On December 19, 2023, the domain core.touch-ins.co.il appeared on the leak site operated by the toufan ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the Israeli insurance-services provider. The group claims to have stolen company data and is using the public posting to pressure the victim, although the exact volume of records and the specific types of information taken remain undisclosed in the listing.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch core.touch-ins.co.il
Get alerted the next time core.touch-ins.co.il files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about core.touch-ins.co.il’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Leak
The toufan leak site entry states that core.touch-ins.co.il was listed on December 19, 2023, and explicitly states that internal files were exfiltrated in a ransomware incident. No customer record count is provided, nor does the posting itemize the contents of the stolen data. The disclosure indicates the data is now held by the attackers and may be released or sold if their demands are not met. Ransomware.live mirrors the listing at the URL below, preserving the original claim that a successful breach and data theft occurred.
Why This Matters for You and Your Family
When an insurance-services company loses control of internal files, the people whose policies, claims, or personal details sit inside those systems face direct exposure. Even without an exact headcount, the breach affects anyone who has interacted with Touch Insurance services in Israel. Your name, address, national ID, policy numbers, banking coordinates, or medical information tied to claims could be sitting in the attackers’ archive. Once that material surfaces on criminal forums, it becomes raw material for identity theft, loan fraud, and targeted phishing that can reach you or your spouse at home.
Insurance data is especially valuable because it often links multiple family members, dependents, and financial accounts in one place. A single exposed policy file can reveal your children’s names and birth dates alongside your home address and payment history. Criminals treat such packages as starter kits for long-term fraud campaigns that can damage credit scores and create tax complications months or years later.