Saban Systems Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Saban Systems was listed on June 19, 2025, by the handala ransomware group, which claims to have exfiltrated internal files from the organization. Anyone connected to Saban Systems should check whether their information may have been affected and take protective steps.
On 19 June 2025, the ransomware group handala listed Saban Systems on its leak site and claimed to have carried out a ransomware attack that included the exfiltration of internal files. The number of people whose information may have been involved remains unknown, and public detail about the precise contents of those files is limited. For anyone who has dealt with the company—employees, contractors, partners, or individuals whose details may appear in operational records—the practical stakes are straightforward: once internal material leaves an organisation’s control, it can be examined, shared, or misused in ways that create lasting personal and professional risk.
Because the scale and exact nature of the exposure have not been independently confirmed, people connected to Saban Systems have little choice but to treat the claim seriously and take basic protective steps while waiting for clearer information.
Breaking down the breach
According to the listing reported on 19 June 2025, handala asserts that it compromised Saban Systems and removed internal files as part of a ransomware attack. No further technical details—such as the initial access method, the duration of the intrusion, the volume of data taken, or any ransom demand—have been made public. The number of individuals affected is listed as unknown. The only data category named is “internal files.” Beyond the group’s own claim on its leak site, independent verification of the incident has not been published, so the listing itself remains an unverified assertion rather than a confirmed forensic finding.
Who is handala?
Handala is a pro-Palestinian threat actor that has operated since at least 2023–2024, primarily targeting Israeli organisations and entities it views as linked to Israeli security or government activity. The group typically combines ransomware encryption with data theft, then posts victim names and sample files on a dedicated leak site to increase pressure. Its public statements often frame attacks in political terms rather than purely financial ones. Handala has previously claimed responsibility for breaches against a range of Israeli companies and infrastructure-related firms. In this case, the group claims Saban Systems was compromised and that internal files were exfiltrated; those claims have not been independently corroborated in the available reporting.
Who is Saban Systems?
Saban Systems is an Israeli technology firm that, according to the material accompanying the handala listing, has become involved in the country’s surveillance infrastructure. The reported summary states that the company has worked through agreements with Shin Bet, Israel’s internal security agency, on the deployment of high-grade surveillance cameras across public and classified sectors under an operation referred to as “Silent Horizon.” Organisations of this type typically handle technical specifications, deployment records, access credentials, project documentation, and communications with government and commercial partners. A breach at such a firm is consequential because the data it holds can touch both commercial operations and sensitive security-related work, raising the possibility that operational details or personal information of staff and associates could be exposed.
What data was at risk
The only category of data named in connection with the incident is internal files said to have been exfiltrated during the ransomware attack. No inventory of specific file types, databases, or personal-data fields has been released. Organisations working in surveillance and security technology commonly store employee records, contractor details, project plans, network diagrams, camera configurations, correspondence with government agencies, and financial or contractual documents. Whether any of those categories were among the files handala claims to hold is unconfirmed. Public detail on the exact contents therefore remains limited, and no definitive list of exposed data types can be stated as fact.
The real-world impact
For individuals whose information may appear in the internal files, the immediate risks include identity misuse, targeted phishing, or unwanted contact if names, contact details, or identification numbers were present. Employees and contractors could face secondary risks if work-related credentials or personal identifiers surface. For Saban Systems itself, the exposure of internal material can disrupt operations, damage trust with partners and government clients, and create longer-term security and reputational costs. Because the company is described as operating in a sensitive surveillance domain, any leak of technical or operational documents could also have broader implications for the systems and locations those documents describe. The absence of confirmed numbers or a detailed data inventory means the full extent of these risks cannot yet be measured; the prudent course is to assume that material of potential value to adversaries or criminals may have left the organisation’s control.
Were you affected?
If you have worked for, contracted with, or supplied personal information to Saban Systems, treat the claim as a prompt for caution. Change passwords on any accounts that reused credentials linked to the company, enable multi-factor authentication wherever available, and monitor financial and email accounts for unusual activity. Be sceptical of unexpected messages that reference the company or request sensitive information. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Until more definitive information is released by the organisation or independent investigators, these basic steps remain the most practical protection available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Plonter Listed by handala Ransomware GroupAmos Spacecom Listed by handala Ransomware GroupAgura B.C LTD Listed by handala Ransomware GroupBibi Gate: The Gatekeeper’s Fall | Tzachi Braverman Listed by handala Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Saban Systems Listed by handala Ransomware Group →
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.