Handala Claims Breach of Clalit, Israel's Largest Healthcare Network

In late February 2026, the Iranian-aligned hacktivist group Handala claimed to have infiltrated the systems of Clalit Health Services, Israel's largest healthcare network serving over four million patients. The group posted on social media that it had released sensitive medical data from more than 10,000 patients, declaring the hack a devastating blow to what it called the core of the Israeli healthcare system.

Claimed Data Exposure

Attached to the group's posts were medical records that appeared to originate from Clalit's database, containing names and personal information of Israeli patients. The group framed the attack as a legitimate response to the ongoing conflict, stating it had delivered a devastating blow and that Israeli security walls had collapsed.

Check Point's Gil Messing characterized the threat level as partially credible: the group generally has done something when it claims an attack, but not to the extent described, indicating a consistent level of exaggeration. This assessment aligns with Handala's documented pattern of inflating the scope and impact of its operations for maximum media effect.

Healthcare as a Strategic Target

The Clalit breach fits within Handala's broader strategy of targeting institutions that generate maximum psychological impact on the Israeli public. Healthcare was among the most frequently targeted sectors in the group's first year of operations, according to analysis by the International Institute for Counter-Terrorism. The attack came amid rising tensions between Israel and Iran, with the group explicitly shifting into a higher gear according to Check Point researchers.

The healthcare sector breach also echoes earlier Iranian-linked operations against Israeli medical infrastructure. In October 2025, the Assaf Harofeh Medical Center was hit by the Russian-speaking Qilin ransomware group, demonstrating that Israeli healthcare remains a high-value target for multiple threat actor categories.

Timing and Context

The Clalit claim preceded Handala's March 2026 escalation against Gulf energy infrastructure by just days, suggesting the group was ramping up operational tempo ahead of the broader Iranian cyber offensive. Unit 42 subsequently documented this acceleration as part of a coordinated campaign involving approximately 60 hacktivist groups operating under Iran's Electronic Operations Room, established on February 28, 2026.

Read the full analysis on IntelFusions