A Policy-Oriented Think Tank Addressing Foreign Policy and National Security Issues for a Safe Israel

Influence Operations Disguised as Cyber Operations

The Handala Hacking Group as a Case Study of Iran’s Cyber Proxy Strategy During the 2026 War with Israel and the United States
Cyber illustration

Introduction: Cyber as an Arena of Asymmetric Warfare in the Israel-Iran Conflict

On March 19, 2026,[1] the FBI announced the seizure of four domains used by the Iranian cyber persona “Handala,” which is linked to Iran’s Ministry of Intelligence, to carry out cyberattacks, disseminate stolen information, and run influence campaigns.[2] The U.S. move followed a destructive cyberattack attributed to the group against the American medical-device company Stryker, which caused major operational disruption. According to U.S. authorities, the domains were used not only to claim responsibility for attacks, but also to issue threats, expose personal information, and incite violence as part of a broader Iranian apparatus of information and psychological warfare in cyberspace.[3] The FBI’s exposure takes on added significance in the context of the Israel-U.S. war with Iran that began on February 28, 2026, in which this persona has been an integral part of the Iranian effort.

The “Handala” cyber group (from the Arabic حنظله, Handala, named after the comic-book figure identified with the Palestinian cause) reflects a distinct Iranian operating model in the digital arena: the use of cyber personas that are not formally presented as official arms of the regime, yet operate on its behalf against Israel and the Iranian opposition in exile, and at the same time are used to bolster the regime’s domestic legitimacy. Handala’s activity since the outbreak of the Israel-Hamas war in October 2023 has shown how Tehran uses cyber operations not only as a tool of influence and operational warfare, but also as a means of securing gains in the asymmetric arena vis-à-vis Israel.

Handala’s activity during Operation Roaring Lion is a continuation of this policy. During the war, the persona has emerged as Iran’s principal offensive cyber instrument and as an important asset in Iran’s core strategic effort. Handala has been employed against the regime’s main adversaries—Israel, the United States, and the Iranian opposition—and has mounted separate operations against each of them.

Iran appears to be gradually relinquishing the plausible deniability that such personas once provided and instead is leveraging their visibility to amplify the media and psychological impact of its operations. This represents a relatively recent shift that has taken shape over the past year.

This paper, together with the previous installment in the series,[4] examines the Iranian regime’s approach to cyberspace as a domain of warfare and how that approach has evolved in response to emerging challenges. It does so through a case study of the “Handala” persona, operated by Iran’s Ministry of Intelligence since late 2023 and likely its most significant offensive cyber instrument since then.

Cyber Personas as a State Instrument: Between Deniability and Direct Use

Despite the ceasefire between Israel and Iran following the twelve-day war in June 2025, Tehran continued to target Israeli interests through cyber operations, intelligence activity, and influence campaigns. A central component of this effort has been the use of hacker groups and cyber personas that present themselves as independent actors but in practice advance the interests of the Iranian regime.

One of the most prominent groups in this context is “Handala,” which has portrayed itself as a pro-Palestinian activist collective with only a vague connection to Iran. However, shifts in its operational pattern—alongside intelligence disclosures and analyses by cybersecurity firms—have pointed to a close link between the group and elements within Iran’s security apparatus, particularly the Ministry of Intelligence.

The persona has been active since at least December 2023,[5] roughly two months after the outbreak of the war between Israel and Hamas. From its inception, the group established a presence on social media, primarily on X and Telegram, which it has used to disseminate influence-oriented messaging, issue threats, and leak data which it claims was obtained through cyber intrusions.

In the period preceding the direct Israel-Iran war in the summer of 2025, Handala operated as part of a broader ecosystem of Iranian cyber personas[6] targeting Israel. Following the ceasefire, however, it gradually consolidated its position as one of the central actors in Iran’s cyber campaign against Israel. This trend intensified further with the outbreak of direct hostilities between Iran, Israel, and the United States on February 28, 2026.

During the current war, the group has been linked to cyberattacks against a range of Israeli targets, including public institutions, private companies, and civilian data repositories, as well as operations against Western entities perceived as supportive of Israel. These activities included hacking and leaking data, defacing websites, and attempts to cause damage to civilian infrastructure. At the same time, the group continued to carry out influence campaigns on social media that were designed to amplify the psychological impact of its operations.

