9.2 Million Israeli Population Records Sold – Authentic but Two‑Decades‑Old Data
What Happened – A seller on a public leak forum advertised the entire Israeli Population and Immigration Authority registry (≈9.2 M records). Independent analysis confirmed the data is genuine, but all records stop at 2005, meaning the breach reflects a 20‑year‑old dump, not a 2026 compromise.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how legacy data stores can become a compliance liability if not regularly reviewed, archived, or securely destroyed.
- Highlights the need for documented data‑retention policies and evidence that personal data is protected or disposed of in line with SOC 2 CC6.1 (Data Retention & Disposal).
- Shows the importance of privacy‑by‑design controls (e.g., consent, DSAR readiness) that can be proven with continuous evidence collection – the exact capability Verisq’s CookiePLUS provides.
Who Is Affected – Government / Public‑sector agencies that maintain large citizen registries; any organization that retains personal data beyond its required lifecycle.
Recommended Actions
- Inventory all legacy personal‑data stores and map them to SOC 2 data‑retention controls.
- Implement a formal data‑disposal schedule and capture evidence of secure deletion for audit.
- Deploy continuous privacy‑compliance monitoring (e.g., CookiePLUS) to prove consent handling and DSAR responsiveness.
Technical Notes – The breach was disclosed via a leak‑forum listing; no CVE or exploit is identified. The data set includes national ID numbers, addresses, phone numbers, birth/death dates, immigration dates, and family links. Validation used Israeli ID check‑digit logic and family‑unit clustering to confirm authenticity. Source: SecurityAffairs