惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog
T
The Blog of Author Tim Ferriss
量子位
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - Franky
小众软件
小众软件
Recent Announcements
Recent Announcements
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
I
InfoQ
美团技术团队
G
Google Developers Blog
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Visual Studio Blog
云风的 BLOG
云风的 BLOG
博客园 - 【当耐特】
IT之家
IT之家
Microsoft Security Blog
Microsoft Security Blog
博客园 - 聂微东
Last Week in AI
Last Week in AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
H
Help Net Security

GRAHAM CLULEY

'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself Google's Gemini lets strangers send messages from your locked Android phone Anubis ransomware: what you need to know
Iranian hackers breach FBI director's personal email, and...
2026-03-31 · via GRAHAM CLULEY

It's not every day that you read that the head of America's top law enforcement agency has been hacked, but then - these aren't ordinary times.

The FBI has confirmed that Iran-linked hackers have broken into the personal email inbox of FBI Director Kash Patel, and published photos of him as well as other stolen documents.

The Handala hacking group, a pro-Iranian, pro-Palestinian hacktivist operation, has published on its website a series of personal photographs of Kash Patel :sniffing and smoking cigars, riding in an antique convertible, and making a face while taking a picture of himself in the mirror with a large bottle of rum." The hackers also posted what appears to be the FBI director's CV.

A sample of the material uploaded by the hackers and reviewed by Reuters appears to show a mix of personal and work correspondence dating between 2010 and 2019.

Reporters at TechCrunch have confirmed that at least some of the leaked emails did originate from Patel's Gmail account by verifying the message headers. The most recent files in the leak appear to date from about 2019.

In a statement the FBI said that it was "aware of malicious actors targeting Director Patel's personal email information," and that it had "taken all necessary steps to mitigate potential risks associated with this activity."

According to the FBI, no classified or government systems have been accessed. The hack appears to have been limited to Patel's private Gmail account, rather than any FBI infrastructure. Although that is, perhaps, not much comfort for the director of the world's most famous law enforcement agency.

To add to Kash Patel's embarrassment, this isn’t even the first time he has been targeted by Iranian hackers. His personal messages were previously hacked in December 2024, before he was appointed FBI director.

The Handala hacking group's activity has escalated recently in response to the United States and Israel launching an attack on Iran. Handala has claimed responsibility in recent weeks for hacks against Stryker and Lockheed Martin in response to the war on Iran.

The Stryker attack saw Handala claim credit for crippling the network of the medical device provider by deleting huge amounts of company data and wiping thousands of employee devices.

Earlier this month, the DOJ seized and took down four websites linked to the Handala group, making the Kash Patel leak look very much like a direct act of retaliation.

The FBI has announced that a US $10 million reward is on offer for information related to the Handala hackers.

The attack on Kash Patel's inbox is more embarrassing than catastrophic. Old personal emails and photos of Patel puffing on cigars are unlikely to compromise national security. But it is clear that Iranian hackers are becoming increasingly destructive and brazen in their attacks, especially against those allied to those who Iran considers to be a threat to its own security.

Private businesses are potentially just at much at risk of having their services disrupted, information stolem, or data erased as those organisations working alongside the US and Israeli government and military.

And clearly senior officials, in government and business, remain high-value targets for state-backed hackers. A personal Gmail account linked to the FBI director can never be considered a low-profile target.

Using strong, unique passwords and enabling multi-factor authentication on personal accounts isn't just good advice for regular users. It's essential hygiene for anyone whose inbox might one day end up being plastered across an Iranian hacking group's website.