Threats Feed|Cyber Toufan|Last Updated 09/07/2026|AuthorCertfa Radar|Publish Date20/12/2023

Cyber Toufan: A New Threat in Cyber Warfare Targeting Israeli Entities

  • Actor Motivations: Exfiltration,Sabotage
  • Attack Vectors: Malware,Ransomware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Cyber Toufan, a newly emerged cyber group, has been conducting aggressive cyberattacks against Israeli organizations, aligning with regional geopolitical tensions. Their operations include extensive data breaches, extracting sensitive personal and business information, and targeting high-value entities like security firms, government agencies, and commercial businesses. The group also engages in psychological warfare and propaganda. Reports suggest coordination with other hacker groups and a potential link to state sponsorship, likely Iran. This suspicion is supported by similarities in tactics between Cyber Toufan and other Iran-linked groups. The group's activities signify a sophisticated level of cyber warfare and geopolitical strategy.

Detected Targets

TypeDescriptionConfidence
CaseBermad
A prominent Israeli water system provider. Bermad has been targeted by Cyber Toufan as the main target.
Verified
CaseMAX Security
A Tel Aviv-based security and risk management company. MAX Security has been targeted by Cyber Toufan as the main target.
Verified
SectorGovernment Agencies and Services
Verified
SectorProfessional Service
Verified
SectorUtilities
Verified
RegionIsrael
Verified

FAQs

Cyber Toufan Al-aqsa Campaign

A sophisticated cyber warfare group named Cyber Toufan Al-aqsa emerged and initiated a wave of aggressive cyberattacks against various organizations, primarily based in Israel. These attacks resulted in severe data breaches where large volumes of private corporate data and personal information were stolen and posted publicly online.

The attacks were carried out by a group calling itself Cyber Toufan Al-aqsa. Security experts suspect the group operates with state-sponsored backing, potentially from Iran, due to the complexity of their methods. Their goals are rooted in digital retaliation and psychological warfare, using data theft to make political statements and spread propaganda amidst regional conflicts.

The scale of the attacks was remarkably wide and rapid, claiming over 100 victims within a single month. The group targeted various sectors, including critical water infrastructure (Bermad), risk management firms (MAX Security), commercial food giants, fashion and e-commerce companies, as well as multiple government agencies.

The attackers targeted these entities because they hold critical national value, manage essential resources, or possess massive amounts of sensitive business and personal details. Disruption to these specific sectors allows the attackers to maximize economic damage, disrupt daily operations, and create a broader psychological impact.

Organizations should deploy dedicated dark web monitoring services to scan for compromised credentials or leaked corporate information before they can be exploited. Additionally, establishing robust digital security frameworks and keeping critical operational technologies isolated are vital steps to prevent network breaches by advanced threat groups.

About Affiliation
Cyber Toufan
Cyber Toufan is an Iranian-linked hacktivist group that emerged in November 2023 following the Hamas-Israel conflict, conducting a rapid series of data breach and leak operations against Israeli and pro-Israel organizations. The group claimed to have compromised and leaked data from dozens of Israeli companies, government agencies, and NGOs within weeks of its emergence, including sensitive personal data of Israeli citizens. Researchers assess Cyber Toufan operates with Iranian state backing given the volume, speed, and organization of its operations. The group uses Telegram channels to publish stolen data and amplify its psychological impact.
View Cyber Toufan's Insights