RaqibCTI

Hacktivist Watch · MENA

Hacktivist claim sources · updated 20h agocurated OSINT · 40 claimed ops

MENA hacktivist groups and the operations they publicly claim — DDoS, defacement and hack-and-leak postings, curated from public claim channels. Every row is a claim by the group, not a confirmed breach or verified outage — metadata only, same posture as Ransomware Watch. A group name links to its actor profile when matched, and shared tradecraft/infrastructure across sources is what Correlated Activity clusters.
This is a curated collection, not a live feed: new claims are added as the analyst verifies them as public postings, not in real time.

Group claims, not confirmed impacts — metadata only.

40Claimed ops · MENA
0Last 90 days
Handala Hack TeamMost active group
IsraelMost-claimed country
Claims by month · this yearJanSep now
Feb 2026: 6
JFMAMJJAS
Claim type40 ops · 4 types
group
country

1 of 40 shown · filtered to Defacement

GroupTypeTargetSectorCountryClaimedMotive
Cyber Av3ngersDefacementUnitronics Vision Series PLCs / HMIs (Israeli-made ICS devices; 'Down with Israel' defacement)Water / Critical InfrastructureIsraelIL2023-11-25anti-Israel

Columns match spec §7 doctrine: group (linked when matched, plain when not), op-type badge, target, sector, country, claim date, motive. No claim/leak/onion URL is ever stored or shown, mirroring Ransomware Watch.