Iran’s Offensive Cyber Apparatus

Iran maintains an offensive cyber apparatus that includes operational units, some affiliated with the Ministry of Intelligence and others with the Islamic Revolutionary Guard Corps. These units conduct cyber operations for a range of purposes—espionage, influence, disruption, and even destruction of data—while relying on cyber personas, hacker groups, and various cover mechanisms designed to obscure any direct link to the Iranian regime.[7]

Many of these units have been exposed in recent years by Western governments, media outlets, and international cybersecurity firms—including Microsoft—which have identified direct links between ostensibly independent personas and Iranian state actors. A notable example is the 2020 cyberattack on the Israeli insurance company Shirbit. The operation was carried out by a unit associated with the Ministry of Intelligence, referred to by cybersecurity researchers as “Pink Sandstorm,” while responsibility was publicly claimed by the cyber persona “Black Shadow,” created to distance the operation from Tehran.[8]

In other words, the hackers from the unit known as Pink Sandstorm carried out the attack but publicly operated under the guise of a group called Black Shadow, which appeared unconnected to Tehran. The hackers launched a public Telegram channel through which they displayed their breach of the company and which at the same time gave them a cover story supporting the impression that they are an independent entity.

The model of reliance on cyber personas and hacker groups that appear to operate independently has become a central component of Iran’s offensive cyber strategy in recent years. These personas conduct hack-and-leak campaigns, website defacements, and influence operations across social media platforms. Handala is currently the most prominent example of this approach.

The Evolution of Handala: From “Palestinian” Proxy to Overt Iranian Instrument

The persona’s name is drawn from the Arab comic figure Handala (حنظلة), a potent symbol of Palestinian identity associated with displacement and perceived injustice. The choice is deliberate: it anchors the group’s activity in an anti-Israel political narrative while fostering identification with the Palestinian cause.[9]

Since its launch in late 2023, Handala’s activity has been difficult to track systematically, in part due to repeated account suspensions on X and Telegram and the creation of replacement channels. Still, early indicators appeared as early as December 2023. Cyberint[10] identified a December 26 post in which the group expressed support for Hamas and stated that it had begun operating against Israel following the killing of IRGC officer Sayyed Razi Mousavi in Syria, in a strike attributed to Israel.[11]
 
At the same time, Israel’s National Cyber Directorate issued a warning (December 25, 2023) about a phishing campaign attributed to an Iranian offensive actor, which used a malicious file labeled “handala.exe” while impersonating the company F5.[12] Although the persona was not formally linked to the incident, both the naming and the operational pattern suggest a possible connection to its early activity. During this period, the group also posted mocking messages directed at Israel’s cyber authorities and even signaled impending attacks in advance, using the tag “F5.”[13]

In its early phase, Handala positioned itself as part of the “axis of resistance,” emphasizing its connection to the Palestinian struggle rather than any direct affiliation with Iran. This posture came at a time when Iran was not yet prioritizing overt, direct attacks on Israel, at least until the killing of senior Quds Force commander Mohammad Reza Zahedi in April 2024.

Over the course of 2024, however, a clearer picture of its organizational affiliation emerged. Multiple reports linked the persona to the threat group Storm-0842,[14] which operates under Iran’s Ministry of Intelligence and is also associated with other personas such as “DarkBit” and “Homeland Justice,”[15] both used in recent years for influence operations and destructive cyber campaigns on the international stage.

Over time, particularly following the direct confrontation between Israel and Iran in the summer of 2025, the group’s activity has aligned more clearly with Iranian regime interests. This shift reflects a gradual transition from a nominally “Palestinian” proxy persona to a more direct operational instrument of Iran. As shown below, Handala’s activity during Operation Roaring Lion provides further evidence that this trajectory is continuing.

Operationally, Handala targets a broad range of Israeli entities, including private companies, government bodies, and public institutions. Its activities include data theft, website defacement, and, at times, influence operations. Notable early examples include the leak of personal data belonging to licensed firearm holders in Israel (February 2025)[16] and claims of a breach involving servers linked to the Soreq nuclear facility (September 2024).[17]

The group also exploits network access for influence influence. In January 2025, it penetrated the systems of the company Maagar-Tech and broadcast sirens and messages in Arabic[18] over public address systems. In June 2024, threatening messages were sent through the systems of the Ma’ale Yosef Regional Council in northern Israel,[19] in an operation attributed to a breach of the company My City.[20]

It should be noted that the group at times exaggerates the scope of its achievements and has claimed responsibility for attacks that cannot be independently verified. That said, it often presents some evidence of access, which contributes to its perceived credibility and enhances its influence.

