Pro-Iranian Hacker Group Claims Major Data Breach of Former Israeli Military Chief

Alleged leak of thousands of sensitive files raises concerns over cybersecurity and intelligence exposure

Hebrew Institute

3 min read

A large-scale cyber intrusion operation (חדירה סייברית [chadira cyberit]) attributed to an Iranian-linked group has resulted in the release of private and sensitive materials belonging to former IDF Chief of Staff Herzl Halevi. The breach forms part of a broader pattern of “hack-and-leak” campaigns (קמפיינים של פריצה והדלפה [kampanyim shel pritza vehadlafah]) targeting Israeli security figures, with the group known as Handala claiming responsibility for extracting extensive data over an extended period.

According to the group, the operation involved long-term data extraction and surveillance (חילוץ נתונים ומעקב [chilutz netunim u'ma'akov]), culminating in the acquisition of more than 19,000 files, including images, videos, and classified materials. In a statement, Handala said: "For years, Handala has silently and relentlessly been right at the heart of General Herzi Halevi's system, the former Chief of Staff of the Zionist Army, watching, recording, and collecting everything that matters."

The group further stated: "During this time, over 19,000 confidential images and videos have been extracted and archived by Handala, from top-secret meetings, classified files, and even crisis rooms of the Zionist military's General Staff." These claims point to a significant breach of secure environments (פריצה לסביבות מאובטחות [pritza lesvivot me'uvtachot]) and potential exposure of high-level military operations (פעולות צבאיות בדרג גבוה [peulot tzva'iyot bedarg gavoah]).

The leaked materials reportedly include personal documents such as passport images, records of official and unofficial meetings, and visual documentation from visits to military installations. Additionally, the dataset contains evidence of international defense coordination (תיאום ביטחוני בינלאומי [ti'um bitachoni beynleumi]) and travel activity patterns (דפוסי תנועה ונסיעות [dfusei tnu'a venesiot]), including undisclosed diplomatic engagements and private flights.

Some of the content also depicts the former military official in private settings, including family environments and personal trips. This aspect of the leak raises concerns regarding privacy violations in intelligence operations (הפרת פרטיות במבצעי מודיעין [hafarat pratyut b'mivtzaei modi'in]) and the use of personal data as part of broader psychological or strategic pressure tactics (טקטיקות לחץ פסיכולוגיות או אסטרטגיות [taktikot lachatz psikologiyot o estrategiyot]).

Handala also claimed it had "fully identified and archived" the "clear, unblurred faces of hundreds of Israeli war criminal pilots, field commanders and security operatives." This suggests a deliberate effort to compile target identification databases (מאגרי זיהוי מטרות [ma'agrei zihuy matrot]) and expand intelligence profiling capabilities (יכולות פרופיל מודיעיני [yecholot profil modi'ini]) across multiple levels of the Israeli security structure.

The method used to access the materials has not been confirmed, though possibilities include unauthorized entry into a personal mobile device or cloud-based accounts such as Google or iCloud. Such vectors are commonly associated with account compromise techniques (טכניקות פריצה לחשבונות [technikot pritza lecheshbonot]) and exploitation of digital storage vulnerabilities (פגיעויות באחסון דיגיטלי [pgi'uyot be'ichsun digitali]).

This incident follows a similar breach in late March involving former Mossad Director Tamir Pardo, where personal correspondence, contact details, and movement patterns were exposed. These repeated cases illustrate a sustained campaign of targeted intelligence collection (איסוף מודיעין ממוקד [isuf modi'in memukad]) combined with public data dissemination strategies (אסטרטגיות הפצת מידע פומבי [estrategiyot hafatzat meida pumbi]).

Security officials have previously warned that such data is used to construct detailed profiles of individuals for potential exploitation. In February, Israel’s internal security service indicated that Iran systematically gathers personal information to support espionage recruitment efforts (מאמצי גיוס לריגול [ma'amatzey gius lerigul]) and operational planning, concerns reinforced by recent arrests of individuals accused of collaboration.

Additional developments reported on the same day included charges against Israeli citizens allegedly involved in producing explosives and carrying out missions on behalf of Iranian authorities. These cases highlight a broader framework of covert operational networks (רשתות מבצעיות סמויות [reshetot mivtza'iyot smuyot]) and the integration of cyber activity with physical security threats (איומים ביטחוניים פיזיים [iyumim bitachoniyim fiziyim]).

The Handala group, which presents itself as pro-Palestinian, is widely assessed to function as part of Iranian intelligence infrastructure, with operations designed to appear decentralized. Over recent years, it has published large volumes of stolen data, including internal police records, identities of military personnel, and information from institutional databases. This ongoing activity reflects a consistent use of information warfare tactics (טקטיקות לוחמת מידע [taktikot lochemet meida]) aimed at undermining adversaries through exposure and disruption.

For requests or suggestions: pr@hebrew-institute.com

Learn the official language of Israel in 30 days thanks to the most complete Grammar, Vocabulary and Culture courses available. Start speaking Hebrew today!

© Copyright 2026 Hebrew Institute