MENA hacktivist groups and the operations they publicly claim — DDoS, defacement and hack-and-leak postings, curated from public claim channels. Every row is a claim by the group, not a confirmed breach or verified outage — metadata only, same posture as Ransomware Watch. A group name links to its actor profile when matched, and shared tradecraft/infrastructure across sources is what Correlated Activity clusters.
This is a curated collection, not a live feed: new claims are added as the analyst verifies them as public postings, not in real time.
Group claims, not confirmed impacts — metadata only.
5 of 40 shown · filtered to Other
| Group | Type | Target | Sector | Country | Claimed | Motive |
|---|---|---|---|---|---|---|
| Nation of Saviors | Other | Israel Education Ministry (DDoS/site compromise) and a Saudi private entity (claimed 21GB data theft) | Government / Education | IsraelIL | 2026-02-28 | pro-palestine |
| Predatory Sparrow ↗ | Other | Bank Sepah and Bank Pasargad (data centers wiped/corrupted; internet, mobile banking and ATMs crippled nationwide) | Banking | IR | 2025-06-17 | anti-iran |
| Handala Hack Team | Other | Maagar-Tec emergency-alert system (compromised to push false alerts; ~20 kindergarten institutions affected) | Public Safety / Alerting | IsraelIL | 2025-01-27 | pro-palestine |
| Handala Hack Team | Other | Israeli citizens via spoofed 'HamsaUpdate' security-update wiper | Consumer | IsraelIL | 2023-12-19 | pro-palestine |
| AnonGhost | Other | 'Red Alert: Israel' rocket-warning app (API exploited to push fake alerts, incl. 'nuclear bomb' message) | Mobile App / Public Safety | IsraelIL | 2023-10-09 | opisrael |
Columns match spec §7 doctrine: group (linked when matched, plain when not), op-type badge, target, sector, country, claim date, motive. No claim/leak/onion URL is ever stored or shown, mirroring Ransomware Watch.