
Tosaf Hacked by Handala Ransomware Group
Tosaf, an industrial giant with over 5,000 employees and 60 offices worldwide, was named on the Handala ransomware data-leak site on February 2, 2025.
Key points
- Claimed by Handala ransomware group.
- Full control of Tosaf's systems.
- Initiated a full lockdown of entry points to facilities.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Feb 2, 2025
- Updated
- Jul 1, 2026
- Confidence
- High
- Evidence
- 3 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch ransomware, endpoint compromise and business interruption exposure.
Business impact
- Impact area
- Availability
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?+
Tosaf, an industrial giant with over 5,000 employees and 60 offices worldwide, was named on the Handala ransomware data-leak site on February 2, 2025. The Handala group claimed to have successfully breached and taken full control of Tosaf's systems, initiating a full lockdown of entry points and exfiltrating data.
When was this signal reported?+
Shadow Tier lists Feb 2, 2025 as the signal date.
Which organization is connected to this signal?+
Tosaf is the organization connected to this public signal.
Explore TosafWhich attack pattern is relevant?+
This signal is connected to current ransomware incidents based on its reported incident context.
Explore current ransomware incidentsRelated signals
Compare shared topics, actors and incident patterns before opening the full signal.
Healthcare AI Company Xsolis Suffers Data Breach Impacting 1.4 Million Individuals
Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information. While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals. The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519. Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”. It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts. Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolis’s hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.
Related context
Tata Electronics Data Leak Exposes Apple iPhone 18 Pro Details
India probes Tata Electronics breach exposing iPhone secrets India is investigating a data breach at Tata Electronics that reportedly exposed confidential information linked to Apple’s unreleased iPhone 18 Pro, the country’s IT secretary said on Thursday (July 3), marking the government’s first public response to the incident. Sensitive documents, including component lists, supplier details and images of the iPhone 18 Pro, were allegedly posted on the dark web by a ransomware group that targeted Tata Electronics, an Apple supplier in India, Reuters reported. “We are investigating,” said S. Krishnan, secretary at the Ministry of Electronics and Information Technology, adding that the case has been referred to India’s Computer Emergency Response Team, the national cybersecurity agency. The breach raises concerns over Apple’s tightly controlled global supply chain, where production of iPhones relies on multiple international suppliers. Apple is expected to launch the iPhone 18 Pro and Pro Max in September. The leaked files are said to include at least six documents revealing supplier assignments for specific components—information Apple does not publicly disclose. Tata Electronics has reportedly hired a global consultancy firm to carry out a forensic audit following the leak, which also allegedly involved documents related to Tesla, Qualcomm and TSMC being published on the dark web, according to Reuters. (Newswire)
Related context
DyStar Group Hit by Settra Ransomware Attack, 1.3 TB of Internal Data Exfiltrated
Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks This page displays the 100 most recent victim disclosures attributed to ransomware groups, as detected by Ransomware.live . Our platform continuously monitors and scrapes ransomware group leak sites to identify and list newly published victims. Recent Breaches › dystar.com Listed by settra Ransomware Group dystar.com Listed by settra Ransomware Group: What Was Exposed & What To Do Occurred June 2026 · publicly disclosed June 28, 2026. Dystar.com was listed by the Settra ransomware group on June 28, 2026, with internal files reported exfiltrated in the attack. An undisclosed number of people may be affected; check the listing and monitor your accounts for signs of compromise. The incident was reported on 28 June 2026. dystar.com appears on a listing attributed to the settra ransomware group. The group claims to hold 1.3 terabytes of data described as the complete digital archive of DyStar. No independent confirmation of the volume, the date of access, or the method of entry has been released. The number of people affected remains undisclosed. Settra is a ransomware operator that lists victim organisations on a public site after encrypting systems and copying files. The group’s listings function as a claim that data has been taken and may be released if demands are not met. No additional statements from settra specific to dystar.com have been verified beyond the listing itself. dystar.com belongs to an organisation that operates in the specialty chemicals sector, supplying dyes and related products to industrial clients. Entities of this type routinely maintain records on production processes, customer accounts, supplier arrangements and internal communications. A breach that exposes such material can affect both commercial operations and any personal details contained in those records. The only category named in available reports is internal files exfiltrated during a ransomware attack. The precise contents of the 1.3 terabytes referenced in the listing have not been itemised by the organisation or independently verified. Organisations in this sector commonly store employee records, contractual documents and operational data, yet the exact composition of the material in this case stays unconfirmed. Internal files can contain identifying information, financial references or communications that retain value long after the initial incident. Individuals named in those files may encounter follow-on risks such as targeted fraud or unwanted contact. For the organisation, the exposure of proprietary material can complicate business relationships and regulatory compliance even if the number of personal records remains unknown. Begin by monitoring accounts linked to any email address you have used with dystar.com or its partners. Enable multi-factor authentication on those accounts and review recent login activity. Request a copy of any personal data the organisation holds about you under applicable data-protection rules. Readers can run a free exposure scan of their email address against known breach data to check for appearances in public listings. Change passwords for any accounts that may share credentials with dystar.com systems. Watch bank and credit statements for unusual activity over the next several months. Contact dystar.com directly to ask what categories of personal information were held and whether they have been notified of the listing. Read GalaxyWarden’s full analysis of the dystar.com Listed by settra Ransomware Group → Publicly posted by settra — unverified claim, pending independent verification Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated a
Related context
Challenge Manufacturing Data Breach Exposes Social Security Numbers
Challenge Manufacturing, an automotive manufacturing company, disclosed a data breach to the Texas Attorney General on June 26, 2026. The Chaos ransomware group claimed responsibility on May 17, 2026, stating they obtained 270 GB of data from the company's systems.
