10M israeli data for sell Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On December 23, 2024, the FunkSec ransomware group listed 10 million Israeli records for sale after exfiltrating internal files in a ransomware attack. Individuals should verify whether their data was exposed and take protective steps.
On December 23, 2024, the ransomware group funksec listed an entry titled "10M israeli data for sell" on its leak site, claiming to have carried out a ransomware attack that involved the exfiltration of internal files. Public reporting identifies the organization simply as "10M israeli data for sell," with the number of people affected listed as unknown. Exact details about the incident remain limited, and the group's listing constitutes an unverified claim rather than independently What's Publicly Reported.
What is known so far centers on the assertion of data theft through ransomware activity. No further verification of the scale, timing of the intrusion, or confirmation from the listed entity has been made public, leaving the full scope of the event unclear.
Inside the incident
According to the available record, funksec reported the incident on December 23, 2024, under the headline "10M israeli data for sell." The group claims that internal files were exfiltrated as part of a ransomware attack. No additional specifics—such as the precise date the intrusion began, the method of initial access, the volume of data taken beyond the headline reference, or any ransom demand—have been disclosed in the public facts. The number of people affected is explicitly unknown. Because the information originates from the group's own leak-site listing, it must be treated as a claim pending independent confirmation. Public detail on the technical course of the attack is limited.
Inside funksec
Funksec is a ransomware group that became publicly visible in late 2024. Like many contemporary ransomware operators, it follows a double-extortion model: data is first stolen and then systems are encrypted, with the threat of public release used to pressure victims. The group maintains a leak site where it posts victim names and, in some cases, sample files or larger archives. Public reporting has noted that funksec often sets relatively low ransom demands compared with more established crews and has been associated with the use of AI-assisted tooling in its operations. Its listings have covered a range of organizations across different sectors and geographies. In this instance, the group claims responsibility for the "10M israeli data for sell" entry; no independent verification of that specific claim appears in the available facts.
About 10M israeli data for sell
Public information about an organization formally named "10M israeli data for sell" is extremely limited. The designation appears to refer to a claimed dataset of Israeli-origin information rather than a conventional company or public institution with a long public track record. In general, large collections of personal or organizational data originating from a single country can include records drawn from commercial databases, public registries, or compromised systems that hold identity, contact, or administrative information. A breach involving such material is consequential because it can expose individuals to identity-related risks and can undermine trust in the systems that originally held the data. Beyond the leak-site listing itself, no further verified background on the entity or its normal operations has been provided in the facts.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as specific categories of personal identifiers, financial records, medical information, or credentials—has been disclosed. Organizations or datasets of this general type commonly hold contact details, identification numbers, and internal operational documents; however, the exact contents of the material claimed by funksec remain unconfirmed. Readers should therefore treat any assertion about particular data fields as speculative until independent analysis or official statements become available.
What's at stake
For individuals whose information may be included, the primary risks are practical rather than abstract: potential misuse of personal details for phishing, social-engineering attempts, or identity fraud. Even limited internal files can contain enough context to make targeted scams more convincing. For the organization or data holder, the stakes include operational disruption, possible regulatory scrutiny if personal data of residents is involved, and reputational damage once a listing appears on a ransomware leak site. Because the number of people affected is unknown and the precise data types are not confirmed, the full extent of exposure cannot yet be quantified. The absence of independent verification also means that the claim itself may be incomplete or overstated, yet the mere publication of such a listing can still generate secondary harm through anxiety and opportunistic fraud attempts.
Were you affected?
If you believe your information could be connected to Israeli-origin datasets or related systems, begin by monitoring financial and email accounts for unusual activity and enable multi-factor authentication wherever possible. Consider placing fraud alerts with relevant credit or identity services if you reside in a jurisdiction that offers them. Change passwords on any accounts that may have reused credentials associated with the affected material. Because public confirmation of the exact contents remains limited, treat unsolicited messages that reference this incident with caution. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
2sign.co.il Listed by funksec Ransomware Groupfuse.io Listed by funksec Ransomware Groupdevoutdigital.com Listed by funksec Ransomware Groupnetox.net Listed by funksec Ransomware GroupLatest breaches
Publicly posted by funksec — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.