Harel Insurance ( Shirbit Server ) Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Harel Insurance (Shirbit Server) appeared on a listing posted by the Handala ransomware group on December 03, 2024. Anyone with accounts or policies at the firm should check for follow-up notices from Harel and review their accounts for unusual activity.
Ransomware groups continue to target insurance and financial-sector systems worldwide, often listing victims on leak sites after claiming to have stolen internal files. In this climate of opportunistic and ideologically motivated attacks, a December 2024 listing involving Harel Insurance’s Shirbit server has drawn attention because of the sensitive nature of the sector and the group’s public claims.
Public reporting indicates that the handala ransomware group listed Harel Insurance (Shirbit Server) on 3 December 2024. The number of people affected remains unknown, and the only data type named is internal files said to have been exfiltrated. Exact technical details of the intrusion are limited to the group’s own statements.
Inside the incident
According to the available record, handala claimed responsibility for hacking a Shirbit proxy server that had been integrated into Harel’s network after the 2021 acquisition. The group stated that Shirbit had been one of the larger insurance providers in Israel, covering vehicles and insurance for government employees and military personnel, and that its infrastructure was transferred to Harel in an interface-oriented manner. The listing describes the event as a ransomware attack in which internal files were allegedly exfiltrated. No independent confirmation of the method, timeline of compromise, volume of data, or encryption of systems has been made public. The number of individuals potentially affected is listed as unknown, and no further forensic details have been disclosed by the organisation or by independent researchers at the time of reporting.
The group behind it: handala
Handala is a publicly documented pro-Palestinian hacktivist collective that has repeatedly claimed cyber operations against Israeli government, military and commercial targets. The group typically publicises its activity on dedicated leak or announcement channels, often framing attacks in geopolitical terms and asserting that data has been stolen for later release or sale. Its tactics, as observed in prior campaigns, commonly include ransomware deployment combined with data exfiltration, followed by listings that pressure victims through the threat of publication. Handala’s statements about this specific incident should be treated as claims: the group asserts that it compromised the Shirbit proxy server and obtained internal files, but those assertions have not been independently verified in the public record. The group’s broader pattern of targeting entities linked to Israeli institutions provides context for why an insurance firm with government and military clients would appear on its list, yet does not confirm the accuracy of any particular technical claim made about Harel or Shirbit.
About Harel Insurance ( Shirbit Server )
Harel Insurance is a major Israeli insurance group. Shirbit, acquired by Harel in 2021, previously operated as a significant provider of vehicle and other insurance products, including coverage for government employees and military personnel. After the acquisition, Shirbit’s infrastructure was integrated into Harel’s network. Organisations of this type routinely process large volumes of personal, financial and policy-related data, including names, contact details, identification numbers, vehicle records, claims histories and, in some cases, information linked to public-sector or security-related clients. A compromise of systems holding such material raises clear concerns about confidentiality and potential secondary misuse, regardless of whether the full extent of any breach has been confirmed.
The information in question
The only data category named in the public listing is “internal files” said to have been exfiltrated during a ransomware attack. No further breakdown—such as customer records, employee data, policy documents or technical credentials—has been disclosed. Insurance companies typically hold personally identifiable information, financial details, claims files and operational records; however, it is not confirmed that any of these specific categories were among the files claimed by handala. Because the precise contents remain unconfirmed, any assessment of exposure must remain provisional until additional verified information becomes available.
Why it matters
If internal files containing personal or policy data were in fact taken, affected individuals could face risks of identity theft, targeted phishing, or unsolicited contact that exploits knowledge of their insurance status or government affiliation. For the organisation, the incident carries potential regulatory, reputational and operational consequences common to any significant data-exfiltration event in the insurance sector. Even when the scale is unknown, the mere listing by a ransomware group can erode customer confidence and trigger mandatory notification processes under applicable privacy laws. The geopolitical framing used by the group may also increase the likelihood of selective data publication intended to cause further harm or embarrassment.
Were you affected?
If you hold or previously held a policy with Harel or Shirbit, monitor account statements and credit reports for unusual activity and be cautious of unexpected emails or calls that reference insurance details. Change passwords on related accounts and enable multi-factor authentication where available. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Official notifications, if any, will come directly from the company or relevant authorities; treat unsolicited offers of “breach assistance” with scepticism until verified.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
IIB ( Israeli Industrial Batteries ) Leaked Listed by handala Ransomware GroupIIB ( Israeli Industrial Batteries ) Listed by handala Ransomware GroupEPS Tech confidential source code ( military ) Listed by handala Ransomware GroupHandala’s attack on Israeli organizations Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.