HomeSecurityIran: Hackers breached FBI Director's personal email

Iran: Hackers breach FBI Director's personal email

Hackers linked to Iran have managed to breach the personal email account of Kash Patel, director of the United States Federal Bureau of Investigation (FBI), and have reportedly leaked a series of photos and other documents online.

Iran FBI

The Handala Hack group , which carried out the breach, said Patel “ will now find his name on the list of successful hacking victims .” In a statement shared with Reuters, the FBI confirmed that Patel’s emails had been targeted and noted that necessary steps had been taken to “ mitigate the potential risks associated with this activity .”

The agency also said that the published data “does not contain government information.” The leak includes emails from 2010 and 2019 allegedly sent by Patel.

Iran – Handala Hack

Handala Hack is believed to be a pro-Iranian, pro-Palestinian hacktivist persona adopted by Iran’s Ministry of Intelligence and Security (MOIS). It is monitored by the cybersecurity community under various aliases, including Banished Kitten, Cobalt Mystique, Red Sandstorm, and Void Manticore. The group also operates another persona called Homeland Justice, targeting Albanian entities since mid-2022.

See also: Dutch Police: Breach via phishing attack

A third persona associated with MOIS is Karma, who is believed to have been completely replaced by Handala Hack by late 2023.

Data gathered by StealthMole revealed that Handala’s online presence extends beyond messaging platforms and cybercrime forums, such as BreachForums, to publicize its activities. The group maintains a multi-layered infrastructure that includes surface web domains, Tor-hosted services, and external file hosting platforms, such as MEGA.

“ Handala has systematically targeted IT and service providers in an attempt to obtain credentials, primarily relying on accounts VPN for initial access compromised ,” Check Point said in a report published this month. “ In recent months, we have identified hundreds of login and brute-force attempts against organizations’ VPN infrastructure connected to Handala’s infrastructure .”

Attacks carried out by the group leverage RDP for lateral movement and launch destructive operations by installing malware such as Handala Wiper and Handala PowerShell Wiper (via Group Policy logon scripts). They also use legitimate disk encryption tools such as VeraCryptto complicate recovery efforts.

Iran: Hackers breach FBI Director's personal email

“ Unlike financially motivated cybercriminal groups, activity associated with Handala has historically emphasized service disruption, psychological impact, and geopolitical conflict ,” Flashpoint noted . “ Operations attributed to the persona often align with periods of heightened geopolitical tension and often target organizations with symbolic or strategic value .”

US-Israel-Iran conflict

This development comes in the context of the US-Israeli-Iran conflict, prompting Iran to launch a cyber counterattack against Western targets. Handala Hack claimed responsibility for the collapse of the networks of medical device and services provider Stryker, deleting a significant portion of corporate data and thousands of employee devices. This attack is the first confirmed destructive wiper operation targeting a US Fortune 500 company.

See also: European Commission investigates breach related to cloud infrastructure

In a statement issued on its website, Stryker said that “the incident has been contained,” adding that it “reacted quickly to regain access and remove the unauthorized party from its environment.” The breach was limited to Microsoft’s internal environment.

The attackers have been found to be using a malicious file to execute commands that allow them to hide their actions. However, the file has no ability to spread across the entire network, Stryker noted.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Palo Alto Networks Unit 42 has indicated that recent destructive operations by Handala Hack likely involve “identity exploitation via phishing and administrative access via Microsoft Intune.” Hudson Rock has found evidence that compromised credentials in these operations.

Targeting FBI director

The recent leak of Patel’s personal emails by the Handala Hack group has intensified an already tense cyber-geopolitical standoff. The incident appears to be a direct response to a US operationthat, following a court order, led to the seizure of four domains linked to activities of the Iranian Ministry of Intelligence (MOIS). At the same time, the United States has announced a reward of $10 million for information that could lead to the identification of members of the group.

Iran: Hackers breach FBI Director's personal email

The seized domains were allegedly used as psychological operations tools, aimed at propaganda and influence. According to the US Department of Justice, these platforms were used to claim responsibility for cyberattacks, publish stolen data, and even incite violence against journalists and dissidents. This strategy reveals a more aggressive approach to cyberspace, where information is being weaponized.

See also: The Port of Vigo was “hit” by a ransomware attack

Data leaks and targeted threats

The attacks exposed sensitive information on approximately 190 individuals affiliated with the Israeli Armed Forces and the government, as well as a massive amount of data (851 GB) from members of the Sanzer Hasidic community. In addition, emails were used to send death threats to Iranian dissidents and journalists internationally. This targeted activity demonstrates a shift from simple espionage to aggressive intimidation operations.

The FBI revealed that the group uses social engineering techniquesto target victims via messaging apps. The attacks involve distributing malware for Windows that is disguised as popular apps like KeePass or WhatsApp. Through these, the attackers gain permanent remote access to victims’ devices, often with the help of bots on Telegram.

The use of services like Telegram as a command and control (C2) infrastructure is a particularly worrying tactic. In this way, malicious activity is “hidden” within normal network traffic, making it extremely difficult to detect. Analysis of compromised devices has revealed audio and screen recording capabilities, especially during Zoom sessions, which increases the risk of real-time espionage.

The Handala Hack case is a typical example of how cyberspace is turning into a field of geopolitical confrontation, where technology, information and propaganda combine in a complex and constantly evolving threat landscape.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS