Ransomware victim disclosure
← All victimsRaz Zimmt (Individual Target) / Israeli National Security Institute
listed as Raz Zimmt’s Chats Leaked to the World · Claimed by Handala · listed 2 months ago
Status timeline
- ListedApr 8, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileThe Israeli National Security Institute (INSS) is a Tel Aviv-based think tank affiliated with Tel Aviv University that conducts policy research on national security, foreign affairs, and strategic issues. Raz Zimmt is identified as the Head of the Iran Desk at INSS. This incident targets an individual researcher rather than an organisation as a whole.
- Industry
- National Security Research & Policy
Attack summary
Severity: high — Confirmed exfiltration and publication of private communications belonging to a named national-security analyst whose work concerns Iran; exposure of such data poses potential intelligence and personal safety risks and constitutes significant sensitive data disclosure.The Handala group claims to have exfiltrated and published the personal WhatsApp messages and X (Twitter) communications of Raz Zimmt, Head of the Iran Desk at the Israeli National Security Institute, framing it as retaliation for his continued employment there.
Data the group says was taken
AI dossier — extracted from the leak post- WhatsApp chat logs
- X (Twitter) private messages
- Personal communications of a named individual
What the group claims
Raz Zimmt, Head of the Iran Desk at the Israeli National Security Institute, Once again, you ignored our warnings, and now you’re facing the consequences. We repeatedly told you that your only way out was to leave the Israeli National Security Institute, but you underestimated us. Now, every single one of your WhatsApp and X…
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