Handala’s Operating Model: A Low-Tech, High-Impact Strategy

Handala’s activity fits within a broader Iranian offensive cyber architecture, particularly units operating under the Ministry of Intelligence that specialize in destructive operations designed to generate impact. Several notable cases illustrate this pattern:

The 2022 cyberattack on Albania, carried out in response to its hosting of the opposition group Mujahedin-e Khalq, involved sustained penetration of government networks, data destruction, and leaks —ultimately leading to a rupture in diplomatic relations between the two countries.[21]

The 2023 attack on the Technion, conducted under the “DarkBit” persona and framed as a ransomware operation, appears to have been intended primarily to inflict damage on Israel rather than to generate financial gain.[22]

More broadly, cyberspace has long served as a central arena for Iran in its ongoing confrontation with Israel. For years, the two sides engaged in activity below the threshold of open conflict, relying on proxies and deniable personas. Even during periods of direct confrontation, the cyber domain continues to function as a semi-distinct arena that allows for flexibility and deniability.

In this context, cyber operations can also compensate for damage inflicted on Iran’s conventional military capabilities during active conflict, while helping to restore domestic standing and project strength externally. Groups such as Handala enable Iran to generate psychological and deterrent effects at relatively low cost and limited risk, while preserving plausible deniability.

Tools and Tactics

A March 12, 2026 study conducted by Check Point provides insight into the operating methods of Iran’s primary offensive cyber persona, Handala. The findings indicate a preference for relatively simple techniques aimed at achieving quick, opportunistic gains. According to Check Point’s researchers, the Handala hackers rely on credential harvesting, deploy dedicated wipers, and carry out manual defacement of networks they have penetrated.[23]

This approach is consistent with broader patterns across Iranian offensive cyber activity in other theaters. It is particularly evident in operations targeting states with advanced cyber infrastructure and robust defenses, such as Israel and the United States. In these cases, Iranian actors tend to exploit short-lived access opportunities and rely on readily available, low-complexity tools rather than invest in more sophisticated capabilities that require greater resources, longer development cycles, and carry higher risk of exposure .

This characteristic aligns with the broader model of Iranian proxy activity in the cyber arena: prioritizing influence-oriented impact and speed of execution over technical sophistication, while exploiting human vulnerabilities, organizational weaknesses, and deficiencies in identity and access management.

Operation Roaring Lion: Acceleration, Exposure, and the Erosion of Plausible Deniability

From the first day of the war, Handala announced it would launch cyber offensives and claimed to have targeted sites in Jordan.[24] In the days that followed, it continued to report attacks across multiple countries, with Israeli targets clearly the focus.

The volume of claims and the rapid pace of publication reflect a familiar pattern: the blending of actual cyber activity with influence operations built on a high frequency of attack claims—some unverifiable and at times unsupported.

Case Study: The INSS Breach and the Logic of Influence-Oriented Impact

The most significant attack claimed by the group inside Israel was likely a breach of servers at the Institute for National Security Studies (INSS) at Tel Aviv University. According to Handala, large volumes of data were exfiltrated, and at least one of the Institute’s social media accounts was compromised.[25]

Following the announcement, the group claimed to have obtained email correspondence from senior figures associated with the institute,  such as:

  • Raz Zimmt – Director of the Iran and the Shiite Axis Program at INSS and a former senior officer in Israeli military intelligence. The attackers claimed to have obtained correspondence allegedly indicating ties with Reza Pahlavi and Iranian actors, and presented documents and messages as evidence.[26]

  • Tamir Hayman – former head of Israeli military intelligence and current head of the INSS. The group released screenshots of correspondence and official documents and claimed to have accessed a substantial volume of information.[27]

  • Laura Gilinski – Deputy Director for Strategic Partnerships at INSS. The group claimed to have accessed approximately 100,000 emails from her account and highlighted her alleged past affiliation with the Mossad.[28]

  • Ilan Steiner – Chief Finance and Operations Officer at the INSS, who Handala claimed had served as Budgets Director in the Mossad. It claimed to have obtained roughly 50,000 of his emails, allegedly containing sensitive information, including material related to Mossad activity.[29]

The link between the breach of INSS servers and the theft of email correspondence has not been fully established. However, the uniform format of the materials released suggests the data may have been obtained through access to the institute’s organizational email system, rather than through direct compromise of individual devices.

The choice of senior figures working on Iran as targets for the hack appears to have been deliberate. It reflects an attempt to create an effect at both influence and intelligence dimensions. In publicizing the breach, Handala emphasized that it possessed “strategic and classified” material with operational implications. This messaging likely seeks to offset Iran’s intelligence disadvantage vis-à-vis Israel, as reflected in recent military operations.

Materials published by the Handala hacking group as proof of its data breaches.

Additional Operations Carried Out Against in Israel

Beyond the INSS incident, Handala has claimed responsibility for a series of additional operations, including:

The breach and defacement of servers belonging to the Gihon water company,[30] including data theft; intrusion into databases associated with the Sanz Hasidic community;[31] and defacement of the website of the Academy of the Hebrew Language.[32]

The group has also issued claims regarding additional operations. In many cases, however, the available evidence does not clearly support the scope or nature of the attacks as described:

  • Exposure of alleged Israeli Air Force personnel – the group claimed to have obtained full details of 50 Israeli pilots involved in strikes in Iran.[33] Cyber researcher Erez Dassa found that the data was outdated and sourced from a job-search website, and that the individuals were not necessarily pilots.[34]

  • Attack on Hebrew University servers – the persona claimed access to data on “hundreds of thousands” of students and faculty and further claimed to have exfiltrated and deleted tens of terabytes of information. It framed the operation as part of the ongoing war between Israel and Iran.[35]

  • Breach of “IDF Persian-language spokesperson accounts” – the group claimed access to these accounts and asserted it had obtained account details and contact information for alleged “agents within the axis of resistance.”[36] The evidence it released suggests a possible compromise of a mobile device, though this cannot be confirmed. Israeli reporting indicates the breach occurred roughly six months earlier and involved two devices.[37]

It should be noted that a significant portion of these claims has not been independently verified, and in some cases may rely on recycled data or be entirely unfounded. This pattern is consistent with the group’s operating model, which combines real cyber activity with the amplification, and at times fabrication of achievements.

Expanding the Battlespace: Attacks Against the United States and Global Targets

Handala claimed responsibility for a large-scale cyberattack against the U.S. medical device company Stryker. According to the group, it wiped out data from more than 200,000 systems, servers, and mobile devices across the globe. Handala framed the attack as retaliation for an incident at a girls’ school in Minab, Iran, and as revenge for Iranian civilian casualties. Stryker confirmed it had experienced a cyber incident that disrupted operations. Reporting indicates the intrusion was carried out via Microsoft-based management systems. Employees were instructed to remove suspicious applications, and mobile devices connected to the organization’s Outlook environment were also affected. Thousands of employees were told to stay home following the incident.[38]

According to an assessment by Coalition Insurance, the attack likely relied on compromised credentials for administrative interfaces, allowing the attackers to carry out large-scale deletion using the organization’s own internal tools rather than dedicated wiper malware.[39] Such credentials could have been obtained through established methods, including spear-phishing, purchases on darknet markets, weak password exploitation, or brute-force attempts.

This incident illustrates Handala’s operating model: leveraging legitimate system access to generate significant destructive impact, while minimizing investment in advanced offensive capabilities.

Following the attack on the U.S. company, the FBI announced on March 19, 2026 that it had seized four domains used by Handala. This move reflects a shift from a primarily defensive posture to more proactive action against the cyber infrastructure of adversarial states. In this case, the objective was not only to disrupt technical operations but also to degrade the persona’s information infrastructure—its ability to publicize achievements, disseminate stolen data, and conduct threats and doxing (the deliberate publication of personal or sensitive information about an individual or organization, typically without consent, in order to harm them, apply pressure, intimidate, or expose their identity). According to FBI documents, the domains were part of a coordinated influence campaign that included calls to target journalists, regime opponents, and individuals identified with Israel.[40]

Recent reporting indicates that Handala’s activity is no longer confined to data leaks or website defacement but now includes elements of direct incitement to violence and personal pressure on targets. According to findings by U.S. authorities, the seized domains were used to publish personal details of approximately 190 individuals linked to Israel’s security establishment, alongside explicit threats and calls for harm against those individuals. Reports also indicate that the group incorporated intimidation tactics into its messaging, including threats against American civilians and attempts to project links to international criminal actors. These findings point to an expansion of Handala’s activity from “classic” cyber operations to a hybrid model combining attack, influence, and personal deterrence.[41]

The group’s response—resuming operations within a short time through alternative domains[42]—underscores the limited effectiveness of such measures against state or proxy actors. Experts note that Iranian groups of this kind are accustomed to losing digital infrastructure and rapidly rebuilding substitutes, meaning the practical impact is often temporary. In this sense, the U.S. action carries greater value at the declarative and legal levels—as a formal act of attribution and a means of applying pressure—than as a tool for sustaining disruption of activity over time.[43]

Cyber as a Tool of Internal Repression: Attacks on the Iranian Opposition

During Operation Roaring Lion, Handala announced that it had exposed the operator of the popular Persian-language channel Vahid Online, as well as the identities of its followers.[44] The channel, which operates across multiple platforms including Telegram, provides frequent updates on developments inside Iran, particularly during periods of conflict. It frequently publishes content that is embarrassing for the regime, including documentation of Israeli strikes and footage from the large-scale protests of January 2026. Handala claimed to have identified the channel’s operator, his location, and the identities of Iranians who had provided him with materials.


The Vahid unveiling was subsequently reported in Iranian state-affiliated media. According to the Tasnim News Agency, the information provided by the group was used for operational purposes, including missile fire directed at the location from which the channel allegedly operates (reported to be in Israel), as well as the arrest of Iranians who had sent it material in violation of Iranian law.[45] The claim that the group provided intelligence that enabled operational action effectively amounts to a public acknowledgment of Handala’s affiliation.

This is not the first instance in which Handala has operated against opposition activists. In the summer of 2025, the persona hacked Telegram accounts belonging to staff of the opposition-affiliated outlet Iran International in London and published extensive personal information about them.[46] The operation was likely intended to reinforce the regime’s standing domestically by targeting a media outlet associated with the Iranian opposition and influential in shaping public opinion. In this context, it has also been revealed that one of Handala’s lead activists maintains ties with Iran’s cyber police (FATA).[47]

Contrary to the view that sees technological sophistication as a central condition for effectiveness in cyberspace, the Handala case shows that even relatively limited capabilities can generate significant impact when combined with an aggressive influence campaign and the presentation of achievements—real or fabricated. This pattern fits within Iran’s strategy of asymmetric warfare and underscores that power in cyberspace is measured not only by technological capabilities, but also by the ability to shape perception, create deterrence, and undermine the adversary’s sense of security.

Conclusions: Cyber Power as a Function of Influence, Not Technological Capability

Analysis of Handala’s operating model suggests it is not an advanced cyber actor in the conventional technological sense, but rather a unit operating within a broader Iranian strategy that combines operational cyber activity with influence warfare. Despite the absence of “game-changing” capabilities, its activity highlights several core features with strategic implications, particularly in the context of the confrontation with the United States and Israel.

Against the United States: The Logic of Imposing Costs

Handala’s activity against U.S. targets illustrates how cyber operations enable Iran to impose direct costs on the United States beyond the immediate geographic theater of conflict. By targeting civilian companies and non-military infrastructure, Iran expands the battlespace while inflicting damage on American interests at relatively low cost and with limited risk of escalation.

The attack on Stryker illustrates this pattern clearly: by leveraging credential harvesting and the organization’s own internal tools, the attackers were able to generate widespread disruption without relying on advanced offensive capabilities. In doing so, Handala demonstrates Iran’s ability to sustain offensive cyber activity even during active military confrontation—including under conditions in which its kinetic capabilities or cyber infrastructure may be degraded—while maintaining functional continuity in the cyber domain.

Against Israel: Influence Warfare and Bridging Capability Gaps

Handala’s cyber activity should be understood as one element within a broader campaign against Israel that also includes kinetic measures, particularly missile fire. In this context, cyber is not a substitute but a supporting instrument, used primarily for its psychological effect: to undermine public confidence, reinforce a sense of exposure, and project achievements—real or fictitious—into the public sphere.

Operations such as data leaks, hacks of civilian systems, and the dissemination of threatening messages serve not only operational purposes but also serve to narrow the perception of the gap between Israeli and Iranian capabilities. In this sense, Handala’s activity can be read as part of a broader Iranian effort to construct a narrative of “balance of power,” directed both inward at domestic audiences and outward toward Israeli society, and to entrench the idea of a sustained confrontation in which Iran retains both resilience and influence.

Against the Iranian Opposition: Disruption and Erosion of Influence

A substantial share of what the regime defines as “problematic ties” between external actors and individuals inside Iran is mediated through online platforms, making cyber activity in this domain particularly effective. Operations against opposition channels are intended first and foremost to disrupt their activity and to undermine their credibility by exposing sensitive or compromising information. In the case of Vahid Online, the exposure also served a domestic deterrent function, framed as a warning of potential arrests for individuals who had submitted content to the channel. Even if such arrests did not occur, the signal itself may deter future cooperation with external outlets.

In conclusion, Handala’s activity underscores that the contribution of cyber operations to Iran’s strategy does not depend primarily on technological sophistication, but on the ability to combine targeted attacks, the exploitation of systemic weaknesses, and sustained influence amplification. This pattern reinforces a broader conclusion: in the cyber domain, effectiveness is measured not only by the scale of direct damage, but by the ability to shape perception, generate deterrence, and influence the overall dynamics of conflict.


[1] The information in this paper is current as of March 21, 2026. The author thanks Daniel Hirschfeld for his assistance in the research for this paper.
[2] “Justice Department Disrupts Iranian Cyber-Enabled Psychological Operations,” U.S. Department of Justice, March 19, 2026.
https://www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations
[3] “FBI Update on Iran-Linked Hackers Who Brought Down Machines of America’s Largest Medical Device Company Stryker; Says Iran Thought They Could Hide Behind…,” Times of India, March 20, 2026.
https://timesofindia.indiatimes.com/technology/tech-news/fbi-update-on-iran-linked-hackers-who-brought-down-machines-of-americas-largest-medical-device-company-stryker-says-iran-thought-they-could-hide-behind-/articleshow/129695549.cms
[4] Cyber as the Continuation of War by Other Means: The Iranian ‘Handala’ Activity,” Jerusalem Institute for Strategy and Security (JISS), August 28, 2026.
https://jiss.org.il/davidi-cyber-as-the-continuation-of-war-by-other-means
[5] “Handala Hack: What We Know About the Rising Threat Actor,” Cyberint, July 16, 2024.
https://cyberint.com/blog/threat-intelligence/handala-hack-what-we-know-about-the-rising-threat-actor
[6] A “persona,” or “identity” in this context, refers to a social media or forum profile with a unique name and symbol, ostensibly representing a hacker group responsible for cyberattacks. Such personas typically include statements or hints regarding the motivations behind the attack (ideological or financial) and may suggest the identity of the perpetrators.
[7] “Iran Surges Cyber-Enabled Influence Operations in Support of Hamas,” Microsoft, February 26, 2026.
https://www.microsoft.com/en-us/security/security-insider/threat-landscape/iran-surges-cyber-enabled-influence-operations-in-support-of-hamas
[8] “The Iranian Attack Group Black Shadow,” Israel National Cyber Directorate, April 9, 2024.
https://www.gov.il/BlobFolder/reports/alert_1727/he/ALERT-CERT-IL-W-1727.pdf
[9] “Handala,” Wikipedia, last accessed March 19, 2026.
https://he.wikipedia.org/wiki/Handala
[10] “Handala Hack: What We Know About the Rising Threat Actor”, Cyberint, July 16, 2024. https://cyberint.com/blog/threat-intelligence/handala-hack-what-we-know-about-the-rising-threat-actor
[11] “Iran: Senior IRGC Commander Killed in Israeli Strike in Syria,” Ynet News, December 25, 2023.
https://www.ynet.co.il/news/article/hkipdfdwt#google_vignette
[12] “Urgent Alert: An Iranian Attack Group Has Conducted a Targeted Phishing Campaign Impersonating the Company F5,” Israel National Cyber Directorate, December 25, 2023.
https://www.gov.il/he/pages/alert_1691
[13] “Operation HamsaUpdate: A Sophisticated Campaign Delivering Wipers Puts Israeli Infrastructure at Risk”, Intezer, December 20, 2023. https://intezer.com/blog/stealth-wiper-israeli-infrastructure
[14] “Iran steps into US election 2024 with cyber-enabled influence operations”, Microsoft, August 9, 2024. https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/5bc57431-a7a9-49ad-944d-b93b7d35d0fc.pdf
[15] “Iran surges cyber-enabled influence operations in support of Hamas”, Microsoft, February 26, 2024. https://www.microsoft.com/en-us/security/security-insider/threat-landscape/iran-surges-cyber-enabled-influence-operations-in-support-of-hamas
[16] “Data Leak Exposes Details of Thousands of Firearm Owners in Israel,” People & Computers, March 9, 2025. https://www.pc.co.il/news/426334
[17] “Report: Iranian Hackers Claim to Have Breached a Nuclear Research Center in Israel,” Ynet News, September 30, 2024. https://www.ynet.co.il/digital/technews/article/hkz211m00cc
[18] “Iranian Hackers Broke into Kindergarten PA Systems and Broadcast ‘Code Red,” Kan 11 News, January 26, 2025.
https://www.kan.org.il/content/kan-news/local/852212
[19] “After the Fires in the North: An Unusual Message Was Distributed via the Ma’ale Yosef Regional Council App,” Israel Hayom, June 1, 2024.
https://www.israelhayom.co.il/tech/tech-news/article/15843626
[20] “Update: The Handala Group Claims Responsibility for Sending Messages to Civilians and Says It Breached the System of the Company My City, Through Which It Distributed Approximately Half a Million Messages…” (post from the Telegram channel “Cyber News – Erez Dassa”), Telegram, June 3, 2024.
https://t.me/CyberSecurityIL/5210
[21] “Albania cuts Iran ties over cyberattack, U.S. vows further action”, Reuters, September 7, 2022. https://www.reuters.com/world/albania-cuts-iran-ties-orders-diplomats-go-after-cyber-attack-pm-says-2022-09-07
[22] “Israel National Cyber Directorate Investigation into MuddyWater Activity in Israel,” March 9, 2023.
https://www.gov.il/he/pages/_muddywater
[23] ” ‘Handala Hack’ – Unveiling Group’s Modus Operandi”, Check Point, March 12, 2026. https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi
[24] “Cyber Advisory: Increased Cyber Risk Amid U.S.–Israel–Iran Escalation”, Sophos X-Ops, March 1, 2026. https://www.sophos.com/en-us/blog/cyber-advisory-increased-cyber-risk-amid-u-s-israel-iran-escalation
[25] “The Handala Group Claims It Breached the Institute for National Security Studies…” (post by “Cyber News – Erez Dassa” on Telegram), Telegram, March 3, 2026.
https://t.me/CyberSecurityIL/8560
