Leaked Documents Reveal Identities of Iran International Staff Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Iran International disclosed on July 09, 2025 that internal files had been exfiltrated in a ransomware attack, and that the handala group had published the identities of some of its staff. Anyone who works or has worked for the organisation should review the leaked material and take appropriate security precautions.
In today's threat landscape, media organisations that report on authoritarian regimes face persistent cyber pressure from politically motivated actors who blend ransomware with public data dumps. These campaigns aim less at pure financial gain and more at intimidation, disruption of operations, and exposure of personnel. Against that backdrop, a listing that appeared on 9 July 2025 has drawn attention to Iran International.
The handala ransomware group claims to have exfiltrated internal files from the broadcaster and to have published material that reveals the identities of staff members. The number of people affected remains unknown, and independent confirmation of the full scope is still limited. For an outlet whose journalists and producers often work under heightened personal risk, any such claim warrants careful public scrutiny.
Breaking down the breach
Public reporting dated 9 July 2025 states that Iran International was listed by the handala ransomware group after an attack in which internal files were exfiltrated. The group asserts that the material includes documents identifying staff. No verified figure for the volume of data, the precise date of intrusion, or the technical method beyond the ransomware characterisation has been released. The number of individuals potentially affected is recorded as unknown. Available summaries quote the group naming specific individuals and describing their alleged roles, but these statements remain claims posted on the group's leak site rather than independently audited findings.
Because the incident is framed as a ransomware event accompanied by data theft, the core allegation is that files left the organisation's systems and were later offered for public view. Beyond that outline, operational details such as initial access vector, dwell time, or encryption status of remaining systems have not been disclosed in the material provided.
Who is handala?
Handala is a publicly documented threat actor that has repeatedly claimed responsibility for ransomware and data-leak operations against organisations it portrays as hostile to Iranian interests. The group typically operates a leak site on which it posts victim names, sample files, and political messaging. Its tactics commonly combine network intrusion, data exfiltration, and the threat or reality of public release, often framed as retaliation rather than pure extortion. Prior activity has focused on media, research, and government-adjacent targets, with an emphasis on naming individuals and releasing internal documents to amplify pressure. In the present case the group claims to have listed Iran International and to have exposed staff identities; those assertions should be treated as unverified claims until corroborated by forensic or official sources.
About Iran International
Iran International is a Persian-language news organisation that provides independent coverage of Iranian affairs to audiences inside and outside the country. Like other international broadcasters operating in contested information environments, it maintains editorial, production, and administrative staff whose work can place them at elevated personal risk. Organisations of this type routinely hold personnel records, internal communications, editorial planning documents, and contact databases. A breach that surfaces such material is consequential because it can compromise the safety of journalists, sources, and support staff who already face surveillance and harassment risks linked to their reporting.
What data was at risk
The available facts state only that internal files were exfiltrated in a ransomware attack. No exhaustive inventory of file types, databases, or personal data categories has been published. Organisations in the media sector typically store employee identification details, contact information, internal correspondence, and operational documents. Whether any of those categories were present in the material claimed by handala remains unconfirmed. The group's own posts refer to documents that allegedly identify staff members, including named individuals described in political terms, yet the precise contents and authenticity of those files have not been independently verified in the public record.
The real-world impact
For people whose names or roles may appear in the released material, the primary risks are doxxing, targeted harassment, and potential physical threats, especially for those with family or professional ties inside Iran. Even partial identity exposure can enable social-engineering attempts or pressure campaigns against relatives. For the organisation itself, the incident raises concerns about operational continuity, source protection, and the need to reassess access controls and staff-security protocols. Because the scale of the leak is unknown, the full extent of these risks cannot yet be quantified; the absence of a confirmed headcount leaves both individuals and the broadcaster in a state of incomplete information.
Reputational and trust effects are also possible. Audiences and contributors may question how securely sensitive material is handled, while staff may experience heightened anxiety about future targeting. These outcomes are typical of politically motivated data-leak campaigns and do not require any assumption of organisational negligence to be taken seriously.
If your data was in this claimed breach
Anyone who believes their information may have been involved should begin with basic protective steps: change passwords on work and personal accounts that share credentials, enable multi-factor authentication where available, and monitor for unusual login attempts or phishing messages that reference the organisation. Review privacy settings on social media and consider limiting publicly visible personal details. If you receive direct threats or harassment, document the contact and report it to relevant authorities or the organisation's security team. Because the exact data set remains unconfirmed, a free exposure scan of your email address against known breach corpora can help determine whether your details have already appeared in other public dumps and can guide further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
No Place to Hide: Unmasking the Masterminds Behind War Drones Listed by handala Ransomware GroupThe Day of Reckoning Awaits the Child-Killers Listed by handala Ransomware GroupThe 200,000 Message Bombshell: Bennett’s Game is Over Listed by handala Ransomware GroupCaught by the Octopus: Bennett’s Darkest Hour Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.