Unverified threat-actor claim — not a regulatory filing
Attribution, victim identity, and counts shown here derive from a threat actor's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Unverified claim. Posted to a leak site Mar 11, 2026 by Handala; no regulatory filing has corroborated it yet.
incident inc_385373a8830040db · merge_method human · confidence 100%
Litigation Timing
Filing span
4days
Time between earliest and latest filing
Not recorded for this incident
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no SEC 8-K in this cluster; needs two dated filings.
Leak SiteUnverified claimLifecycle stage 1 of 3: Unverified claimUnverified claimConfirmedEnforced
Affected (total reported)
41
Data types
—
Jurisdictions
1
Linked filings
2
all Leak Site
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
🌐GLOBALClaimed by HandalaFirst sightinglinked via operator-confirmed · 100%
We announce to the world that, in retaliation for the brutal attack on the Minab school and in response to ongoing cyber assaults against the infrastructure of the Axis of Resistance, our major cyber operation has been executed with complete success. The Zionist-rooted corporation, Stryker, one of the key arms of the global Zionist lobby...
🌐GLOBALClaimed by HandalaMost recentlinked via operator-confirmed · 100%
Today, for the first time, we proudly release the documentation of a unique cyber operation, an operation that will etch the name Handala Hack into the minds of all players in the global cybersecurity arena. In a swift and calculated attack, we succeeded in penetrating the deepest layers of the network belonging to the medical...
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.