Ransomware victim disclosure
← All victimsNaftali Bennett (personal device compromise)
listed as Operation Octopus: Naftali Bennett · Claimed by Handala · listed 8 months ago
Status timeline
- ListedDec 17, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileNaftali Bennett is a former Prime Minister of Israel (2021–2022) and former Minister of Defense, known for his background in the technology and cybersecurity sector before entering politics. The claim targets him as an individual, not a corporate entity. He is also a co-founder of Cyota, a cybersecurity company, and has publicly championed Israel's cybersecurity credentials.
- Industry
- Government / Political Figure (Former Head of State)
Attack summary
Severity: critical — The alleged compromise of a former head of state's personal smartphone by a known threat actor (Handala, linked to Iranian-aligned operations) represents a critical severity incident due to the potential exposure of sensitive government, intelligence, or political communications held on a personal device of a high-profile national security figure.Handala claims to have compromised Naftali Bennett's personal iPhone 13, implying exfiltration of data from the device; no ransom is stated and no specific data categories are confirmed in the truncated post, but the framing suggests personal and potentially sensitive communications or files were accessed.
Data the group says was taken
AI dossier — extracted from the leak post- Personal iPhone 13 contents
- Potentially personal communications
- Potentially sensitive political or security-related data
What the group claims
Dear Naftali Bennett, You once prided yourself on being a beacon of cybersecurity, parading your expertise before the world. Yet, how ironic that your own iPhone 13 has fallen so easily to the hands of Handala. For all your boasts and bravado, your digital fortress was nothing more than a paper wall waiting to be…
Sources
Source
Indexed 8 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

