Handala Hackers Breach Telegram Accounts Linked to Israeli Officials
On December 2025, the hacking group Handala, linked to Iran, intensified its operations against Israel's political figures by claiming to have accessed data from the mobile devices of two prominent officials. However, the threat intelligence firm KELA…
On December 2025, the hacking group Handala, linked to Iran, intensified its operations against Israel's political figures by claiming to have accessed data from the mobile devices of two prominent officials. However, the threat intelligence firm KELA found that the scope was limited to unauthorized access to Telegram accounts rather than a full device compromise.
The first breach, called "Operation Octopus" by Handala, targeted Naftali Bennett, a former Israeli Prime Minister. The group alleged that they hacked Bennett's iPhone 13, releasing contact lists, photos, and around 1,900 chat conversations. The data leak included contacts of senior officials, journalists, and executives. Bennett later confirmed unauthorized access to his Telegram account but maintained that his phone was not compromised.
Following this, Handala claimed to have accessed the iPhone of Tzachi Braverman, Chief of Staff to Prime Minister Benjamin Netanyahu. The group alleged possession of encrypted communications, financial records, and evidence related to corruption.
According to KELA, Handala was active on platforms like BreachForums, Ramp, and Exploit, posting approximately 140 times during this period.
The released data included contact lists, videos from public events, and unclassified documents. The Israeli Prime Minister's Office denied the breach.
On December 2025, the hacking group Handala, linked to Iran, intensified its operations against Israel's political figures by claiming to have accessed data from the mobile devices of two prominent officials.
KELA's review of the data suggests that the alleged chat conversations were largely empty contact cards generated by Telegram. Only about 40 out of the 1,900 chats contained actual messages.
The investigation revealed that Handala's sites, running on WordPress, sometimes exposed administrative login pages. The contacts in the data dump were linked to active Telegram accounts, indicating access via Telegram rather than full device compromise.
Modern political targeting often involves hijacking messaging accounts through methods like SIM swapping, SMS interception, social engineering, and phishing. These do not necessarily require hacking the entire device.
Telegram's cloud password is a potential vulnerability if not enabled or if compromised by phishing or keylogging. Session hijacking remains a viable threat, with Telegram Desktop session data potentially providing full account access if obtained from a compromised device.
Handala has previously used phishing campaigns to distribute malware, but recent leaks suggest that account-level compromise is impactful without full device access. The group has been linked to Iran's cyber ecosystem, using "leak brands" for coercion and narrative influence.
For individuals and organizations, it is crucial to enhance security measures like enabling Telegram's cloud password, securing SIM cards, auditing active sessions, and isolating messaging apps from cloud backups to mitigate account compromise risks.
Based on reporting by GBHackers.




