala is a ransomware operator known for targeting organizations it associates with Israeli interests. The group maintains a leak site where it posts claims of successful intrusions and sometimes releases sample data to pressure victims. In this case the group claims it has taken down “one of Mossad’s most critical intelligence figures, Laura Gilinski,” describing the action as shattering “the iron walls of secrecy” within the “Zionist regime.” Such statements are standard for the actor and serve to publicize the listing; independent verification of the underlying access has not been provided.

Laura Gilinski and its sector

Laura Gilinski is identified publicly as a former Deputy Head of Planning & Strategy at Mossad and current Deputy Director of the Institute for National Security Studies (INSS). Organizations and individuals in this sector routinely hold strategic assessments, correspondence with government bodies, personnel records, and research materials on security policy. A breach at this level is consequential because the material can intersect with the records of colleagues, external partners, and administrative staff even when the primary target is one person.

What was likely exposed

The facts state only that internal files were exfiltrated. The precise contents, file counts, and any personal data categories have not been disclosed. Entities of this type commonly maintain documents that reference names, contact details, project timelines, and internal communications; however, whether any of those categories are present in the exfiltrated material remains unconfirmed.

What's at stake

For individuals whose information appears in the files, the main risks are secondary misuse of contact data, impersonation attempts, or targeted follow-on activity. For the organization, the exposure of internal planning or correspondence can complicate ongoing work and require resource-intensive review of what was taken. Because the number of affected people is unknown, the full scope of these consequences cannot yet be measured.

What to do if you're exposed

Begin by monitoring official communications from any organization with which you have professional ties to Laura Gilinski or INSS. Enable or strengthen multi-factor authentication on all accounts that use the same email or password patterns that might appear in internal directories. Review recent financial and login activity for anomalies. Readers can run a free exposure scan of their email address against known breach data to check whether their information has already appeared in public listings from this or other incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyLaura Gilinski security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Laura Gilinski’s full breach history →

More recent breaches

Handala Hack Strikes 27 Companies for Minab’s Innocents Listed by handala Ransomware GroupApril 8, 2026Exposing Israel’s Drone Queen: The Fall of Colonel Haimovich Listed by handala Ransomware GroupApril 7, 2026Raz Zimmt’s Chats Leaked to the World Listed by handala Ransomware GroupApril 6, 2026Passover Wiped Clean: 22TB of Data Gone from 14 Companies Listed by handala Ransomware GroupApril 2, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Laura Gilinski Listed by handala Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by handala — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram