The Iranian-linked Handala group claimed it had disrupted Israeli radar systems and placed the Kfar Yona municipality under a “cyber siege” amid renewed Iran-Israel hostilities. Reporting on the incident found that the evidence released by the group does not substantiate a radar intrusion: the screenshots and access shown appear to match a Tadiran Telecom Aeonix IVR/VoIP administration panel, suggesting compromise of a municipal or organizational phone system rather than military radar infrastructure.
Researchers said the operation fits a broader pattern in which cyber activity is used to amplify battlefield messaging during escalating regional conflict involving Hezbollah fire, Israeli strikes in Beirut, IRGC missile launches, and Israeli retaliatory strikes on Tehran, Tabriz, and Isfahan. While the specific radar-disruption claim bears the hallmarks of propaganda and remains uncorroborated by independent evidence or official acknowledgment, Handala is described as a real state-affiliated threat actor with documented capabilities including credential theft, abuse of legitimate enterprise tools, wiper malware, and hack-and-leak operations, raising the likelihood of further disruptive attacks and inflated claims.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
During renewed Iran-Israel hostilities, the Iranian-linked Handala group claimed it had disrupted Israeli radar systems and placed the Kfar Yona municipality under a "cyber siege." The reporting notes these claims were made publicly by the group but were not independently verified.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcemalware.news
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.