







{"id":24268,"date":"2025-06-22T07:46:58","date_gmt":"2025-06-22T07:46:58","guid":{"rendered":"https:\/\/cissar.com\/?p=24268"},"modified":"2025-06-25T06:45:22","modified_gmt":"2025-06-25T06:45:22","slug":"handala","status":"publish","type":"post","link":"https:\/\/cissar.com\/index.php\/2025\/06\/22\/handala\/","title":{"rendered":"Handala"},"content":{"rendered":"\n<p><strong>Summary<\/strong><br>An Iran-linked cyber hacktivist group known as Handala (also referred to as Hanzala) has recently claimed responsibility for a spate of high-stakes attacks targeting Israeli organizations, including critical infrastructure and government-affiliated entities. These digital strikes reflect deeper geopolitical tensions following military confrontations between Iran and Israel.<\/p>\n\n\n\n<p><strong>Key Developments<\/strong><\/p>\n\n\n\n<p>1.<strong>Massive Data Breaches<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Handala reportedly exfiltrated data from Israeli petroleum conglomerate Delek Group and subsidiary Delkol, leaking some 300,000 documents and approximately 2\u202fTB of internal files (<a href=\"https:\/\/www.scworld.com\/brief\/handala-hacking-group-asserts-attacks-against-israel\" data-type=\"link\" data-id=\"https:\/\/www.scworld.com\/brief\/handala-hacking-group-asserts-attacks-against-israel?utm_source=chatgpt.com\">scworld.com<\/a>, <a href=\"https:\/\/www.timesofisrael.com\/iranian-hackers-broadcast-rocket-sirens-odes-to-terrorism-in-some-20-kindergartens\">timesofisrael.com<\/a>).<\/code><\/pre>\n\n\n\n<p>2.<strong>Kindergarten PA System Breach &amp; Text Alerts<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>The group claimed to have hacked public address systems in at least 20 Israeli kindergartens, broadcasting rocket sirens and threatening messages over emergency channels (<a href=\"https:\/\/www.iranintl.com\/en\/202501265679\">iranintl.com<\/a>).<\/code><\/pre>\n\n\n\n<p>3.<strong>Attacks on High\u2011Value Military Target<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>In prior campaigns, Handala asserted it compromised the Israeli military\u2019s radar and Iron Dome systems, alongside penetrating an electronics firm Rada Electronics (<a href=\"https:\/\/www.presstv.ir\/Detail\/2024\/11\/26\/737960\/How-Handala-hackers-infiltrated-israeli-spy-military-apparatus\">presstv.ir<\/a>).<\/code><\/pre>\n\n\n\n<p><strong>Motivations &amp; Tactics<\/strong><\/p>\n\n\n\n<p>Ideological drive: Handala identifies with pro\u2011Palestinian and Iranian nationalist agendas, often acting in response to regional military events (e.g. strikes on Iranian nuclear sites or Hezbollah incidents) (<a href=\"https:\/\/thecyberexpress.com\/iran-threat-group-handala-targets-israel\">thecyberexpress.com<\/a>).<\/p>\n\n\n\n<p>Reputation building: The group frequently defaces websites, leaks sensitive data including personal info of senior Israeli politicians such as Benny Gantz and Gabi Ashkenazi and claims high-profile infrastructure hacks (<a href=\"https:\/\/thecyberexpress.com\/iran-threat-group-handala-targets-israel\">thecyberexpress.com<\/a>).<\/p>\n\n\n\n<p>Psychological warfare: Beyond data theft, Handala broadcast audio alerts like sirens and alarm messages to incite fear among civilians (<a href=\"https:\/\/www.iranintl.com\/en\/202501265679\">iranintl.com<\/a>).<\/p>\n\n\n\n<p><strong>Impact &amp; Verification<\/strong><br>Unverified claims: Many of the group&#8217;s assertions particularly about military systems and nuclear facilities lack independent confirmation. Israeli authorities either deny these incidents or indicate investigations are ongoing (<a href=\"https:\/\/www.iranintl.com\/en\/202501265679\">iranintl.com<\/a>).<br><br>Demonstrated breaches: The kindergarten PA and Delek data leaks are supported by statements from affected entities, corroborated through official and media disclosures (<a href=\"https:\/\/www.scworld.com\/brief\/handala-hacking-group-asserts-attacks-against-israel\">scworld.com<\/a>).<br><br>Regional ripple effect: Israel\u2019s National Cyber Directorate is working with private firms and government avenues to mitigate ongoing threats and reinforce critical infrastructure defenses (<a href=\"https:\/\/www.iranintl.com\/en\/202501265679\">iranintl.com<\/a>).<\/p>\n\n\n\n<p><strong>Geopolitical Context<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>These cyberattacks occur amid increased hostilities\u2014including Israeli airstrikes on Iranian facilities and Iran\u2019s rocket assaults on Israel\u2014marking the cyber domain as a key battleground .\n\nHandala exemplifies Iran\u2019s use of proxy-like cyber operations, reflecting a pattern where nation-states leverage hacktivist groups to advance geopolitical motives while maintaining deniability (<a href=\"https:\/\/thecyberexpress.com\/iran-threat-group-handala-targets-israel\">thecyberexpress.com<\/a>).\n<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"280\" src=\"https:\/\/cissar.com\/wp-content\/uploads\/2025\/06\/image-1024x280.png\" alt=\"\" class=\"wp-image-24269\" srcset=\"https:\/\/cissar.com\/wp-content\/uploads\/2025\/06\/image-1024x280.png 1024w, https:\/\/cissar.com\/wp-content\/uploads\/2025\/06\/image-300x82.png 300w, https:\/\/cissar.com\/wp-content\/uploads\/2025\/06\/image-768x210.png 768w, https:\/\/cissar.com\/wp-content\/uploads\/2025\/06\/image.png 1099w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Looking Ahead<\/strong><br>As regional tensions continue, Handala and similar groups may escalate further targeting even more sensitive systems like nuclear, defense, or financial networks. Cross-border coordination between governments and cyber security agencies is vital for detecting, attributing, and mitigating these evolving hybrid threats.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><em>Stay tuned for updates as investigations unfold and more technical insights emerge on the methods and impact of these attacks.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SummaryAn Iran-linked cyber hacktivist group known as Handala (also referred to as Hanzala) has recently claimed responsibility for a spate of high-stakes attacks targeting Israeli organizations, including critical infrastructure and government-affiliated entities. These digital strikes reflect deeper geopolitical tensions following military confrontations between Iran and Israel. Key Developments 1.Massive Data Breaches 2.Kindergarten PA System Breach [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24271,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-24268","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-middle-east"],"_links":{"self":[{"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/posts\/24268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/comments?post=24268"}],"version-history":[{"count":4,"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/posts\/24268\/revisions"}],"predecessor-version":[{"id":24317,"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/posts\/24268\/revisions\/24317"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/media\/24271"}],"wp:attachment":[{"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/media?parent=24268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/categories?post=24268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cissar.com\/index.php\/wp-json\/wp\/v2\/tags?post=24268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}