LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Shin Bet Listed by handala Ransomware Group

HIGH severityUnverified claimHow we verify

Shin Bet Listed by handala Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 3, 2024
Shin Bet Listed by handala Ransomware Group

Reported October 3, 2024.

HIGH
Severity
October 3, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Shin Bet was listed by the handala ransomware group on 3 October 2024, with internal files reportedly exfiltrated from the organisation. Individuals are advised to check any official channels for information on whether their data may have been exposed and to follow recommended protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On October 03, 2024, the Israeli internal security service known as Shin Bet was listed by the ransomware group handala, which claimed to have conducted a ransomware attack that exfiltrated internal files. The number of people affected remains unknown, and public detail on the full scope of the incident is limited. The group's listing asserts that Shin Bet's comprehensive security system was compromised, including a proprietary application installed on officers' Android and iOS devices that enables extensive monitoring. This claim has not been independently confirmed in the available record.

A breach involving a national security organisation of this kind carries weight because of the sensitive nature of the data such agencies typically handle and the potential implications for operational security and individuals connected to it. What follows is a factual account grounded strictly in the reported details and established public background on the parties involved.

What happened

According to the reported summary dated October 03, 2024, Shin Bet was listed by the handala ransomware group as the victim of a ransomware attack in which internal files were exfiltrated. The group claims that Shin Bet’s comprehensive and exclusive security system was hacked. Specifically, the listing states that Shin Bet designed a system involving its own application installed on the Android and iOS phones of its officers; this application allegedly takes over complete security of the device and enables comprehensive and extensive monitoring by Shin Bet. Public detail on the precise method of intrusion, the timeline of the attack, the volume of data taken, or any ransom demand is undisclosed. The listing itself is presented as a claim by the group rather than a verified confirmation of successful compromise.

Who is handala?

Handala is a known ransomware and hacktivist group that has publicly claimed responsibility for attacks against Israeli targets and organisations perceived as linked to Israeli interests. Public reporting on the group describes it as operating with a mix of data theft, encryption, and leak-site publication tactics typical of modern ransomware actors. It has previously listed victims on dedicated leak sites, often accompanying claims with samples or descriptions of stolen material to pressure targets. In this instance, handala’s listing of Shin Bet is treated as an unverified claim; the group asserts it exfiltrated internal files, but no independent confirmation of the breach’s success or the authenticity of any materials is contained in the available facts. The group’s broader pattern involves publicising alleged compromises to maximise attention and leverage.

Who is Shin Bet?

Shin Bet, also known as the Israel Security Agency or Shabak, is Israel’s domestic intelligence and security service. It is responsible for counter-terrorism, counter-espionage, and the protection of critical infrastructure and state secrets within Israel’s borders. Organisations of this type routinely hold highly sensitive operational data, personnel records, intelligence products, communications, and technical security systems. A claimed breach of such an agency is consequential because it could, if verified, affect national security operations, the safety of personnel, and the integrity of monitoring or protective tools used by officers. The facts do not establish negligence or state the extent of any compromise; they record only the group’s listing and the described claims about an internal security application.

What was likely exposed

The facts name the exposed material as internal files exfiltrated in a ransomware attack. Exact contents, file counts, or categories beyond that description are not disclosed. Organisations of Shin Bet’s type typically maintain personnel information, operational plans, technical configurations for security tools, communications logs, and device-management data. The group’s claim specifically references a proprietary application for Android and iOS devices used by officers. Because the precise data set remains unconfirmed, the following points summarise only what is stated or reasonably typical without asserting them as Reported Facts of this incident:

Public detail is limited; no independent inventory of the exfiltrated material has been provided in the record.

What's at stake

If the claimed exfiltration of internal files is accurate, the real-world risks include potential exposure of operational methods, officer identities or contact details, and technical details of security systems. For individuals connected to Shin Bet—officers, staff, or family members—this could translate into heightened personal security concerns, phishing or social-engineering attempts, or unwanted attention. For the organisation itself, any confirmed compromise of monitoring tools or internal systems could require remediation of device fleets, review of access controls, and assessment of whether sensitive intelligence or protective capabilities were affected. The number of people affected is unknown, so the scale of individual impact cannot be quantified from the available facts. Even unconfirmed claims of this nature can create operational friction and public scrutiny for a security service.

Were you affected?

Because the number of people affected is unknown and the exact data types beyond “internal files” are not detailed, it is not possible to determine from public information alone whether any specific individual was involved. Practical first steps include monitoring personal accounts and devices for unusual activity, reviewing any official notifications that may be issued by Shin Bet or relevant authorities, and treating unsolicited communications that reference the incident with caution. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Stay alert to verified updates from official sources rather than relying solely on claims posted by threat actors.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyShin Bet security record
79/100
DoxxScan™ · Moderate doxx risk
B- 75Above-average record

2 reported incidents on record.

See Shin Bet’s full breach history →
RelatedMore incidents at Shin Bet

More recent breaches

Elad municipality Listed by handala Ransomware GroupNovember 3, 2024Israel Prime Minister Emails Listed by handala Ransomware GroupOctober 2, 2024Soreq NRC Listed by handala Ransomware GroupSeptember 28, 2024Israel foreign affairs minister Emails Listed by handala Ransomware GroupSeptember 26, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Shin Bet Listed by handala Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by handala — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram