On June 14, 2025, the Handala ransomware group listed Israel’s fuel supplier Delek and its subsidiary Delkol on its leak site, claiming to have stolen more than 2 terabytes of internal files from the companies that operate a significant portion of the country’s fuel distribution network.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Israel’s fuel supply system
Get alerted the next time Israel’s fuel supply system files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Israel’s fuel supply system’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates the attackers gained access to Delek and Delkol systems and exfiltrated large volumes of internal documents. The data includes operational files that could reveal fuel station layouts, supply chain logistics, and potentially sensitive corporate information. The Handala leak page, hosted on an onion site and tracked by ransomware.live, displayed samples and announced the breach with a countdown timer typical of extortion campaigns. No exact number of individuals whose personal data may have been exposed has been confirmed, yet anyone whose records passed through these corporate systems could be affected. Available reporting describes the incident as a classic ransomware double-extortion play: encrypt systems where possible and threaten to publish stolen data unless a ransom is paid.
Why This Matters for You and Your Family
When fuel suppliers are hit, the consequences reach far beyond corporate boardrooms. Delek and Delkol manage networks of gas stations, logistics fleets, and customer loyalty programs that store names, addresses, payment details, and vehicle information. If any of those records were included in the 2 terabytes of exfiltrated data, your family’s everyday transactions could become ammunition for identity thieves. A single leaked loyalty card linked to your home address can give criminals the starting point they need to build a full profile. Children’s after-school sports schedules, family travel plans, and even medical appointment reminders sometimes sit inside corporate calendars or shared drives; once those appear on dark-web forums, the risk of harassment or targeted scams increases sharply.
The Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one company. Criminals scan stolen spreadsheets for email addresses, phone numbers, and employee names, then cross-reference them against breached gaming platforms, social media, and data-broker sites. A fuel-company employee’s work email tied to a child’s Roblox or Fortnite account can create a direct path to doxxing. Public reporting shows these chains often lead to swatting, blackmail, or account takeovers that affect the entire household. Credential leaks like this one cascade quickly: a reused password from a corporate portal ends up on a child’s gaming login, exposing the whole family to harassment and financial fraud.