Amos Spacecom Listed by handala Ransomware Group
If you are a customer of Amos Spacecom, here’s what is being claimed, and what it would mean for you.
We, the Handala Hack, have successfully breached the security systems of Spacecom (Space Communication Ltd.), the operator of the critical AMOS satellite network. Every piece of sensitive information, including military, governmental, and security data transmitted and stored within their infrastructure, is now fully in our possession. Spacecom’s AMOS satellites serve a wide array of functions,…
— from Handala’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Amos Spacecom customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On September 27, 2025, the Handala ransomware group publicly listed Spacecom, the operator of Israel’s AMOS satellite network, claiming full access to sensitive internal files including military, governmental, and security data transmitted and stored on its infrastructure.
What's Publicly Reported from Reporting
Public reporting indicates the Handala Hack group states it breached Spacecom’s security systems and exfiltrated every piece of sensitive information held within the AMOS satellite network. The announcement appeared on the group’s leak site, hosted on an onion domain and mirrored by ransomware tracking services such as ransomware.live. No exact victim count has been disclosed, and the precise volume or specific documents exposed remains unconfirmed by independent sources. Spacecom has not yet issued a public statement detailing the incident or confirming the claims.
The exposed material is described by the attackers as including data that passed through or was stored on the AMOS satellites, which provide communication services across government, military, and commercial sectors. As of the listing date, the group had not published sample files or set an explicit public extortion deadline, though ransomware actors routinely use such listings to pressure victims into negotiation.
Why This Matters for You and Your Family
When critical communications infrastructure is breached, the consequences reach far beyond the company itself. If military, governmental, or security data was truly taken, downstream risks can include identity theft, targeted phishing, and physical safety threats for anyone whose personal information touched those systems. Ordinary families who rely on satellite-dependent services for internet, phone, or emergency communications may find their data indirectly exposed through government or contractor records.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Credential leaks from such incidents frequently appear in later dumps. Once an email, password, or API key escapes, it can be used to compromise personal accounts that have nothing to do with satellites. Your family’s email, banking logins, or children’s online accounts become targets when one reused password surfaces in a high-value breach like this.
The Doxxing and Identity-Chain Implications
Ransomware groups increasingly combine stolen corporate data with personal identifiers to create detailed profiles. A single leaked government or contractor record can link an employee’s work email to home address, phone number, and family members. Attackers then follow these chains across social media, gaming platforms, and data-broker sites to build full doxxing packages.
Children’s gaming accounts are especially vulnerable because kids often reuse nicknames or email addresses tied to a parent’s breached work identity. What begins as a corporate ransomware incident can cascade into harassment, swatting, or account takeovers targeting your household. Public reporting on similar incidents shows these identity chains can remain active for years after the initial breach.
Handala Group’s Publicly Known Track Record
Public reporting attributes the Handala Hack group with emerging in 2024 and focusing primarily on Israeli targets. The group has claimed responsibility for attacks on various organizations in Israel and has used its leak sites to publish stolen data when ransom demands are not met. Their typical playbook involves initial access through common vectors such as phishing or unpatched remote desktop services, followed by exfiltration of sensitive files and public shaming on dark-web leak boards. Extortion usually combines data publication threats with direct pressure on the victim organization.
What to do
- Run a DoxxScan to map every link between your emails, phone numbers, usernames, and real-world identity so you can break chains before attackers exploit them.
- Rotate any password you used at Spacecom or related government or contractor services, then enable 2FA with an authenticator app everywhere that same password was reused.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next time your information appears it is caught and addressed within hours rather than months.
- Cover the entire household with DoxxScan family protection, which includes children’s gaming accounts that frequently chain back to the same addresses or parent emails exposed in incidents like this.
- Let remediation specialists handle takedown requests across data brokers and leak sites so you do not have to negotiate directly with threat actors or spend weeks chasing removal requests yourself.
The Spacecom listing is a reminder that even infrastructure attacks can quickly become personal. Taking concrete steps now limits how far attackers can travel down the identity chain that leads to you and your family. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, and hands-on remediation by specialists who manage the entire process, including household and children’s gaming-account coverage.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Kessler Creative Listed by coinbasecartel Ransomware Group
Kessler Creative was listed on the coinbasecartel ransomware leak site. The group claims to have sto…
RXPE Group Listed by coinbasecartel Ransomware Group
RXPE Group was listed on the coinbasecartel ransomware leak site. The group claims to have stolen in…
Abacus Advisors Listed by coinbasecartel Ransomware Group
Abacus Advisors was listed on the coinbasecartel ransomware leak site. The group claims to have stol…