Iranian MOIS Cyber Unit Penetrated Israels Top Security Think Tank in Six-Year Campaign Targeting Former Intelligence Chiefs
Haaretz published on May 4 an investigation drawing on more than 100,000 leaked emails and messages, showing that
Per the single Haaretz investigation, MOIS treats INSS as a standing access node inside Israel's intelligence analytical community: exfiltrated credentials spanning building entry codes, camera passwords, and Unit 8200 identities simultaneously enable cyber collection, physical-access planning, and HUMINT targeting. The Shine assassination plot, developed from INSS communications, confirms Tehran designed the operation to convert analytical access into kinetic targeting. Prior reporting established the dual design. The Haaretz release adds that physical-access credentials were exfiltrated and compromised accounts remained active infrastructure as of 2026. Handala's selective disclosure may serve a psychological operation against Israeli institutional confidence rather than reflect actual exploitation. MOIS will likely continue leveraging unrevoked access against INSS-affiliated officials within the next 12 months, absent confirmed remediation.