LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Israel foreign affairs minister Emails Listed by handala Ransomware Group

HIGH severityUnverified claimHow we verify

Israel foreign affairs minister Emails Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 26, 2024
Israel foreign affairs minister Emails Listed by handala Ransomware Group

Reported September 26, 2024.

HIGH
Severity
September 26, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Israel’s foreign-affairs-ministry emails were listed by the Handala ransomware group on 26 September 2024; the date of the underlying intrusion has not been established. Individuals whose email addresses or attachments may have been among the internal files should review any notices from the ministry and change passwords or enable multi-factor authentication as a precaution.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 26, 2024, the ransomware group handala publicly listed a collection described as Israel foreign affairs minister Emails on its leak site. The group claims the material consists of internal files obtained through a ransomware attack and includes approximately 60,000 secret emails tied to Gabi Ashkenazi, a former Israeli Minister of Foreign Affairs and Chief of General Staff. The number of people affected remains unknown, and independent confirmation of the full scope or authenticity of the claimed data has not been established in the available record.

This listing matters because it concerns communications associated with a senior former official and, by the group’s own assertion, potentially broader government holdings. Public detail is limited to the group’s statements and the reported date of the listing; no verified technical analysis of the breach method or complete inventory of files has been released.

Breaking down the breach

According to the reported summary, handala stated that it had exfiltrated internal files in a ransomware attack and was releasing a first portion of what it called 60,000 secret emails. The group described the material as only a small part of a larger “data lake” concerning Gabi Ashkenazi and issued a broader political claim that current Israeli officials and ministries were not safe. The listing appeared on September 26, 2024. No further technical details—such as the initial access vector, the precise date of the intrusion, encryption status of systems, or ransom demand—have been disclosed in the public facts. The number of individuals whose information may appear in the files is listed as unknown. The group’s leak-site announcement remains an unverified claim unless corroborated by independent forensic reporting.

Inside handala

Handala is a known ransomware and hacktivist actor that has repeatedly targeted Israeli government, military, and civilian entities. Public reporting over recent years shows the group typically combines data theft with political messaging, posting sample files or full archives on dedicated leak sites and framing its operations as resistance against Israeli institutions. Its tactics commonly include ransomware deployment followed by threats of public release if demands are unmet, accompanied by inflammatory statements directed at Israeli officials. Prior activity has focused on ministries, defense-related organizations, and individuals connected to the Israeli government. In this case, the group claims the Israel foreign affairs minister Emails form part of a larger collection on Gabi Ashkenazi; that assertion is presented solely as the group’s own statement and has not been independently verified in the available record.

Israel foreign affairs minister Emails and its sector

The listed material is associated with the office and communications of Israel’s foreign affairs minister, specifically referencing Gabi Ashkenazi, who previously held that post and earlier served as Chief of General Staff. Organizations of this type routinely handle diplomatic correspondence, policy drafts, classified or sensitive internal memoranda, contact lists of officials and foreign counterparts, and operational planning documents. A breach involving such holdings is consequential because foreign-ministry communications can reveal negotiation positions, personnel movements, and relationships with other governments. Even partial exposure of historical or current email archives can create lasting intelligence value for adversaries and complicate ongoing diplomatic work. Public facts do not confirm whether active ministry systems or only personal or archival accounts linked to the former minister were involved.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack, with the group claiming roughly 60,000 secret emails related to Gabi Ashkenazi. Exact data types beyond that description—such as attachments, contact databases, or classified markings—are not further itemized in the public record. Organizations in the foreign-affairs sector typically hold email traffic, calendars, internal reports, and personal identifiers of staff and interlocutors. Because the precise contents remain unconfirmed, it is not possible to state with certainty which categories of information were actually present in the claimed archive. The group’s assertion that the release is only a fraction of a larger data lake is likewise unverified.

The real-world impact

For individuals whose names, addresses, or correspondence appear in the files, the primary risks include targeted phishing, social-engineering attempts that exploit authentic context, and potential reputational or security harm if private discussions become public. For the organization, the consequences can include erosion of trust among diplomatic partners, the need to review and rotate compromised credentials or communication channels, and the possibility that adversaries will mine the material for long-term intelligence. Because the number of affected people is unknown and the authenticity of the full dump is unconfirmed, the scale of these risks cannot yet be quantified. No financial figures or confirmed secondary exploitation have been reported in the available facts.

If your data was in this claimed breach

If you believe your information may have been included, take the following practical steps:

Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Remain alert for further official statements, as additional confirmation or clarification may emerge over time.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyIsrael foreign affairs minister Emails security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Israel foreign affairs minister Emails’s full breach history →

More recent breaches

Elad municipality Listed by handala Ransomware GroupNovember 3, 2024Shin Bet Listed by handala Ransomware GroupOctober 3, 2024Israel Prime Minister Emails Listed by handala Ransomware GroupOctober 2, 2024Soreq NRC Listed by handala Ransomware GroupSeptember 28, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Israel foreign affairs minister Emails Listed by handala Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by handala — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram