/

Iranian Hack Turns Leaked Israeli Contacts Into Intelligence Windfall

Haaretz investigation reveals how a hack-and-leak campaign exposed thousands of sensitive contacts, mapping Israeli security networks and global power brokers

3 mins read
IDF [Photo: .Ynetnews]

An Iranian-backed hacking operation that breached the phones and messaging accounts of senior Israeli political figures has exposed what security experts describe as an intelligence gold mine, raising alarm over the vulnerability of personal devices used by those at the heart of government. According to a detailed investigation by Haaretz, the leaks go far beyond personal embarrassment, opening the door to surveillance, intimidation and potential espionage on a sweeping scale.

The breach involved contact lists belonging to former prime minister Naftali Bennett, Prime Minister Benjamin Netanyahu’s chief of staff Tzachi Braverman, and former justice minister Ayelet Shaked. Together, the leaked data comprises thousands of personal phone numbers and conversations, many linked to individuals holding sensitive current or former security roles. Haaretz reported that dozens of those exposed are now considered at risk of targeting by foreign intelligence services.

Among the names appearing in the contact lists are global leaders and influential figures, including French President Emmanuel Macron, UAE ruler Mohammed bin Zayed, UAE Foreign Minister Abdullah bin Zayed, OpenAI chief executive Sam Altman and U.S. venture capitalist Shaun Maguire. The presence of such figures underscores how deeply interconnected political, security and technological elites have become — and how valuable even a simple contact list can be to a hostile intelligence service.

The hacking group behind the leaks, known as Handala, specializes in so-called “hack-and-leak” influence operations. Haaretz found that the group has already begun enriching the exposed contact lists by cross-referencing them with other major Israeli databases stolen in previous breaches. These include population registries, voter databases and insurance records containing sensitive personal details of political, judicial and military figures.

Three weeks ago, Handala claimed it had gained access to Bennett’s device, releasing roughly 4,500 contacts along with thousands of conversations from Telegram. Bennett initially denied the breach but later acknowledged that access to his account had been obtained “through various means.” Similar leaks followed involving Braverman, whose contact list included about 2,400 names alongside photos, videos and recent messages, and Shaked, whose WhatsApp contacts and conversations dating back several months were also exposed.

It remains unclear whether the hackers directly compromised the devices or accessed cloud backups linked to messaging apps. Cybersecurity specialists told Haaretz that the distinction matters little. Even without message content, contact lists alone can be transformed into detailed intelligence maps. In several cases, contacts were saved with labels identifying unit numbers, roles or affiliations. Dozens of individuals associated with Shin Bet units responsible for protective security were explicitly identified, alongside ministry security officers, senior personnel in classified units and staff at sensitive facilities.

Experts warn that leaked phone numbers represent a direct attack surface. A mobile number is a persistent identifier that can be exploited to infer location, hijack accounts through SMS-based authentication, or launch tailored phishing and impersonation campaigns. As Haaretz has previously documented, weaknesses in the global SS7 telecommunications protocol allow surveillance firms — and potentially hostile states — to track phones worldwide, intercept messages or silently locate targets without their knowledge.

Beyond telecom vulnerabilities, advertising technologies and open-source intelligence tools can link phone numbers to social media profiles, fitness apps and other digital footprints. These techniques can reveal daily routines, travel patterns, home addresses and family connections without ever hacking a device. By cross-referencing multiple breached databases, attackers can rapidly map not just individuals but entire professional and familial networks.

In recent weeks, some Israelis whose numbers appeared in the leaks have reportedly received threatening SMS messages purporting to come from Iranian intelligence. Haaretz confirmed that recipients were sent messages inviting them to contact Iranian embassies or warning that their families were at risk. Links embedded in the messages led to detailed family trees listing relatives and ID numbers, apparently generated automatically by combining data from multiple breaches.

While sources familiar with the matter told Haaretz that the operation appears designed primarily to intimidate rather than signal an imminent attack, they described it as a serious security failure. Senior officials are expected to follow strict protocols when using personal devices, including avoiding saving sensitive contacts under real names. Once leaked, such phone numbers are considered “burned” and should be replaced.

Israel’s Shin Bet has said it is examining the incident but has not issued a formal response, while the Defence Ministry body responsible for cyber incidents declined to comment. Former officials stressed that the case highlights a systemic problem: the routine use of commercial messaging apps and personal phones for sensitive communications, even at the highest levels of government.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Latest from Blog