/

Hack, Leak, and Strike: Iran’s Six-Year Cyber War Inside Israel’s Most Sensitive Think Tank

A Haaretz investigation based on over 100,000 leaked emails and messages reveals how Iranian-linked hackers combined cyber intrusion, intelligence gathering, and alleged assassination plots against Israel’s Institute for National Security Studies

4 mins read
Israel’s Institute for National Security Studies (INSS)

For years, Israel’s Institute for National Security Studies (INSS) believed it was operating in the realm of policy research and strategic analysis. But a sweeping cyber campaign attributed to Iranian intelligence services has turned it into something else entirely: a sustained target in a hybrid war that blends hacking, psychological influence, espionage, and alleged physical surveillance. A Haaretz investigation, drawing on more than 100,000 leaked emails, files, and messages, shows that the assault on INSS has been ongoing for at least six years, escalating from routine phishing attempts into a multi-layered intelligence operation that now includes assassination-related activity and the exposure of deeply sensitive internal systems.

The leaks, published by the hacker group Handala and analyzed by Haaretz, suggest that Iran’s Ministry of Intelligence has treated INSS not as a civilian think tank but as an extension of Israel’s security establishment. Handala, which presents itself as a pro-Palestinian hacktivist collective but has been identified by U.S. officials as an Iranian cyber unit, released more than 100,000 stolen files in recent months. These materials extend into late 2025 and include internal communications, administrative documents, and operational details from senior INSS personnel, including former heads of Israeli Military Intelligence and Mossad-related figures who now occupy leadership roles at the institute.

The scale of the breach is significant not only for what was taken but for what it reveals. According to Haaretz’s analysis, the data shows repeated penetration of email accounts belonging to senior researchers, some of whom had previously served in Israel’s most sensitive intelligence units. In several cases, attackers impersonated INSS officials to distribute stolen reports and lure foreign contacts into compromised communications. What began around 2019 as routine intrusion attempts quickly evolved into coordinated access to high-level accounts, including that of former Military Intelligence chief Amos Yadlin and other senior figures connected to Israel’s defense ecosystem.

By 2021 and 2022, Iranian operators had escalated their methods. The leaked correspondence shows attempts to use compromised accounts to target prominent Israeli figures, including former Foreign Minister Tzipi Livni, in what appeared to be spear-phishing operations designed to extract sensitive information or facilitate travel-based lures. In parallel, researchers were repeatedly targeted with malicious documents and impersonation campaigns. In one instance, Iran-linked hackers leaked a researcher’s book before its official publication, an act that blurred the line between espionage and psychological harassment.

The breach also exposed something more alarming: the integration of cyber operations with physical intelligence gathering. According to documents reviewed by Haaretz, the campaign included not only digital infiltration but also coordination with local agents and attempts to support assassination planning against Israeli individuals associated with the institute. While not all claims could be independently verified, Israeli security officials cited in the investigation described a pattern in which cyber reconnaissance fed directly into real-world targeting efforts, including surveillance of individuals’ homes and vehicles.

At the center of the campaign is the hacker group Handala, which has spent years targeting Israeli institutions while operating under a shifting identity. In April 2025, during the height of the Iran-Israel conflict, Handala published emails belonging to six senior INSS figures, including current director Tamir Hayman and prominent researchers such as Sima Shine and Raz Zimmt. The group claimed to have stolen more than 400,000 files, though Haaretz verified at least 99,000 of them. While much of the material appears administrative, cybersecurity experts told Haaretz that it contains critical security exposures, including passwords for surveillance cameras, Wi-Fi networks, and internal Zoom systems used for sensitive meetings.

In one particularly striking case, a leaked calendar entry reportedly contained the access code to the INSS building itself, effectively handing over physical entry information to the attackers. Other documents identified military personnel from Unit 8200, Israel’s elite signals intelligence unit, as well as diplomats and NATO-linked officials who had interacted with the institute. The exposure of such information illustrates how cyber breaches can rapidly transition into physical security risks, especially when digital infrastructure is tightly connected to real-world access systems.

The investigation also highlights repeated warnings from cybersecurity firms over the years. Private companies such as Check Point and ClearSky provided assistance to INSS, while Israel’s National Cyber Directorate reportedly issued guidance following multiple breaches. However, Haaretz notes that official security agencies were not directly involved in securing the institute’s systems, leaving gaps in protection for both current staff and former intelligence officials who remain connected to sensitive networks.

One of the most concerning aspects of the campaign is its persistence. Even after multiple incidents were exposed, attackers continued to successfully breach accounts and impersonate researchers. In 2024 and 2025, phishing attempts expanded to include AI-generated impersonations and malicious PDFs designed to harvest login credentials. In parallel, Iranian operatives allegedly used stolen data to support broader influence operations, including disinformation campaigns and attempts to shape narratives around Israeli military and diplomatic activity.

The leaks also show how cyber operations intersect with physical surveillance. In one case reported by Haaretz, Israeli authorities arrested a couple allegedly recruited by Iranian intelligence to monitor INSS personnel, including photographing sensitive sites and tracking individuals over extended periods. According to Israeli security officials, such intelligence was used not only for espionage but potentially for planning targeted attacks, including assassination attempts against individuals associated with the institute.

Former Israeli security officials cited in the report describe the situation as a structural vulnerability. Because many INSS researchers are former senior members of the Mossad, Military Intelligence, or Shin Bet, they remain attractive targets long after leaving formal service. Yet responsibility for their digital security is fragmented, falling neither fully under state protection nor fully under institutional safeguards. This gap, Haaretz reports, has allowed attackers to repeatedly exploit personal email accounts and private devices without significant resistance.

INSS has acknowledged the cyber threats but maintains that it is an independent research body that does not handle classified material and operates in coordination with Israel’s security agencies. However, cybersecurity experts cited in the investigation argue that its systems have effectively functioned as an entry point for ongoing attacks against wider Israeli networks. One expert told Haaretz that compromised INSS accounts were still being used in 2025 to distribute malware to additional targets, suggesting that the breach remains active rather than contained.

Beyond espionage, the campaign also reflects a broader geopolitical shift in which cyber operations, influence warfare, and physical intelligence gathering are increasingly integrated. What the Haaretz investigation ultimately reveals is not a single breach, but a sustained system of pressure: a long-term Iranian strategy aimed at mapping Israel’s security ecosystem through one of its most connected intellectual hubs. INSS, once viewed primarily as a think tank, now appears in the data as something far more exposed—a digital and strategic battlefield where research, intelligence, and warfare have become indistinguishable.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog