Ransomware victim disclosure
← All victimsNaftali Bennett Chats
Claimed by Handala · listed 7 months ago
Status timeline
- ListedDec 17, 2025
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileNaftali Bennett served as the 13th Prime Minister of Israel (2021–2022) and is a prominent Israeli political figure and businessman. This record does not represent a company but rather a targeted breach of a named individual's personal device. The victim entity is effectively Bennett's personal digital presence/communications.
- Industry
- Government / Political — Former Head of State
Attack summary
Severity: critical — Confirmed exfiltration and publication of private communications from the device of a former head of government constitutes a critical-severity national-security and personal-data incident, involving potentially sensitive political, diplomatic, or personal information at the highest level of public interest.Handala Hack claims to have exfiltrated 1,900 private chat messages directly from Naftali Bennett's personal device, publishing them to contradict his public denial of any breach. No ransom demand was stated; the group's stated motive appears to be political exposure.
Data the group says was taken
AI dossier — extracted from the leak post- Private chat messages (1,900 conversations)
- Personal device communications
- Potentially sensitive political correspondence
The group's post references roughly 1900 proof files.
What the group claims
Naftali Bennett has publicly denied any breach and insists that his phone was never hacked. However, the truth speaks for itself. As Handala Hack, we are exposing 1,900 chats directly from his device to prove beyond any doubt that his claims are false. The evidence is clear and undeniable, Bennett’s attempt to mislead the public…
Sources
Source
Indexed 7 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

