Benny Gantz Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Benny Gantz was listed by the Handala ransomware group on 23 September 2024, with internal files reportedly exfiltrated from the organisation. Individuals whose data may have been involved should verify their exposure and take appropriate protective steps.
Ransomware groups and politically motivated threat actors continue to list high-profile individuals and institutions on leak sites, often mixing verified intrusions with unverified claims. In this environment, a September 2024 listing of Benny Gantz by the handala ransomware group fits a broader pattern of targeted data-exfiltration operations aimed at Israeli political and security figures. Public detail remains limited, yet the claim itself warrants careful examination because of the sensitivity of the material allegedly involved and the potential consequences for anyone whose information may have been caught in the net.
According to available reporting, Benny Gantz was listed by handala on or around 23 September 2024. The group asserts that internal files were exfiltrated in a ransomware attack and that a portion of confidential emails has been published. The number of people affected is unknown, and independent confirmation of the full scope has not been publicly established. The incident matters because it involves a former senior Israeli defense official whose communications and records could contain sensitive political, military, or personal data.
Inside the incident
On 23 September 2024, Benny Gantz appeared on a handala leak-site listing. The group claims it conducted a ransomware attack that resulted in the exfiltration of internal files. In its accompanying statement the group asserts that “35/000 Confidential Emails of Benny Gantz” have been published for the first time and that the material relates to confidential meetings held at his office. The statement further claims the group has monitored the former defense minister “for many years” and is releasing only a small portion of the data as a warning. No independent verification of the intrusion method, the exact volume of data, the date of the alleged compromise, or the authenticity of the published files has been provided in the public record. The number of individuals whose data may be involved remains unknown.
Who is handala?
Handala is a pro-Palestinian threat actor that has operated since at least 2023, frequently targeting Israeli government, military, and private-sector entities. The group typically claims to conduct ransomware-style operations or pure data-theft campaigns, then posts victim names and sample files on its leak site to amplify pressure. Its public messaging is overtly political, often framing attacks as responses to Israeli policy. Handala has previously listed a range of Israeli organizations and individuals, asserting possession of emails, documents, and internal databases. In the present case the group claims to have held long-term access to Benny Gantz’s environment and to have selectively released material; these assertions remain unverified claims rather than What's Publicly Reported.
About Benny Gantz
Benny Gantz is a prominent Israeli politician and former defense minister who has also served in senior military and cabinet roles. Individuals and offices of this stature routinely handle classified or sensitive correspondence, meeting records, personnel details, and policy documents. A compromise of such an environment is consequential because it can expose not only the principal but also staff, interlocutors, and third parties whose communications or personal data appear in the files. Even when the precise contents remain unconfirmed, the potential presence of political, security, or personal information elevates the stakes for anyone connected to the office.
What data was at risk
The only data types named in the available record are “internal files exfiltrated in a ransomware attack.” The group further claims that thousands of confidential emails have been published. Exact contents, file inventories, and the identities of any third parties whose data may be included are not disclosed. Organizations and offices of this kind typically hold email archives, calendars, meeting notes, contact lists, and internal memoranda; whether any of those categories were in fact taken remains unconfirmed. Public reporting does not establish the authenticity or completeness of the material the group says it has released.
What's at stake
If the claimed files are authentic, affected individuals could face risks of identity misuse, targeted phishing, reputational harm, or exposure of private communications. For the office itself, the incident raises concerns about the integrity of sensitive political and security-related correspondence. Because the number of people affected is unknown and the precise data types beyond “internal files” and claimed emails are unconfirmed, the full extent of real-world impact cannot yet be measured. The listing alone, however, can generate secondary effects such as increased social-engineering attempts against anyone whose name appears in the alleged material.
What to do if you're exposed
Anyone who believes their information may have been involved should take measured, practical steps:
- Monitor financial and email accounts for unusual activity and enable multi-factor authentication where available.
- Treat unsolicited messages that reference the incident or claim to possess private data with caution; verify any requests through official channels.
- Consider placing fraud alerts with credit bureaus if personal identifiers may have been exposed.
- Preserve any suspicious communications for potential reporting to relevant authorities.
- Run a free exposure scan of your email address to check whether it has already appeared in known breach datasets.
Public detail on this incident remains limited. Continued monitoring of official statements and verified breach notifications is the most reliable way to determine whether further action is required.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Elad municipality Listed by handala Ransomware GroupShin Bet Listed by handala Ransomware GroupIsrael Prime Minister Emails Listed by handala Ransomware GroupSoreq NRC Listed by handala Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Benny Gantz Listed by handala Ransomware Group →
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.