Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts

In December 2025, the hacking group Handala, linked to Iran, claimed to have compromised the mobile devices of two Israeli political figures. However, analysis by Kela cyber intelligence researchers indicated that the breaches were limited to Telegram…

In December 2025, the hacking group Handala, linked to Iran, claimed to have compromised the mobile devices of two Israeli political figures. However, analysis by Kela cyber intelligence researchers indicated that the breaches were limited to Telegram accounts, rather than full device access.

The group alleged that they breached former Prime Minister Naftali Bennett's iPhone 13, releasing contact lists, photos, videos, and approximately 1,900 chat conversations. They later claimed similar access to Tzachi Braverman's device, the Israeli Chief of Staff. Despite these claims, the actual breach revealed vulnerabilities in account security rather than device-level compromise.

Kela's forensic examination of the leaked materials showed that most exposed conversations were empty contact cards generated by Telegram during synchronization. Only about 40 conversations contained actual messages, with even fewer showing substantial exchanges. All exposed contacts were linked to active Telegram accounts, confirming the data source.

The incident highlighted vulnerabilities in session management and account security, even on encrypted messaging platforms. The infection mechanism likely involved multiple attack vectors, such as SIM swapping and exploiting SS7 protocol weaknesses in telecommunications infrastructure. Additionally, sophisticated phishing campaigns may have captured one-time passwords through fake login pages or malicious QR codes.

In December 2025, the hacking group Handala, linked to Iran, claimed to have compromised the mobile devices of two Israeli political figures.
Omar Sabbagh · The Levant Herald

Session hijacking was another probable attack vector, involving the copying of the tdata folder from Telegram Desktop. This authentication file contains active session data that can grant full account access when restored elsewhere, bypassing OTP and multi-factor authentication.

The group potentially harvested OTP codes through various techniques, such as triggering verification via voice calls, extracting codes from voicemail by exploiting unchanged default PINs, or impersonating Telegram support to socially engineer staff into disclosing credentials.

Telegram's default settings increased these risks. The cloud password feature is optional and disabled by default, allowing OTP possession to provide complete account access. Standard chats lack end-to-end encryption, storing data on Telegram servers rather than locally, thus expanding the attack surface.

Advertisement

Handala first emerged in December 2023, establishing presence across multiple cybercrime forums and operating various Telegram channels. Their operations have primarily targeted Israeli companies and organizations, demonstrating support for Iran and Palestinian causes.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories