Threats · 138 days ago
Handala is no longer just leaking names and data. It is pairing public doxxing with direct threats over WhatsApp, which turns exposed personnel into targets for coercion, intimidation, and possible physical follow-on pressure. The standard response of treating this as a nuisance influence campaign misses that the messaging is tailored to deployed service members and meant to shape behavior, not just spread propaganda.
The group told US troops in Bahrain they were under surveillance and would be hit with drones and missiles. It also boasted on Telegram about publishing personal information on 2,379 US Marine Corps members stationed in the Persian Gulf. The campaign follows earlier activity against Israeli infrastructure and a broader shift toward direct contact with US institutions and military personnel.
For defense and government organizations, the risk is no longer limited to data exposure. Once personal details are public and the threat actor can reach individuals directly, the campaign can move from online intimidation to persistent targeting of deployed personnel.
2 sources covering this story
Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats
US Marines stationed around the Persian Gulf have been receiving WhatsApp messages from strangers suggesting they call home and make their final goodbyes.
Iranian Cyber Group Handala Targets US Troops in Bahrain
US service members received WhatsApp messages claiming they would be targeted with drones and missiles.
Part of the PlainSec briefing for 2026-05-01