Related context
Latvijas Valsts Mezi (LVM) Suffers Cybersecurity Breach
Cybersecurity breach reveals vulnerability of Latvia's strategic infrastructure: minister RIGA, June 26 (Xinhua) -- A recent incident in which hackers managed to access IT systems of Latvia's state-owned company Latvijas Valsts Mezi (LVM) revealed the relative vulnerability of the country's strategic infrastructure, Smart Administration and Regional Development Minister Edgars Tavars said Friday. The cybersecurity breach in LVM has caused particular concerns because the company has been entrusted with developing an electoral IT platform for Latvia's parliamentary elections, which are scheduled to take place this fall. In an interview with the TV3 channel on Friday, Tavars called on all state institutions to identify cybersecurity flaws in their own systems and learn a lession from the LVM incident. The minister believes, though, that in general, Latvian IT specialists are good enough to prevent similar incidents from repeating in the future. Tavars said that the electronic voter register, on which LVM has been working, was completed before the incident and was not at risk. In general, "we are definitely not ringing alarm bells about the elections," the minister said. LVM discovered the cybersecurity breach of its IT systems last weekend. In response, the company took all its external IT systems offline and also shut down some internal communication systems. A foreign ransomware group, which has carried out similar attacks against companies and government agencies in other countries, has claimed responsibility on the cyberattack on LVM. Cyberattack on Latvian State Forests detected LVM is one of three companies developing this year’s Saeima election system . However, the company noted that the development of the election system was kept separate and was not affected. Security measures will be reviewed as a precaution. The cyberattack occurred on Monday, June 22. According to the company, since the incident began, the external information technology (IT) systems maintained by LVM, including “LVM GEO,” the mapping service system, and the hunting app “Mednis”, have been shut down and are unavailable for security reasons. Several of LVM’s internal systems, which facilitate the company’s exchange of information with service providers and clients, have also been taken offline. LVM spokesperson Tomass Kotovičs stated that the threat has been eliminated, but it will take time to restore the systems to operation. Baiba Kaškina, head of “Cert.lv,” explained that the attack was thwarted immediately. According to her, there is no reason to believe that it was specifically targeted at Latvia. “Cert.lv” is inclined to believe that this was a commercially motivated attack aimed at demanding a ransom and demonstrating the attackers’ capabilities. The State Police Cybercrime Combating Directorate, based on publicly available information, has launched an internal investigation on its own initiative to clarify the circumstances of the incident and identify the possible perpetrator, according to the LETA news agency. Select text and press Ctrl+Enter to send a suggested correction to the editor Select text and press Report a mistake to send a suggested correction to the editor
Related context
South Korean Domain Registrar Gabia Hacked, Exposing 350,000 User Records
South Korean domain registrar Gabia experienced a cyberattack on Saturday, July 26, 2026, which impacted the online connectivity of approximately 100,000 registered domains. The incident led to the exposure of data belonging to 350,000 users. The compromised information included names, user IDs, passwords, and registration numbers. This breach highlights the significant risks associated with compromised credential reuse, as a large portion of the exposure originated from "Combolist sources." Additionally, active infostealer activity, linked to malware families such as LummaC2, Redline, and Rhadamanthys, was identified, further indicating a focus on credential theft impacting both clients and employees. The incident also revealed 245 compromised employee accounts, posing an infrastructure risk, and 30,782 leaked client credentials, creating regulatory liability. The timeline of related events showed an increase in client-related incidents from August 2025 through April 2026, with a peak in March 2026, and spikes in employee-related events in January, April, and May 2026. Remediation efforts should prioritize credential hygiene, multi-factor authentication enforcement, and enhanced monitoring for suspicious login activity, particularly targeting login forms and account management services. The incident was reported by the Korea Herald on Monday, July 28, 2026.