Israel Ministry of National Security Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On January 29, 2025, the Israel Ministry of National Security appeared on a list published by the handala ransomware group, with internal files reported as exfiltrated in the attack. An undisclosed number of individuals may have been affected; anyone with ties to the ministry should review official notices and change credentials if advised.
Ransomware groups continue to target government institutions worldwide, often blending data theft with public claims designed to amplify disruption and political messaging. In this environment, listings on leak sites serve as both pressure tactics and assertions of access, even when independent confirmation remains limited.
On January 29, 2025, the Israel Ministry of National Security was listed by the handala ransomware group. The group claims it exfiltrated internal files in a ransomware attack and describes a sequence of actions against systems tied to shelters. Public detail on the scale, confirmation of access, and exact impact is limited, yet the listing raises clear questions about the security of sensitive government systems and the potential exposure of operational data.
What happened
According to the reported listing, the handala group claims to have compromised the Israel Ministry of National Security. The group states that internal files were exfiltrated as part of a ransomware attack. Its accompanying summary describes a sequence it presents as ongoing: hacking the comprehensive integrated management system of the regime’s shelters, sounding a red alert, directing people to shelters, closing doors, playing audio, wiping the system, and urging a call to 101. The number of people affected is unknown. Timing beyond the January 29, 2025 reporting date, the precise method of initial access, and independent verification of the claimed actions are undisclosed in available public information. The listing itself constitutes a claim by the group rather than a confirmed technical assessment.
Inside handala
Handala is a threat actor that has publicly positioned itself as a pro-Palestinian hacking group. It is known for targeting Israeli organizations and government-linked entities, frequently combining ransomware-style data exfiltration claims with politically charged messaging. The group typically publicizes alleged breaches on leak sites or associated channels, often framing operations as retaliation or symbolic disruption. Its tactics commonly include claims of system access, data theft, and, in some cases, operational interference, though independent confirmation of each claim varies. In this instance, the group’s listing of the Israel Ministry of National Security and the detailed sequence it describes should be treated as its own assertions. No additional claims specific to this victim beyond the provided summary are established as fact here.
Israel Ministry of National Security and its sector
The Israel Ministry of National Security oversees internal security functions, including coordination with police and related public-safety bodies. Organizations of this type typically manage systems that support emergency response, public alerts, shelter coordination, and administrative records tied to national security operations. A breach claim against such a ministry is consequential because it involves infrastructure that can affect civilian safety procedures and the confidentiality of internal government data. Even when full technical details remain unconfirmed, listings of this nature draw attention to the broader risk landscape facing government agencies that hold operational and citizen-related information.
What data was at risk
The available facts state that internal files were exfiltrated in a ransomware attack. Exact data types beyond that description are not disclosed. Organizations such as a national security ministry commonly hold operational documents, system configurations for emergency management, administrative records, and potentially information linked to personnel or public-safety coordination. Because the precise contents of any exfiltrated material remain unconfirmed, it is not possible to state specific categories of personal or classified data as fact. The group’s claims regarding shelter-management systems further suggest that operational files may have been involved, yet these remain assertions pending independent verification.
What's at stake
For individuals, any exposure of internal government files could create risks of secondary misuse if personal or contact details were included, though the number of people affected is unknown and the exact data is unconfirmed. For the organization, the stakes include potential disruption of systems used for public alerts and shelter coordination, erosion of operational confidence, and the need to investigate and contain any confirmed intrusion. Ransomware claims of this kind also carry reputational and continuity costs, as agencies must assess whether backups, access controls, and incident-response plans were sufficient. In concrete terms, the primary concerns are unauthorized access to sensitive operational material and the possibility that claimed system interference could affect emergency procedures, even if those claims have not been independently verified.
Were you affected?
If you have had dealings with the Israel Ministry of National Security or related services, monitor official communications for any confirmed notices. Change passwords on related accounts, enable multi-factor authentication where available, and remain alert for phishing that references the incident. Because the number of people affected and the precise data involved are unknown, treat any unsolicited contact claiming connection to this event with caution. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Bibi Gate: The Gatekeeper’s Fall | Tzachi Braverman Listed by handala Ransomware GroupShelter Locations in Israel Listed by handala Ransomware GroupY.G. New Idan Listed by handala Ransomware GroupIsrael Police Listed by handala Ransomware GroupLatest breaches
Publicly posted by handala — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.