Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
government-diplomatic-threatstate-sponsored-espionageunderground-data-leakhacktivist-operation

Iran-Linked Handala Hackers Breach FBI Director's Personal Gmail

Updated 3mo agoFirst seen Mar 27, 202615 sources

Iran-linked hackers operating as the Handala Hack Team claimed they breached FBI Director Kash Patel’s personal Gmail account and published excerpts from the stolen material online. Reporting says the leak totaled about 800 MB and included personal photographs, a purported resume, and hundreds of emails, with exposed correspondence spanning roughly 2010 to 2019 and appearing to contain both personal and work-related messages. A Justice Department official confirmed Patel’s email account had been compromised and said the leaked material appeared authentic, though the emails themselves were not independently verified.

Handala framed the intrusion as an embarrassment for U.S. security leadership and warned that if the FBI director could be compromised, other personnel could be targeted as well. Western cybersecurity researchers have assessed Handala as a pro-Palestinian hacktivist persona linked to Iranian government cyberintelligence units, and the breach follows other activity attributed to the group, including a claimed attack on medical technology company Stryker. The incident also comes after U.S. actions against Handala, including domain seizures and a $10 million reward offer tied to identifying members of the group.

Share:
Iran-Linked Handala Hackers Breach FBI Director's Personal Gmail
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Mar 30, 20263mo ago

State Department reissues $10 million reward naming Handala

On 2026-03-30, the U.S. State Department reissued a $10 million reward for information on Iranian cyber actors, specifically naming Handala and the Iranian IT company Parsian Afzar Rayan Borna. The move followed the Patel email intrusion and reflected continued U.S. efforts to identify and disrupt actors linked to Iran's MOIS.

State Department reissues $10 million reward for info on Iranian hackers | The Record from Recorded Future News
Mar 28, 20263mo ago

Report ties Handala Hack Team to Iran's MOIS

The Hacker News reported that the Handala Hack Team persona is linked to Iran’s Ministry of Intelligence and Security (MOIS), framing the group as a disruptive actor focused on psychological impact as well as destructive operations. The attribution connected the Patel email breach and prior Stryker wiper activity to a broader Iran-aligned cyber campaign.

Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack
Mar 27, 20263mo ago

FBI says Patel email leak was historical and mitigation steps were taken

The FBI confirmed the theft of Director Kash Patel's personal emails, said the exposed material was historical and contained no government information, and stated that mitigation steps had been taken. The statement marked a formal FBI response to the incident beyond the earlier Justice Department confirmation.

FBI confirms theft of director’s personal emails by Iran-linked hacking group | The Record from Recorded Future News

Justice Department confirms Patel email compromise appears authentic

A Justice Department official confirmed that Patel's personal email account had been compromised and said the leaked material appeared authentic. Reuters reviewed exposed material but could not independently verify the emails themselves.

Handala publishes excerpts and data from Patel's account online

After the breach, Handala publicly released excerpts from the stolen material and reportedly leaked about 800 megabytes of data online. The group framed the intrusion as an embarrassment for U.S. security leadership.

Handala breaches Kash Patel's personal Gmail account

Iran-linked hackers operating as the Handala Hack Team compromised FBI Director Kash Patel's personal Gmail account. The exposed correspondence reportedly spanned mainly 2010 to 2019 and included personal photographs, a purported resume, and work-related emails.

Mar 19, 20263mo ago

FBI seizes four Handala-linked domains and offers $10 million reward

On 2026-03-19, the FBI reportedly seized four domains linked to the Handala persona and the U.S. offered a $10 million reward for information identifying the group's members. The later Patel account intrusion was framed in the reference as retaliation for this law enforcement action.

Inside Handala’s Hack on the FBI Director
Mar 11, 20264mo ago

Attack on Stryker used Intune admin access to remotely wipe devices

On 2026-03-11, attackers allegedly used compromised Microsoft Intune Global Administrator credentials and legitimate remote wipe functionality in an attack on Stryker, rendering tens of thousands of devices inoperable across 79 countries. The incident was presented as evidence of a shift toward identity compromise and abuse of legitimate administrative tools rather than custom malware.

Iran-Linked Handala Hacked the FBI Director’s Personal Email. Here Is What That Actually Tells You About the Group. | by Sigmund Brandstaetter CISSP, CCSP, CISM, OSCP, CEH | Mar, 2026 | OSINT Team
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

58 LINKEDOpen in app
Affected products
9 linked
GmailIphoneTelegram DesktopTelegramKeepassWindowsWhatsappZoomVeracrypt
Organizations
35 linked
StrykerGoogleMicrosoft CorporationSOCRadarReutersLockheed MartinCheck Point Software TechnologiesTechCrunchPalo Alto NetworksSecurity AffairsMeyka AI PTY LTDVerifoneCisco SystemsMegaSplunkLinkedinKELAFlashpointSecurityWeekZoom CommunicationsRecorded FutureHudson RockBritish Broadcasting CorporationResecurityXGitHubHackread.comxAIDistrict 4 LabsStealthMoleAmerica OnlineHalcyon Ransomware Research CenterOSINT PHParsian Afzar Rayan BornaCareCloud
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Iran-Linked Handala Hackers Breach FBI Director's Personal Gmail | Mallory