Iran-linked hacker group offers $30,000 bounty for Israel's military info
File photo of former Israel air defense forces commander Zvika Haimovich in front of an Arrow II missile defense battery.
An Iran-linked hacker group said it was offering a $30,000 reward for information related to Israel’s military sector after releasing material it said identified people involved in designing Israeli missile defense systems.
The group, known as Handala, said it had released information on 13 individuals it described as key designers of systems such as Arrow and David’s Sling.
The material published by the group included photos, names, professional credentials, email addresses, locations and phone numbers.
“These individuals, who were once thought to be hidden in the shadows, are now fully exposed to the world,” the group said in a statement carried by Iran’s ISNA news agency, adding that it would pay $30,000 for what it called valuable information.
Israeli media outlets, including the Jerusalem Post, have not confirmed whether the information released by the group is accurate.
Who is Handala?
Handala is widely described by cybersecurity researchers and Western officials as tied to Iran’s Ministry of Intelligence.
Researchers say the group operates as part of a broader cyber unit known as Banished Kitten, also referred to as Storm-0842 or Dune, which they link to the ministry’s Domestic Security Directorate.
The group has been linked to cyber operations against Israeli infrastructure and public institutions for around two years.
In January, it claimed responsibility for a cyberattack on Israeli kindergartens that disrupted public address systems at about 20 locations. In August, the group was linked to hacks targeting multiple Israeli entities, including academic institutions, technology firms, media outlets and industrial companies.
Handala has also been linked to cyber operations targeting Iran International, a London-based Persian-language broadcaster. In July, Iran International said leaked materials published by Iranian state outlets originated from earlier hacks carried out in the summer of 2024 and January 2025.
The broadcaster attributed those hacks to a broader cyber unit known as Banished Kitten. The channel said the hackers may have installed malware through compromised Telegram accounts. “These cyberattacks are part of a broader campaign of threats targeting Iran International, including physical threats against our staff,” it said.
Iran International said its journalists have faced sustained harassment since the channel was founded in 2017, including threats of assassination and kidnapping, physical assaults, online abuse and hacking.