Cyber Toufan (Al-Aqsa) is a pro-Palestinian, anti-Israel hacktivist group that emerged in November 2023 amid the Israel-Hamas war, taking its name from Hamas's October 7 'Toufan Al-Aqsa' (Al-Aqsa Flood) operation. It runs destructive hack-and-leak campaigns against Israeli companies, government-linked entities, and foreign firms doing business with Israel, combining data theft, daily Telegram leak dumps, and outright server/database wiping. Several security vendors assess a possible Iranian state nexus, though the group publicly maintains an independent hacktivist identity.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Cyber Toufan surfaced in mid-to-late November 2023, within weeks of the October 7 Hamas assault and the ensuing war in Gaza, branding its campaign #OpCyberToufan after Hamas's 'Al-Aqsa Flood.' Its breakout event was the compromise of Signature-IT, an Israeli web-hosting and services provider, on or around 16 November 2023. Framed by Check Point as a supply-chain attack, the Signature-IT intrusion gave the group reach into dozens of downstream Israeli organizations at once; the group itself disputed the exact framing but did not deny the impact. Through this and related access the actor exposed data from roughly 49-60+ organizations over the following weeks, promising a month of daily leaks. Named victims reported across sources include the Israel Innovation Authority, Toyota Israel, IKEA Israel, Homecenter, the Ministry of Welfare and Social Security, the Ministry of Health, the Israel Securities Authority, the Israel National Archive, Israel Nature and Parks, The Academic College of Tel Aviv, and security firm Max Security, along with international firms doing business with Israel. Dark Reading reported the operation touched 100-plus Israeli organizations within a single month. A defining trait was destruction, not just leaking: the group and independent researchers (e.g., Kevin Beaumont) documented wholesale wiping of servers and databases, with reporting of over 1,000 servers destroyed and about a third of victims left offline for weeks because backups had also been erased. This destructive, wiper-oriented posture placed Cyber Toufan alongside the broader wave of pro-Hamas destructive activity against Israel in late 2023 (the same period SentinelLabs/SentinelOne tracked BiBi/BiBi-Linux wipers, named for a nickname of PM Netanyahu), though a specific custom-malware family is not consistently attributed to Cyber Toufan by name. Notably, in later intrusions the group reportedly avoided custom malware, relying on built-in system utilities and legitimate/stolen credentials (living-off-the-land) to move and remain undetected. Leaks and announcements were distributed via a dedicated Telegram channel; the group timed operations to battlefield developments and paused during ceasefire periods. Attribution is contested: Check Point labeled it an Iranian threat actor and Cybernews, SOCRadar, and Recorded Future's The Record echoed a likely Iranian state-aligned nexus based on scale, sophistication, timing, target choice, and wiper methodology, while the group maintains an independent pro-Palestinian identity and has not confirmed its origins - so the Iran nexus should be carried at medium confidence and clearly caveated. The actor did not disappear after 2023: through 2025-2026 reporting (Cyber Daily, Iran International, The Jerusalem Post, Insurance Journal) an 'Iran-linked' Cyber Toufan/Toufan Hackers resurfaced targeting Israeli and allied defense supply chains - including a claimed compromise of supply-chain firm MAYA Technologies affecting up to 17 Israeli defense contractors and the leak of material tied to the Australian ADF Redback (Hanwha/Redback IFV) program - indicating continued, evolving operations. MENA relevance: HIGH and REAL - Israel is a confirmed primary victim country, the near-exclusive focus of Cyber Toufan's destructive hack-and-leak and wiping campaigns since November 2023 (Signature-IT supply chain, dozens of Israeli government-linked and commercial orgs, and Israeli defense contractors). The Israel targeting is well-corroborated; the Iran-nexus attribution behind it is an assessed, unconfirmed link and should remain caveated.