Soreq Nuclear Center Ransomware Breach by Handala Group

Incident Date:

September 28, 2024

World map

Overview

Title

Soreq Nuclear Center Ransomware Breach by Handala Group

Victim

Soreq NRC

Attacker

Handala

Location

Yavne, Israel

, Israel

First Reported

September 28, 2024

Ransomware Attack on Soreq Nuclear Research Center by Handala Group

The Soreq Nuclear Research Center (SNRC), a prominent Israeli institution, has recently fallen victim to a ransomware attack claimed by the Handala group. This incident underscores the vulnerabilities faced by critical infrastructure facilities engaged in sensitive research.

About Soreq Nuclear Research Center

Established in 1958, the Soreq Nuclear Research Center is a key player in Israel's scientific landscape, operating under the Israel Atomic Energy Commission. Located near Yavne, Israel, SNRC is renowned for its contributions to nuclear science, radiation safety, and applied physics. The center's research spans nuclear medicine, radiopharmaceuticals, electro-optics, and non-destructive testing. With a workforce of up to 1,000 employees, SNRC is a significant entity in the government sector, boasting advanced facilities like the Israeli Research Reactor-1 and the Soreq Applied Research Accelerator Facility.

Details of the Ransomware Attack

The attack on SNRC was discovered on September 30, with the Handala group claiming responsibility via their dark web leak site. While the extent of the data breach remains unclear, the sensitive nature of SNRC's research heightens the potential impact of the attack. The center's focus on civilian and academic sectors, rather than military applications, makes this breach particularly concerning for international nuclear research collaborations.

Profile of the Handala Group

Handala is a cybercriminal organization known for its pro-Palestinian agenda, frequently targeting Israeli institutions. Despite being labeled as a ransomware group, Handala is more accurately described as a wiper group, aiming to destroy data rather than extort money. Their tactics include sophisticated phishing campaigns and multi-stage malware loading processes, which could have facilitated their penetration into SNRC's systems. The group's history of targeting Israeli entities, including defense and governmental organizations, aligns with their claim of breaching SNRC.

Potential Vulnerabilities and Implications

SNRC's role in advancing nuclear technology and its collaboration with international entities make it a high-value target for cyberattacks. The center's reliance on digital infrastructure for research and development activities may have exposed vulnerabilities that Handala exploited. This incident highlights the critical need for enhanced cybersecurity measures in protecting sensitive research data and maintaining the integrity of international scientific collaborations.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.