Iran International
bd_1f0728e093b32a25 · schema v1 · pii pii-v1
Full breach record for Iran International →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Handala on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Iran International has been successfully hacked. All of the network’s systems, servers, and communication infrastructure have been fully compromised and infected. A complete internal data dump has been extracted. This includes: Confidential internal and external communications Personal and security details of staff members Identities and contact logs of media liaisons Bank records, financial contracts, and...
Source provenance
- Source URL
- https://www.ransomware.live/id/SXJhbiBJbnRlcm5hdGlvbmFsQGhhbmRhbGE=
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2025
- Raw hash
- 3a9b051ffa5f9520815c5774567dd2121bd76ba960a86d33c1a1e4e863a35cce
Reporting entity
- Name
- handala
Victim entity
- Name
- Iran Internationalnorm: iran international
- Industry
- Telecom & Mediallm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· handala
- Threat actor
- HandalaExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.