[26] “Handala’s Access to Documents of Joint Israeli Projects with Reza Pahlavi” (original in Persian – دسترسی حنظله به اسناد پروژه‌های مشترک اسرائیل با رضا پهلوی, post on the X account of Fars News Agency), X, March 13, 2026.
https://x.com/FarsNews_Agency/status/2032430961699271060
[27] “Handala Targeted the Former Head of Israeli Military Intelligence” (original in Persian – حنظله سراغ رئیس سابق آمان رفت, post on the X account of Fars News Agency), X, March
[28] “Confidential Documents of the Most Important Female Intelligence Figure in the Mossad Exposed” (original in Persian – اسناد محرمانه حیاتی‌ترین چهره‌ اطلاعاتی موساد فاش شد), Fars News Agency, March 15, 2026.
https://farsnews.ir/miladmaniee/1773567507970306944
[29] “Handala: The Mossad’s Secret Archive Exposed” (original in Persian – حنظله: گنجینه مخفی موساد افشا شد, from the Telegram channel of Tasnim News Agency), Telegram, March 17, 2026.
https://t.me/Tasnimnews/397632
[30] “The Handala Group Claims It Breached the Gihon Company (the water and sewage company of the Jerusalem area)…” (post by “Cyber News – Erez Dassa” on Telegram), Telegram, March 7, 2026.
https://t.me/CyberSecurityIL/8577
[31] “The Handala Group Claims It Breached Databases of the Sanz Hasidic Community…” (post by “Cyber News – Erez Dassa” on Telegram), Telegram, March 6, 2026.
https://t.me/CyberSecurityIL/8573
[32] “Iranian Hackers Breached the Popular Website: ‘No Need to Learn Hebrew Anymore’,” Maariv, March 11, 2026. https://www.maariv.co.il/economy/tech/article-1294745
[33] “Handala Exposes Information on 50 Israeli Pilots” (original in Persian – افشای اطلاعات ۵۰ خلبان اسرائیل توسط حنظله, post on the X account of Fars News Agency), X, March 10, 2026.
https://x.com/FarsNews_Agency/status/2031246808458944575
[34] The Handala Group Publishes Information Allegedly Belonging to 50 Soldiers Serving in the Air Force; in Practice, the Data Is Old…” (post on the Telegram channel “Cyber News – Erez Dassa”), Telegram, March 10, 2026. https://t.me/CyberSecurityIL/8589
[35] “Handala Breached Data of Hundreds of Thousands of Zionist Students and Faculty” (original in Persian – حنظله اطلاعات صدها هزار دانشجو و استاد صهیونیست را هک کرد), Fars News Agency, March 13, 2026.
https://farsnews.ir/miladmaniee/1773403477241094231
[36] “The Persian-Language Pages of the Zionist Army Were Hacked…” (original in Persian – صفحه‌های فارسی ارتش صهیونیستی هک ش, post on the X account of Fars News Agency), X, March 6, 2026.
https://x.com/FarsNews_Agency/status/2029965618586284372
[37] “Iranian Hackers Breach Phone of IDF Spokesperson Unit Soldier,” Ynet, March 12, 2026.
https://www.ynet.co.il/news/article/hkxi005gqze
[38] “Telegram Hacktivist Activity Timeline of Iran – Israel & US War”, SOC Radar, Last Updated – March 13, 2026. https://socradar.io/blog/telegram-activity-timeline-iran-israel-us-war
[39] “How Infostealers May Have Opened the Door to the Stryker Wipe”, Joe Toomey, Coalition, March 12, 2026. https://www.coalitioninc.com/blog/security-labs/how-infostealers-may-have-opened-door-stryker-wipe
[40] “FBI update on Iran-linked hackers who brought down machines of America’s largest medical device company Stryker; says: Iran thought they could hide behind…”, Times of India, March 20, 2026.
https://timesofindia.indiatimes.com/technology/tech-news/fbi-update-on-iran-linked-hackers-who-brought-down-machines-of-americas-largest-medical-device-company-stryker-says-iran-thought-they-could-hide-behind-/articleshow/129695549.cms?utm_source=chatgpt.com
[41] “FBI seizes domains tied to Iranian hackers linked to Stryker cyberattack”, Axios, March 19, 2026.
https://www.axios.com/2026/03/20/iran-cyber-attack-stryker-domains-fbi?utm_source=chatgpt.com
[42] “Handala Launches a New Website” (original in Persian – “وب‌سایت جدید حنظله راه‌اندازی شد”), Fars News Agency, March 20, 2026. https://farsnews.ir/miladmaniee/1773981987066525162/%D9%88%D8%A8-%D8%B3%D8%A7%DB%8C%D8%AA-%D8%AC%D8%AF%DB%8C%D8%AF-%D8%AD%D9%86%D8%B8%D9%84%D9%87-%D8%B1%D8%A7%D9%87-%D8%A7%D9%86%D8%AF%D8%A7%D8%B2%DB%8C-%D8%B4%D8%AF
[43] “Iran-linked hackers restore website after US seizes domains,” Reuters, March 20, 2026.
https://www.reuters.com/technology/iran-linked-hackers-restore-website-after-us-seizes-domains-2026-03-20/?utm_source=chatgpt.com
[44] “Handala Exposes the Identity of the Owner of the Vahid Online Telegram Channel” (original in Persian – حنظله هویت مالک کانال تلگرامی وحید آنلاین را افشا کرد), Tasnim News Agency Telegram channel, March 17, 2026.
https://t.me/Tasnimnews/397674
[45] Ibid.
[46] “Iran International Confirms the Breach of Telegram Accounts of Its Staff” (original in Persian – “ایران اینترنشنال هک حساب‌های تلگرامی کارکنانش را تأیید کرد”), DW Persian, July 8, 2025.
https://www.dw.com/fa-ir/%D8%A7%DB%8C%D8%B1%D8%A7%D9%86-%D8%A7%DB%8C%D9%86%D8%AA%D8%B1%D9%86%D8%B4%D9%86%D8%A7%D9%84-%D9%87%DA%A9-%D8%AD%D8%B3%D8%A7%D8%A8%D9%87%D8%A7%DB%8C-%D8%AA%D9%84%DA%AF%D8%B1%D8%A7%D9%85%DB%8C-%DA%A9%D8%A7%D8%B1%DA%A9%D9%86%D8%A7%D9%86%D8%B4-%D8%B1%D8%A7-%D8%AA%D8%A3%DB%8C%DB%8C%D8%AF-%DA%A9%D8%B1%D8%AF/a-73202383
[47] “Iran International Report on the Identity of Members of the Handala Group and Their Links to the Islamic Republic” (original in Persian – گزارش ایران‌اینترنشنال از هویت عوامل گروه حنظله و ارتباط آن‌ها با جمهوری اسلامی), August 14, 2025. https://www.iranintl.com/202508143905


