LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Israel Police Listed by handala Ransomware Group

HIGH severityUnverified claimHow we verify

Israel Police Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 9, 2025
Israel Police Listed by handala Ransomware Group

Reported February 9, 2025.

HIGH
Severity
February 9, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Israel Police was listed by the handala ransomware group on February 09, 2025, after internal files were taken in a ransomware attack that affected an undisclosed number of people. Anyone who may have had contact with the Israel Police is advised to check for signs of data misuse and to follow official guidance on protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 9 February 2025 the Israel Police appeared on a listing by the handala ransomware group. The group claims it carried out a ransomware attack and exfiltrated internal files. The number of people affected remains unknown, and public detail about the precise contents of those files is limited. For anyone whose personal or professional information may sit inside police systems—witnesses, complainants, officers, or members of the public who have interacted with the force—the practical stakes are straightforward: once internal material leaves an organisation’s control, it can be examined, copied, or misused by others, creating lasting privacy and security risks that are hard to reverse.

What is known so far comes almost entirely from the group’s own claim. Independent confirmation of the scale, method, or full contents of any stolen material has not been made public. That uncertainty itself is part of the problem for those who may be affected: without clear facts, people cannot yet judge how directly they are exposed or what steps will best protect them.

Breaking down the breach

According to the available record, the Israel Police was listed by handala on 9 February 2025. The group describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. No figure for the number of people affected has been released, and no further technical details—such as the exact date of intrusion, the vector used, or the volume of data taken—have been disclosed in the public summary. The group’s accompanying statement is rhetorical and taunting rather than technical; it asserts that the organisation’s defences failed and that the attackers now hold material, but it supplies no verifiable inventory or proof package beyond the claim itself.

Because the listing originates from the threat actor, it must be treated as an unverified assertion until corroborated by the organisation or by independent investigators. At present the public record contains only the fact of the listing, the characterisation of the event as a ransomware attack involving internal-file exfiltration, and the date the claim was reported. Everything else—scope, dwell time, encryption status, or ransom demand—remains undisclosed.

Inside handala

Handala is a known cyber threat actor that has publicly aligned itself with pro-Palestinian causes and has repeatedly claimed responsibility for operations against Israeli government, security, and commercial targets. Public reporting over recent years has associated the group with data-leak and ransomware-style campaigns in which it posts stolen material or screenshots on leak sites and issues political statements. Its typical pattern involves claiming unauthorised access, asserting that sensitive files have been copied, and using the resulting publicity to amplify its message. The group often frames its actions as retribution rather than pure financial extortion, though the precise mix of motives can vary from incident to incident.

In this case the group’s own wording follows that established style: a direct address to the Israel Police, mockery of its security posture, and an assertion that internal material has been taken. No additional claims unique to this victim—beyond the general statement that internal files were exfiltrated—appear in the provided record. As with other handala listings, the appearance of a victim’s name on its site constitutes a claim that requires independent verification; it does not by itself prove the full extent of any compromise.

About Israel Police

The Israel Police is the national civilian law-enforcement body responsible for maintaining public order, investigating crime, and providing policing services across Israel. Like any modern police organisation, it maintains extensive digital systems that support investigations, personnel management, operational planning, and public-facing services. Such systems routinely hold records that touch large numbers of people: case files, witness and complainant details, officer information, intelligence notes, and administrative data. Because police work depends on the confidentiality of sources, the integrity of evidence, and the safety of personnel, any unauthorised access to internal material carries consequences that extend beyond ordinary corporate data loss.

A breach claim against a police force therefore raises immediate questions about operational security, the protection of individuals who have cooperated with investigations, and public confidence in the institution’s ability to safeguard sensitive information. Even when the precise contents of an alleged theft remain unconfirmed, the mere possibility that internal files have left official control is consequential for both the organisation and the people whose lives intersect with its work.

What data was at risk

The only data type named in the public record is “internal files exfiltrated in ransomware attack.” No further breakdown—such as whether the material included personal identifiers, case documents, personnel records, or technical configurations—has been disclosed. Organisations of this kind typically hold a wide range of sensitive information: personal data of citizens who report crimes or appear as witnesses, details of ongoing investigations, officer contact and assignment information, and internal administrative records. It is therefore reasonable to expect that any large collection of internal police files could contain material of that nature. However, the exact contents of the files allegedly taken in this incident remain unconfirmed. Until an official inventory or independent analysis is released, no specific categories of personal data can be stated as factually exposed.

The real-world impact

For individuals, the primary risks are privacy intrusion and secondary misuse. If personal details or case-related information were among the internal files, those details could be examined by unauthorised parties, used for social-engineering attempts, or published in ways that cause distress or physical risk—particularly for people who have provided information to the police. Officers and staff whose own data appears in internal systems face similar concerns about doxxing or targeted harassment. Because the number of people affected is unknown, the circle of potential exposure cannot yet be drawn with precision.

For the organisation itself, the claim raises operational and reputational issues. Even an unconfirmed listing can force internal reviews of systems, temporary restrictions on data access, and public communication challenges. If material was in fact removed, investigators may need to reassess the integrity of ongoing cases or the safety of sources. The absence of confirmed scale or content does not eliminate these pressures; it simply leaves them unresolved until more information becomes available.

If your data was in this claimed breach

If you have had any dealings with the Israel Police—whether as a complainant, witness, officer, or member of the public—and are concerned that your information may have been involved, begin with basic precautions. Monitor financial and online accounts for unusual activity, be cautious of unexpected messages that reference police matters or request personal details, and consider placing fraud alerts with relevant credit or identity-protection services where available. Keep records of any suspicious contact. Because the exact data set remains undisclosed, these steps are precautionary rather than a response to confirmed exposure of any particular record.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Such a scan will not confirm or rule out involvement in this specific incident, but it can indicate whether your details have surfaced elsewhere and help you prioritise further protective measures. Stay alert for any official statements from the Israel Police that may clarify the scope of the claim; until then, treat the handala listing as an unverified assertion and act on the side of caution with your personal information.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyIsrael Police security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Israel Police’s full breach history →

More recent breaches

Bibi Gate: The Gatekeeper’s Fall | Tzachi Braverman Listed by handala Ransomware GroupDecember 28, 2025Shelter Locations in Israel Listed by handala Ransomware GroupJune 23, 2025Y.G. New Idan Listed by handala Ransomware GroupJune 14, 2025Israel Ministry of National Security Listed by handala Ransomware GroupJanuary 29, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Israel Police Listed by handala Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by handala — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram