HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

9.2 Million Israeli Population Records Sold – Authentic but Two‑Decades‑Old Data

A leak‑forum seller offered the entire Israeli Population and Immigration Authority registry; analysis proved the data is genuine but dates stop at 2005, exposing legacy personal data. The incident underscores the compliance need for robust data‑retention and privacy controls.

LiveThreat™ Intelligence · 📅 August 11, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

9.2 Million Israeli Population Records Sold – Authentic but Two‑Decades‑Old Data

What Happened – A seller on a public leak forum advertised the entire Israeli Population and Immigration Authority registry (≈9.2 M records). Independent analysis confirmed the data is genuine, but all records stop at 2005, meaning the breach reflects a 20‑year‑old dump, not a 2026 compromise.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how legacy data stores can become a compliance liability if not regularly reviewed, archived, or securely destroyed.
  • Highlights the need for documented data‑retention policies and evidence that personal data is protected or disposed of in line with SOC 2 CC6.1 (Data Retention & Disposal).
  • Shows the importance of privacy‑by‑design controls (e.g., consent, DSAR readiness) that can be proven with continuous evidence collection – the exact capability Verisq’s CookiePLUS provides.

Who Is Affected – Government / Public‑sector agencies that maintain large citizen registries; any organization that retains personal data beyond its required lifecycle.

Recommended Actions

  • Inventory all legacy personal‑data stores and map them to SOC 2 data‑retention controls.
  • Implement a formal data‑disposal schedule and capture evidence of secure deletion for audit.
  • Deploy continuous privacy‑compliance monitoring (e.g., CookiePLUS) to prove consent handling and DSAR responsiveness.

Technical Notes – The breach was disclosed via a leak‑forum listing; no CVE or exploit is identified. The data set includes national ID numbers, addresses, phone numbers, birth/death dates, immigration dates, and family links. Validation used Israeli ID check‑digit logic and family‑unit clustering to confirm authenticity. Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/196942/cyber-crime/9-2-million-israeli-records-sold-as-a-new-breach-are-20-years-old.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →