List of Spacecom employees Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
A list of Spacecom employees was published by the Handala ransomware group on September 28, 2025, after internal files were taken in a ransomware attack. Anyone who has worked with or been employed by Spacecom should review the published data and consider protective steps if their information appears.
Ransomware groups and hacktivist actors continue to target aerospace and satellite operators, treating employee directories and internal files as high-value leverage in an era of persistent data-exfiltration campaigns. Against that backdrop, a listing attributed to the handala ransomware group appeared on 28 September 2025, claiming that a roster of Spacecom employees and related internal material had been taken.
Public detail remains limited: the number of people affected is unknown, and independent confirmation of the breach itself has not been released. What is known is that handala publicly listed “List of Spacecom employees” and asserted that internal files had been exfiltrated in a ransomware attack. For anyone whose contact details may appear in such a file, the claim alone is enough to warrant careful attention.
Breaking down the breach
According to the group’s own leak-site entry dated 28 September 2025, handala claims to have obtained and listed a collection of Spacecom employee contact information together with other internal files. The listing characterises the material as having been exfiltrated during a ransomware attack. No technical indicators of compromise, no confirmed intrusion vector, and no verified file volume have been disclosed by Spacecom or by independent investigators. The number of individuals whose data may be involved is listed as unknown. The group’s accompanying text invites readers to download the employee list and contact staff directly, but that language is promotional claim rather than verified fact. Until Spacecom or a competent authority issues a statement, the incident rests solely on the group’s unverified assertion.
Who is handala?
Handala is a publicly documented pro-Palestinian hacktivist collective that has repeatedly claimed responsibility for data leaks and ransomware-style operations against Israeli commercial and government-linked entities. The group typically operates by posting victim names and sample files on dedicated leak sites, often framing the releases as political pressure rather than pure financial extortion. Its tactics commonly include the theft of internal documents, employee directories and operational data, followed by public taunting and free distribution of the material. Prior listings have targeted a range of Israeli firms in technology, defence-adjacent and infrastructure sectors. In the present case, handala’s claim that it holds Spacecom employee data should be treated as an unverified assertion pending corroboration; the group has not released independently verified proof of the full dataset.
List of Spacecom employees and its sector
Spacecom is an Israeli satellite-communications operator that manages geostationary satellites providing broadband, broadcast and government connectivity services across multiple continents. Organisations of this type routinely maintain detailed employee directories, contractor lists, internal operational documents and technical configuration data. Because satellite operators sit at the intersection of commercial telecommunications and national-security-relevant infrastructure, any unauthorised release of staff contact details or internal files can create both personal-privacy and operational-security concerns. The listing of an employee roster therefore carries weight beyond ordinary corporate data loss: it potentially exposes individuals who work on systems that keep satellites in orbit and that support critical communications links.
What data was at risk
The only data types named in the available record are “internal files exfiltrated in ransomware attack,” specifically framed by the group as a downloadable list of Spacecom employees. Exact contents—names, email addresses, phone numbers, job titles, or any additional documents—are not independently confirmed. Organisations in the satellite-communications sector typically hold personnel records, access credentials, network diagrams and project documentation; whether any of those categories appear in the claimed dump remains unconfirmed. Public detail on the precise scope is therefore limited to the group’s assertion that employee contact information and related internal material were taken.
What's at stake
For individuals whose details may appear in the claimed list, the immediate risks are targeted phishing, social-engineering attempts and unwanted contact. Attackers who possess verified work email addresses and phone numbers can craft convincing messages that reference real colleagues or satellite operations, increasing the chance of credential theft or malware delivery. For Spacecom itself, the exposure of internal files—if the claim proves accurate—could reveal organisational structure, project timelines or technical details useful to further intrusion attempts. Reputation and customer trust may also be affected simply by the public listing, regardless of the ultimate verification of the data. Because the number of people affected remains unknown, the full scale of personal and operational impact cannot yet be quantified.
What to do if you're exposed
Anyone who works or has worked at Spacecom, or who has reason to believe their contact details appear in the claimed material, should take the following practical steps:
- Treat unsolicited emails, calls or messages that reference Spacecom operations with heightened scepticism; verify any request through a known, out-of-band channel.
- Change passwords on work and personal accounts that share the same credentials, and enable multi-factor authentication wherever it is available.
- Monitor financial and credit accounts for unusual activity and consider placing a fraud alert if sensitive personal data may have been included.
- Preserve any suspicious communications for possible later reporting to company security or law-enforcement contacts.
- Run a free exposure scan of your email address against known breach datasets to check whether your information has already surfaced in public dumps.
These measures do not require confirmation that the handala listing is authentic; they are standard hygiene when any credible claim of employee-data exposure appears. Official guidance from Spacecom, if and when it is issued, should take precedence over third-party advice.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Plonter Listed by handala Ransomware GroupAmos Spacecom Listed by handala Ransomware GroupVynopsis Listed by handala Ransomware GroupClockWorkAdmin Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.