JISS Policy Papers are published through the generosity of the Greg Rosshandler Family.


Picture of Dr. Avi Davidi

Dr. Avi Davidi

Dr. Avi Davidi is a senior Research Fellow at the Jerusalem Institute for Strategy and Security (JISS) and the Elrom Air and Space Research Center, Tel Aviv University. With over 36 years of experience in U.S.-Israel-Iran relations, strategic intelligence, and cyber threats, he is a recognized expert on Iranian affairs. Dr. Davidi previously served as Iran Director at Israel’s Ministry of Strategic Affairs, led digital diplomacy at the Ministry of Foreign Affairs, and was the Editor-in-Chief of the Times of Israel in Persian. Since December 2025, he has been serving as Head of the National Projects Division of the "Horizon" Division at the Ministry of Innovation, Science and Technology. He holds a Ph.D. in International Relations from the University of Southern California (USC).

Recent publications

Security Through Economics: Regional Infrastructure as a Lever for Stability

Long-term security depends not only on preventing threats but also on shaping shared interests. Economics,...

Mapping the Middle East’s Game of Camps

The multi-front war has altered the balance within and between the region’s rival camps, requiring...

Halting Arms Sales to Qatar Is Only the First Step

Israel’s decision to end defense exports to Qatar addresses only part of the problem. Doha...

By signing up, you agree to our user agreement (including the class action waiver and arbitration provisions), our privacy policy and cookie statement, and to receive marketing and billing emails from jiss. You can unsubscribe at any time.

Sign up for the newsletter

For up-to-date analysis and commentary.

Are You In?

Join 8,000+ Subscribers who enjoy our weekly digest