Ransomware victim disclosure
← All victimsIsrael's National Security Institute (linked to Mossad Budget Directorate)
listed as Mossad’s Secret Treasury Exposed: 50,000 Confidential Emails Leaked · Claimed by Handala · listed 3 months ago
Status timeline
- Listed
Mar 17, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileThe Israel National Security Institute (INSS) is a research and policy institution affiliated with Israel's national security apparatus. The leak post specifically targets Ilan Steiner, described as a former Budget Director of Mossad and current CFO of the institute. The organization operates at the intersection of intelligence, defense policy, and government finance.
- Industry
- Government Intelligence & National Security
Attack summary
Severity: critical — Claimed exfiltration of 50,000 emails from a senior official with dual roles in Mossad's budget directorate and a national security research institute constitutes a critical disclosure involving government intelligence, defence finance, and potentially classified communications.Handala Hack claims to have breached the email systems and confidential data of a senior official (Ilan Steiner), exfiltrating approximately 50,000 confidential emails linked to Mossad's budget directorate and the National Security Institute. No ransom was demanded; the data is stated as published.
Data the group says was taken
AI dossier — extracted from the leak post- Confidential emails (approx. 50,000)
- Intelligence/budget directorate communications
- Financial records (inferred from CFO role)
- National security correspondence
What the group claims
Today, a shadow has been lifted from one of the darkest layers of the Israeli intelligence and security apparatus. In a sophisticated operation, Handala Hack succeeded in breaching the email systems and confidential data of Ilan Steiner, former Budget Director of Mossad and current Chief Financial Officer of Israel’s National Security Institute, the research and…
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
