LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Israel defense minister private photos Listed by handala Ransomware Group

HIGH severityUnverified claimHow we verify

Israel defense minister private photos Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 24, 2024
Israel defense minister private photos Listed by handala Ransomware Group

Reported September 24, 2024.

HIGH
Severity
September 24, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Israel Defense Minister private photos were listed by the Handala ransomware group on September 24, 2024. Anyone connected to the minister’s office should review their systems for signs of compromise and take steps to secure their data.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In a threat landscape where politically motivated ransomware and hacktivist groups increasingly target high-profile individuals and government-linked figures, claims of personal data theft have become a recurring feature of geopolitical cyber conflict. Groups often list victims on leak sites to amplify pressure, blending technical intrusion with public messaging. Against that backdrop, a September 2024 listing by the Handala ransomware group concerning private photos associated with an Israeli defense minister has drawn attention, even as independent confirmation of the full scope remains limited.

Public reporting indicates that Handala claimed to have listed material described as private photos of Benny Gantz, a former Israeli defense minister. The group framed the incident as a ransomware-related exfiltration of internal files. Exact numbers of people affected are unknown, and many operational details have not been independently verified. The episode matters because personal imagery of senior political and security figures can create real risks of harassment, blackmail, or broader information operations if it is authentic and released.

Inside the incident

According to available records, the incident was reported on September 24, 2024, under the headline that “Israel defense minister private photos” had been listed by the Handala ransomware group. The organization named in the listing is given as “Israel defense minister private photos.” The data types described as exposed are internal files said to have been exfiltrated in a ransomware attack. The number of people affected is listed as unknown.

The group’s own reported summary states that it holds “2/000 private photos of Benny Gantz,” referring to him as the former defense minister and asserting that the material would be published. The message includes political language directed at Gantz and a claim that the photos constitute a “gift” that would also reach him. Timing of any initial intrusion, the precise technical method of access, and whether a ransom demand was paid or files were actually released in full are not disclosed in the public facts. The listing itself should be treated as an unverified claim by the group rather than confirmed fact.

Who is handala?

Handala is a publicly documented threat actor that has operated in the ransomware and hacktivist space with a stated focus on Israeli and related targets. Open-source reporting has associated the group with politically framed campaigns, data-leak site postings, and claims of file exfiltration intended to generate pressure or publicity. Typical tactics observed across such groups include unauthorized access followed by threats to publish stolen material, often accompanied by ideological messaging. Handala has previously appeared in coverage of incidents involving Israeli entities, though each claim must be evaluated separately.

In this case, the group claims to have obtained and listed private photos of Benny Gantz and to have conducted a ransomware-style exfiltration of internal files. No independent confirmation of those specific assertions is contained in the available facts. Readers should therefore regard the leak-site listing as the group’s claim rather than established evidence of successful compromise or of the exact contents of any archive.

About Israel defense minister private photos

The named organization in the listing is “Israel defense minister private photos,” which appears to refer to personal or private photographic material associated with a senior Israeli defense official rather than a conventional corporate entity. Benny Gantz has served as Israel’s defense minister and remains a prominent political figure. Individuals in such roles typically hold or are associated with sensitive personal communications, imagery, and documents that, if compromised, can have both personal and national-security implications.

Organizations and individuals in the defense and political sector commonly manage classified or restricted material, personal devices, and private media. A breach involving private photos of a former defense minister is consequential because it can expose personal life details, create leverage for coercion, and feed into broader information campaigns. Public detail on the precise systems or accounts involved in this listing is limited.

What was likely exposed

The facts name the exposed data types as internal files exfiltrated in a ransomware attack. The group’s summary specifically claims two thousand private photos of Benny Gantz. Beyond that claim, the exact contents of any archive have not been independently confirmed, and the number of people affected remains unknown.

Organizations and high-profile individuals in the defense and political sphere typically hold personal photographs, contact information, internal correspondence, and device backups. Whether any of those categories beyond the claimed photos were present is unconfirmed. Readers should treat the group’s description as an assertion rather than verified inventory.

Why it matters

If authentic private photographs of a former defense minister were obtained and threatened with publication, the immediate risks include personal embarrassment, potential blackmail, and targeted harassment of the individual and close associates. For the broader public and for institutions, such incidents can erode trust in the security of personal devices and accounts used by senior officials. Even when claims remain unverified, the mere listing can generate secondary effects such as phishing attempts that impersonate the victim or the group, or opportunistic scams that reference the alleged breach.

From an organizational perspective, any successful exfiltration of internal files—if it occurred—raises questions about access controls, device hygiene, and monitoring. The facts do not establish negligence or confirm the technical path of intrusion; they simply record the group’s claim and the reported date. Real-world impact therefore depends on whether the material is genuine, whether it is released, and how widely it circulates. Until those points are clarified, the primary concern remains the potential for personal harm and information misuse rather than any quantified financial loss, which is not reported here.

What to do if you're exposed

If you believe your own information or images may have been caught up in this or a related incident, begin with practical steps: change passwords on email and cloud accounts that store personal media, enable multi-factor authentication where available, and review account activity logs for unfamiliar access. Monitor for unexpected messages that reference the alleged photos or demand payment. Preserve any suspicious communications for later reporting to relevant authorities if needed. Because the number of people affected is unknown and the full contents are unconfirmed, treat unsolicited contact with caution.

Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Such scans do not prove involvement in this specific listing, but they provide a useful baseline for further monitoring. Stay alert to official statements from Israeli authorities or cybersecurity agencies that may later clarify the status of the claim.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyIsrael defense minister private photos security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Israel defense minister private photos’s full breach history →

More recent breaches

Elad municipality Listed by handala Ransomware GroupNovember 3, 2024Shin Bet Listed by handala Ransomware GroupOctober 3, 2024Israel Prime Minister Emails Listed by handala Ransomware GroupOctober 2, 2024Soreq NRC Listed by handala Ransomware GroupSeptember 28, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Israel defense minister private photos Listed by handala Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by handala — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram