On February 25, 2026, Clalit, Israel’s largest healthcare organization, confirmed that attackers had exfiltrated internal files during a ransomware operation claimed by the Handala group. The breach affects an organization that serves millions of patients, meaning sensitive personal and medical records linked to you or your family may now be in the hands of an organized cyber group.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Clalit
Get alerted the next time Clalit files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Clalit’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on the Handala leak site describes the incident as part of an operation the group named “Justice for the Oppressed.” The attackers state they penetrated Clalit’s network and removed internal files. No exact victim count has been released, and the precise volume or categories of data remain unclear from available reporting. The group published proof of access and samples on its leak site hosted via ransomware.live.
February 25, 2026 marks the public disclosure date. Clalit has not yet issued a detailed list of exposed record types, but healthcare organizations typically hold names, addresses, national ID numbers, medical histories, and billing information. Industry research from sources such as DoxxScan™ continuous monitoring indicates that healthcare breaches frequently expose exactly this combination of data.
Why This Matters for You and Your Family
When a major healthcare provider is breached, the information stolen is among the most permanent and damaging. Unlike a credit card number, your medical records and national identifiers cannot be reissued. If your family uses Clalit or any affiliated clinic, your data may already be circulating among threat actors who trade or weaponize it for identity theft, insurance fraud, or targeted harassment.