Security News This Week: Iranian Hackers Breached Kash Patel’s Email—but Not the FBI’s
As the United States-Israel war with Iran barrels into its second month, President Donald Trump is reportedly plotting a potential mission to send US special forces into the country to take Tehran’s enriched uranium. Experts say such a plan would be extremely risky, likely putting the lives of troops in peril with a low chance of success.
Iranian Hackers Breached Kash Patel’s Email—but Not the FBI’s
The Iranian hacker group Handala—perhaps the most public and chaotic face of Iran’s efforts at cyber retaliation in the midst of the US and Israeli war against the country—today announced it had hacked an email account belonging to FBI director Kash Patel. ‘The so-called ‘impenetrable’ systems of the FBI were brought to their knees within hours by our team,’ the group wrote in a statement on its website.
A collection of emails posted to the hackers’ site and labeled with the name of Patel’s apparent Gmail address appears to contain years of Patel’s messages and photos, from hotel reservations and business deals to photos of his travels and his family, mostly dated from 2010 to 2019. A Justice Department official confirmed to Reuters that Patel’s email had been breached, and that the leaked emails appeared to be real.
Handala’s second claim, however—that it hacked the FBI—seems, for now, to be fiction. All evidence points to Handala having breached Patel’s older, personal Gmail account. Widely believed to be a ‘hacktivist’ front for Iran’s intelligence agency the MOIS, Handala suggested on its website that the emails contained classified information, but the messages initially reviewed by WIRED didn’t appear to be related to any government work.
Handala, which cybersecurity experts have described to WIRED as an ‘opportunistic’ hacker group whose cyberattacks and breaches are often calculated more for their propaganda value than their tactical impacts, has nonetheless made the most of Patel’s embarrassing breach. ‘To the whole world, we declare: the FBI is just a name, and behind this name, there is no real security,’ the group wrote in its statement. ‘If your director can be compromised this easily, what do you expect from your lower-level employees?’
Handala Hackers Put $50 Million Bounty on Trump and Netanyahu’s Heads
For further evidence of Handala’s bombastic rhetoric, look no further than another post on its website earlier this week (we’re intentionally not linking to it) that offered a $50 million bounty to anyone who could ‘eliminate’ US president Donald Trump and Israeli prime minister Benjamin Netanyahu. ‘This substantial prize will be awarded, directly and securely, to any individual or group bold enough to show true action against tyranny,’ the hackers’ statement read, along with an invitation to any would-be assassins to reach out via the encrypted messaging app Session.
‘All our communication and payment channels utilize the latest encryption and anonymization technologies, your safety and confidentiality are fully guaranteed.’ That bounty, Handala explained, was posted in answer to a statement about Handala published on the US Department of Justice website last week that offered $10 million for information leading to the identity or location of anyone who carries out ‘malicious cyber activities against US critical infrastructure’ on behalf of a foreign government.
‘Our message is clear: If you truly have the will and the power, come and find us!’ Handala wrote in its response. ‘We fear no challenge and are prepared to respond to every attack with even greater force.’
4 Years in, Apple’s Pegasus-Killer Remains Undefeated, Company Says
Apple says no device with its Lockdown Mode security feature enabled has ever been successfully compromised by mercenary spyware in the nearly four years since its launch. Amnesty International’s security lab head, Donncha Ó Cearbhaill, also says his team has seen no evidence of a successful attack against a Lockdown Mode–enabled iPhone. And Citizen Lab, which has documented several successful spyware attacks against iPhones, says none involve a Lockdown Mode bypass, while in two cases its researchers found the feature actively blocked attacks against NSO Group’s Pegasus and Intellexa’s Predator.
Google researchers, meanwhile, found one spyware strain that simply abandons infection attempts when it detects the feature is enabled. Lockdown Mode works by disabling commonly exploited iPhone features, such as most message attachment types and features like links and link previews. Incoming FaceTime calls are blocked unless the user has pre-approved the caller.
That’s not all! Each week we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines (except the one that has no link) to read the full story. And stay safe out there.







