A pro-Iranian hacking group calling itself Handala claimed responsibility for compromising a personal account belonging to FBI Director Kash Patel and posted what appeared to be old personal photographs, a résumé, and other personal documents online. The FBI said malicious actors targeted Patel’s personal email information and that it had taken mitigation steps, adding that the exposed material was historical and did not include government information.
Reporting said Patel had previously been notified by the FBI in December 2024 that he was a target of an Iranian hacking operation before he became FBI director. U.S. authorities have described Handala as a pro-Iranian, pro-Palestinian proxy actor linked to prior operations against U.S. officials, and the government is offering up to $10 million for information that helps identify the group’s members; the group has also recently claimed responsibility for disrupting Stryker systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The FBI said malicious actors targeted Patel's personal email information, that mitigation measures had been taken, and that the exposed material was historical and did not include government information.
On March 27, 2026, the pro-Iranian group Handala claimed it had hacked an account belonging to FBI Director Kash Patel and posted what appeared to be old personal photos, a resume, and other personal documents online.
According to the reporting, the FBI informed Kash Patel in December 2024 that he had been targeted in an Iranian hacking operation before he became FBI director.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybernews.com
Open sourcepbs.org
Open sourcepcmag.com
Open sourceyahoo.com
Open sourcecnn.com
Open sourcepolitico.com
Open sourcecbsnews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.