MENA hacktivist groups and the operations they publicly claim — DDoS, defacement and hack-and-leak postings, curated from public claim channels. Every row is a claim by the group, not a confirmed breach or verified outage — metadata only, same posture as Ransomware Watch. A group name links to its actor profile when matched, and shared tradecraft/infrastructure across sources is what Correlated Activity clusters.
This is a curated collection, not a live feed: new claims are added as the analyst verifies them as public postings, not in real time.
Group claims, not confirmed impacts — metadata only.
40 of 40 shown
| Group | Type | Target | Sector | Country | Claimed | Motive |
|---|---|---|---|---|---|---|
| BD Anonymous Team | DDoS | Qatar Ministry of Interior online services | Government / Interior | QatarQA | 2026-02-28 | pro-palestine |
| Dark Storm Team | DDoS | Israeli financial entities (DDoS and claimed data-leak activity; secondary spillover into Saudi Arabia) | Financial Services | IsraelIL | 2026-02-28 | pro-palestine |
| DieNet | DDoS | Kuwait government/critical infrastructure (Ministry of Defense, Kuwait Airport, Kuwait Finance House, National Bank of Kuwait, Gulf Bank) — part of a Gulf-wide (BH/QA/AE/KW/SA) DDoS wave | Government / Finance / Aviation | KuwaitKW | 2026-02-28 | pro-iran |
| Handala Hack Team | DDoS | Jordanian fuel-station / gas infrastructure (nationwide disruption claimed, unverified) | Energy / Fuel Distribution | JordanJO | 2026-02-28 | pro-iran |
| Nation of Saviors | Other | Israel Education Ministry (DDoS/site compromise) and a Saudi private entity (claimed 21GB data theft) | Government / Education | IsraelIL | 2026-02-28 | pro-palestine |
| Handala Hack Team | Data leak | Clalit Health Services (Israel's largest HMO; claimed medical data of 10,000+ patients) | Healthcare | IsraelIL | 2026-02-25 | pro-palestine |
| Cyber Toufan ↗ | Data leak | Maya Engineering (Israeli defense contractor; 117 internal CCTV videos + weapons-component drawings leaked; part of claimed 17-firm supply-chain breach) | Defense Manufacturing | IsraelIL | 2025-11-04 | pro-palestine |
| Team Fearless | DDoS | Multiple Qatar government websites (cited Doha inaction after Israeli strike on Hamas leadership in Doha) | Government | QatarQA | 2025-09-10 | pro-palestine |
| Cyber Fattah | Data leak | 2024 Saudi Games records (6,000+ athletes/visitors; passports, IDs, IBANs, bank statements, medical forms) | Sports / Government | Saudi ArabiaSA | 2025-06-22 | pro-iran |
| Predatory Sparrow ↗ | Data leak | Nobitex cryptocurrency exchange (~$90M drained to vanity 'burn' wallets; full source code and internal docs published) | Cryptocurrency Exchange | IR | 2025-06-18 | anti-iran |
| Predatory Sparrow ↗ | Other | Bank Sepah and Bank Pasargad (data centers wiped/corrupted; internet, mobile banking and ATMs crippled nationwide) | Banking | IR | 2025-06-17 | anti-iran |
| Mr Hamza | DDoS | Israeli government / critical websites (unnamed; #OpIsrael, peaked 16 Jun 2025 after Israeli strikes on Iran) | Government / Multiple | IsraelIL | 2025-06-16 | pro-iran |
| Handala Hack Team | Data leak | Israel Police (claimed ~2.1TB; ~350,000 files incl. weapon permits, personnel and case records; Israel denies, points to third-party vendor) | Law Enforcement | IsraelIL | 2025-02-09 | pro-palestine |
| Handala Hack Team | Other | Maagar-Tec emergency-alert system (compromised to push false alerts; ~20 kindergarten institutions affected) | Public Safety / Alerting | IsraelIL | 2025-01-27 | pro-palestine |
| Handala Hack Team | Data leak | El'ad municipality (claimed 3+ TB) | Municipal | IsraelIL | 2024-11-03 | pro-palestine |
| Handala Hack Team | Data leak | Shin Bet (claimed data on ~30,000 officers) | Intelligence | IsraelIL | 2024-10-03 | pro-palestine |
| Handala Hack Team | Data leak | Soreq Nuclear Research Center (claimed ~197GB; assessed by Israel as psychological warfare) | Nuclear Research | IsraelIL | 2024-09-30 | pro-palestine |
| Handala Hack Team | Data leak | Emails attributed to former Israeli FM Gabriel 'Gabi' Ashkenazi (60,000+ emails claimed) | Government / Political | IsraelIL | 2024-09-26 | pro-palestine |
| Handala Hack Team | Data leak | Ma'agan Michael Kibbutz (22GB exfiltrated; 5,000+ warning SMS) | Agriculture / Local Community | IsraelIL | 2024-06-15 | pro-palestine |
| Anonymous Sudan ↗ | DDoS | UAE entities (unspecified) — claimed as retaliation over alleged RSF support | — | UAEAE | 2024-02-01 | anti-UAE |
| Handala Hack Team | Other | Israeli citizens via spoofed 'HamsaUpdate' security-update wiper | Consumer | IsraelIL | 2023-12-19 | pro-palestine |
| Cyber Av3ngers ↗ | Defacement | Unitronics Vision Series PLCs / HMIs (Israeli-made ICS devices; 'Down with Israel' defacement) | Water / Critical Infrastructure | IsraelIL | 2023-11-25 | anti-Israel |
| Cyber Toufan ↗ | Data leak | Israel Innovation Authority | Government | IsraelIL | 2023-11-16 | pro-palestine |
| Cyber Toufan ↗ | Data leak | Signature-IT hosting provider (data of ~40-49 Israeli firms; servers wiped) | IT Hosting / Multiple | IsraelIL | 2023-11-16 | pro-palestine |
| AnonGhost | Other | 'Red Alert: Israel' rocket-warning app (API exploited to push fake alerts, incl. 'nuclear bomb' message) | Mobile App / Public Safety | IsraelIL | 2023-10-09 | opisrael |
| Anonymous Sudan ↗ | DDoS | The Jerusalem Post website | Media | IsraelIL | 2023-10-08 | opisrael |
| KillNet ↗ | DDoS | Israeli government website (and claimed Shabak/Shin Bet site) | Government | IsraelIL | 2023-10-08 | pro-russia |
| Mysterious Team Bangladesh | DDoS | UAE government ministries (Defence, Energy & Infrastructure, Health & Prevention portals) | Government | UAEAE | 2023-05-20 | opuae |
| Anonymous Sudan ↗ | DDoS | Flydubai airline website | Aviation | UAEAE | 2023-05-06 | anti-UAE |
| Anonymous Sudan ↗ | DDoS | Dubai Police and UAE government / media websites | Government / Law Enforcement | UAEAE | 2023-05-06 | anti-UAE |
| Anonymous Sudan ↗ | DDoS | UAE government portals and Emirati banks (8 official UAE domains) | Government / Banking | UAEAE | 2023-05-05 | anti-UAE |
| Anonymous Sudan ↗ | DDoS | Iron Dome / missile-alert systems (claim unconfirmed by Israel) | Defense | IsraelIL | 2023-05-02 | opisrael |
| Anonymous Sudan ↗ | DDoS | Israeli government, port and Mossad websites | Government | IsraelIL | 2023-04-26 | opisrael |
| Anonymous Sudan ↗ | DDoS | Israel Post and Israeli banks (Bank Leumi, Discount Bank, Mizrahi-Tefahot, First International Bank) | Postal / Banking | IsraelIL | 2023-04-14 | opisrael |
| Cyber Toufan ↗ | Data leak | Mann-Shinar (Israeli infrastructure-projects firm; claimed ~5GB incl. 800+ design files) — ~March 2025 | Engineering / Infrastructure | IsraelIL | — | pro-palestine |
| Handala Hack Team | Data leak | Israeli Air Force personnel (claimed 180+ profiles / dossiers on pilots and drone operators) | Defense / Military | IsraelIL | — | pro-palestine |
| RipperSec | DDoS | Israeli media, government and supporting organisations (Medusa botnet; aggregate 2024 campaign) | Government / Media | IsraelIL | — | pro-palestine |
| SN_BLACKMETA | DDoS | Israeli telecoms and the Tel Aviv Stock Exchange | Telecom / Finance | IsraelIL | — | pro-palestine |
| SN_BLACKMETA | DDoS | Saudi Ministry of Defense website | Government / Defense | Saudi ArabiaSA | — | pro-palestine |
| SN_BLACKMETA | DDoS | Middle Eastern financial institution (reported as a UAE bank) — six-day, ~100-hour DDoS | Financial Services | UAEAE | — | pro-palestine |
Columns match spec §7 doctrine: group (linked when matched, plain when not), op-type badge, target, sector, country, claim date, motive. No claim/leak/onion URL is ever stored or shown, mirroring Ransomware Watch.