LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Saturday Unveilings – Shadows Have Names Listed by handala Ransomware Group

HIGH severityUnverified claimHow we verify

Saturday Unveilings – Shadows Have Names Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 25, 2025
Saturday Unveilings – Shadows Have Names Listed by handala Ransomware Group

Reported October 25, 2025.

HIGH
Severity
October 25, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Saturday Unveilings – Shadows Have Names has been listed by the handala Ransomware Group, with internal files exfiltrated during the attack. The incident was disclosed on October 25, 2025; individuals are advised to check whether their data was exposed and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On October 25, 2025, the ransomware group handala publicly listed an entry titled “Saturday Unveilings – Shadows Have Names.” The group claims to have drawn six new names from what it describes as high-ranking engineers, architects of Israel’s air and naval power, individuals linked to the Weizmann Institute’s covert operations, and nuclear scientists. Public detail remains limited: the number of people affected is unknown, and the only data type confirmed in available reporting is internal files said to have been exfiltrated in a ransomware attack. The listing itself is a claim by the group and has not been independently verified in the provided facts.

Because the entry focuses on named individuals rather than a conventional corporate victim, the incident raises questions about personal exposure of people working in sensitive technical and research roles. Exact scope, timing of any intrusion, and confirmation of the files’ contents are undisclosed.

Inside the incident

Available reporting states only that handala listed the “Saturday Unveilings – Shadows Have Names” entry on October 25, 2025, and that the group asserts internal files were exfiltrated during a ransomware attack. The accompanying summary language claims six new names have been selected: high-ranking engineers, architects of Israel’s air and naval power, minds behind Weizmann Institute covert operations, and nuclear scientists. No further technical details—such as the date of any intrusion, the method used, the volume of data taken, or whether encryption was applied—are provided in the facts. The number of people affected is listed as unknown. All specifics beyond the group’s own leak-site language remain unconfirmed.

The group behind it: handala

handala is a ransomware and hacktivist group that has repeatedly targeted Israeli entities and individuals associated with defense, technology, and research sectors. Publicly documented activity shows the group typically combines data theft with public naming or doxxing on its leak site, often framing releases as political statements. It has previously claimed operations against Israeli organizations and personnel, using ransomware both for disruption and for the subsequent publication of stolen material. In this case the group claims the “Saturday Unveilings” listing and the exfiltration of internal files; those assertions are presented here solely as the group’s statements and have not been independently corroborated by the available facts.

Who is Saturday Unveilings – Shadows Have Names Listed by handala Ransomware Group?

The designation “Saturday Unveilings – Shadows Have Names Listed by handala Ransomware Group” refers to the title of the leak-site entry itself rather than a conventional commercial or governmental organization. According to the group’s own summary language, the entry concerns six individuals described as high-ranking engineers, architects of Israel’s air and naval power, personnel connected to the Weizmann Institute’s most covert operations, and nuclear scientists. Organizations and research bodies of this character typically hold technical designs, personnel records, research data, and security clearances. A public naming of such individuals is consequential because it can expose people who work in sensitive national-security and scientific roles to heightened personal risk, even when the precise institutional affiliation of any single file set remains unconfirmed.

What data was at risk

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, volumes, or specific personal data fields is provided. Organizations and research environments of the kind referenced in the group’s summary commonly maintain personnel files, technical documents, project records, and contact information. Because the exact contents remain undisclosed, it is not possible to confirm which categories of data—if any—were actually taken or published. Readers should treat any claim of specific data exposure as unconfirmed until independent verification appears.

What's at stake

For the named individuals, the primary risk is personal: public association with sensitive defense or nuclear research can lead to harassment, social-engineering attempts, or physical-security concerns. Family members and colleagues may also face secondary exposure if contact details or workplace information appear in any released material. For the broader research and defense communities, the incident underscores the ongoing targeting of technical talent. The organization or institutions linked to these individuals—if any files originated from them—face potential operational disruption, loss of proprietary technical knowledge, and the need to review access controls and personnel-protection measures. Because the scale of the claimed exfiltration is unknown, the full extent of these risks cannot yet be quantified.

Were you affected?

If you believe your name or professional details may appear in material related to this listing, begin by monitoring official notifications from any employer or research body with which you are affiliated. Change passwords on work and personal accounts, enable multi-factor authentication where available, and remain alert for unexpected contact that references your professional role. Because the number of people affected is unknown and the precise data set is unconfirmed, the most practical immediate step for any individual is to check whether their email address has already appeared in previously documented breach collections. Free exposure-scan services can perform that check against known public breach data and provide a starting point for further personal monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Attributed to

Method

More recent breaches

No Place to Hide: Unmasking the Masterminds Behind War Drones Listed by handala Ransomware GroupDecember 20, 2025The Day of Reckoning Awaits the Child-Killers Listed by handala Ransomware GroupDecember 19, 2025The 200,000 Message Bombshell: Bennett’s Game is Over Listed by handala Ransomware GroupDecember 18, 2025Caught by the Octopus: Bennett’s Darkest Hour Listed by handala Ransomware GroupDecember 17, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Saturday Unveilings – Shadows Have Names Listed by handala Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by handala — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram