Iran-linked hackers operating as the Handala Hack Team claimed they breached FBI Director Kash Patel’s personal Gmail account and published excerpts from the stolen material online. Reporting says the leak totaled about 800 MB and included personal photographs, a purported resume, and hundreds of emails, with exposed correspondence spanning roughly 2010 to 2019 and appearing to contain both personal and work-related messages. A Justice Department official confirmed Patel’s email account had been compromised and said the leaked material appeared authentic, though the emails themselves were not independently verified.
Handala framed the intrusion as an embarrassment for U.S. security leadership and warned that if the FBI director could be compromised, other personnel could be targeted as well. Western cybersecurity researchers have assessed Handala as a pro-Palestinian hacktivist persona linked to Iranian government cyberintelligence units, and the breach follows other activity attributed to the group, including a claimed attack on medical technology company Stryker. The incident also comes after U.S. actions against Handala, including domain seizures and a $10 million reward offer tied to identifying members of the group.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-30, the U.S. State Department reissued a $10 million reward for information on Iranian cyber actors, specifically naming Handala and the Iranian IT company Parsian Afzar Rayan Borna. The move followed the Patel email intrusion and reflected continued U.S. efforts to identify and disrupt actors linked to Iran's MOIS.
The Hacker News reported that the Handala Hack Team persona is linked to Iran’s Ministry of Intelligence and Security (MOIS), framing the group as a disruptive actor focused on psychological impact as well as destructive operations. The attribution connected the Patel email breach and prior Stryker wiper activity to a broader Iran-aligned cyber campaign.
The FBI confirmed the theft of Director Kash Patel's personal emails, said the exposed material was historical and contained no government information, and stated that mitigation steps had been taken. The statement marked a formal FBI response to the incident beyond the earlier Justice Department confirmation.
A Justice Department official confirmed that Patel's personal email account had been compromised and said the leaked material appeared authentic. Reuters reviewed exposed material but could not independently verify the emails themselves.
After the breach, Handala publicly released excerpts from the stolen material and reportedly leaked about 800 megabytes of data online. The group framed the intrusion as an embarrassment for U.S. security leadership.
Iran-linked hackers operating as the Handala Hack Team compromised FBI Director Kash Patel's personal Gmail account. The exposed correspondence reportedly spanned mainly 2010 to 2019 and included personal photographs, a purported resume, and work-related emails.
On 2026-03-19, the FBI reportedly seized four domains linked to the Handala persona and the U.S. offered a $10 million reward for information identifying the group's members. The later Patel account intrusion was framed in the reference as retaliation for this law enforcement action.
On 2026-03-11, attackers allegedly used compromised Microsoft Intune Global Administrator credentials and legitimate remote wipe functionality in an attack on Stryker, rendering tens of thousands of devices inoperable across 79 countries. The incident was presented as evidence of a shift toward identity compromise and abuse of legitimate administrative tools rather than custom malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
socradar.io
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcebbc.com
Open sourcecybercenter.space
Open sourcekoreatimes.co.kr
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.