Passover Wiped Clean: 22TB of Data Gone from 14 Companies Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On 2 April 2026, the handala ransomware group listed 14 companies on its leak site, claiming to have taken 22 TB of internal files. The number of people potentially affected is not yet known; anyone who does business with the listed organisations should review the disclosures and follow their guidance.
On April 2, 2026, the handala group publicly listed an incident it described as “Passover Wiped Clean,” claiming that 22 terabytes of data from 14 companies had been removed. The number of individuals whose personal information may be included remains unknown, and no independent confirmation of the volume or contents has been released. For anyone whose records are held by the listed companies, the practical question is whether internal files now circulating contain identifying details that could be used for fraud, targeted scams, or further unauthorized access.
Breaking down the breach
The only confirmed public information is the date of the listing and the group’s statement that internal files were allegedly exfiltrated during a ransomware operation. No timeline for the intrusion, method of initial access, or confirmation that data were encrypted or deleted has been disclosed. The listing itself constitutes the group’s claim; no victim statement or law-enforcement verification has been reported.
Inside handala
Handala is a publicly documented threat actor that has conducted operations against organizations it associates with Israeli interests. Its typical pattern involves claiming data removal, posting political messaging timed to holidays or events, and listing victims on leak sites. Prior activity attributed to the group has included both ransomware deployment and selective publication of stolen material. In this case the group claims responsibility for a large-scale operation framed around the Passover holiday, but no additional technical details about the attack on these specific companies have been supplied.
Who is Passover Wiped Clean: 22TB of Data Gone from 14 Companies Listed by handala Ransomware Group?
The listing refers to 14 companies presented under the collective title “Passover Wiped Clean.” Public information does not identify the individual firms or their precise sector. Organizations of this description commonly maintain customer records, employee files, financial documentation, and operational correspondence. A breach affecting multiple such entities simultaneously raises the possibility that aggregated internal material from several sources is now outside the control of the original owners.
What was likely exposed
The only data type named in the available facts is “internal files exfiltrated in ransomware attack.” No inventory of file categories, no count of records, and no confirmation that personal identifiers, financial data, or communications were present have been released. While companies of this kind routinely store names, contact details, account numbers, and internal correspondence, the exact contents remain unconfirmed beyond the general description provided.
What's at stake
Individuals whose information appears in the exfiltrated files face the standard risks associated with any large-scale internal-data exposure: increased chance of identity theft, phishing, or account takeover. The organizations involved face potential regulatory scrutiny, loss of customer trust, and the operational cost of investigating and containing the incident. Because the number of affected people is still unknown, the full scope of personal impact cannot yet be measured.
What to do if you're exposed
Monitor accounts for unusual activity and enable multi-factor authentication where available. Request copies of any personal data held by the companies under applicable privacy laws. Readers can run a free exposure scan of their email address against known breach data sets to check whether their information has already appeared in public listings.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Handala Hack Strikes 27 Companies for Minab’s Innocents Listed by handala Ransomware GroupExposing Israel’s Drone Queen: The Fall of Colonel Haimovich Listed by handala Ransomware GroupRaz Zimmt’s Chats Leaked to the World Listed by handala Ransomware GroupIranWire Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.