Ransomware victim disclosure
← All victimsShin Bet
Claimed by Handala · listed 2 years ago
Status timeline
- ListedOct 3, 2024
- Data leakeddate unknown
At a glance
- Group
- Handala
- Status
- Data leaked
- Country
- Israel
- Sector
- Government
- Listed on leak site
- Oct 3, 2024
About the victim
AI dossier — public-source company profileShin Bet (Shin Bet Security Agency) is Israel's domestic security and counterintelligence service, responsible for internal security and counter-terrorism operations within Israel.
- Industry
- Government - Intelligence & Security
Attack summary
Severity: critical — Claimed compromise of a national intelligence agency's internal security infrastructure and officer devices represents an existential threat to operational security, officer safety, and state security. If authentic, this would constitute a breach of classified government systems.Handala claims to have compromised Shin Bet's proprietary mobile security system deployed on Android and iOS devices used by agency officers, gaining access to comprehensive device monitoring and control capabilities.
Data the group says was taken
AI dossier — extracted from the leak post- Mobile security system source code/documentation
- Device monitoring infrastructure details
- Officer communications/metadata
- Security protocols and procedures
What the group claims
Shin Bet’s comprehensive security system was hacked! Shin Bet has designed a comprehensive and exclusive security system for itself, which by installing its own application on the Android and iOS phones of its officers, takes over the complete security of the device and gives Shin Bet the possibility of comprehensive and extensive monitoring! This comprehensive…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

