A seller on a leak forum advertised 9.2 million Israeli population records as a newly stolen 2026 registry allegedly taken from the Population and Immigration Authority, but reporting found the dataset is authentic historical data, not evidence of a fresh compromise. Analysis of sample records reportedly confirmed valid Israeli ID check digits and realistic household structures, while showing that key date fields stop in 2005, undermining the seller’s claim that the database is current.
The records are assessed as a resurfaced copy of the long-known "Agron 2006" leak, which originated after a Ministry of Social Affairs employee copied the registry in 2006. The seller, using the handle GordonFreeman, reportedly tried to support the claim by sharing tail rows from the database, but those entries also ended in 2005. Although the incident does not appear to reflect a new breach, the exposed permanent identifiers, including national ID numbers, birthdates, and family relationship data, still create ongoing identity theft and social-engineering risk.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Israel’s Justice Ministry made six arrests in 2011 in connection with the Agron 2006 population registry case. This tied law enforcement action to the earlier theft and spread of the database.
In 2006, an employee at Israel’s Ministry of Social Affairs copied the entire population registry and took it home. The copied data later became known as the "Agron 2006" database.
Based on the authority, scale, field structure, and consistent 2005 cutoff, investigators assessed the advertised dataset was likely a resurfaced copy of the long-known Agron 2006 leak rather than a new breach. The finding reframed the incident as recirculation of old stolen data.
After being challenged, the seller claimed the published sample only reflected the oldest portion of the database and shared purported final rows to support that assertion. Those tail-end records also ended in 2005, undermining the claim that the rest of the database was current.
Ransomnews reviewed the sample and found the records appeared genuine, with ID numbers largely passing check-digit validation and family-unit patterns matching a real household-structured database. However, all key date fields, including birth, death, immigration, and update fields, stopped in 2005, showing the dataset was not a current 2026 registry.
A seller using the handle GordonFreeman advertised a 7.5 GB database of about 9.2 million records, claiming it was Israel’s 2026 national population registry obtained by breaching the Population and Immigration Authority. The listing said the data included national ID numbers, addresses, phone numbers, birth and death dates, immigration dates, and family links.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.