Skip to content

Israel Science and Technology Directory Files Published, Though Most of It Was Already Public

Breach Report Israel Public Web Directory Published Free

Israel Science and Technology Directory Files Published, Though Most of It Was Already Public

A forum actor posting as weykofa has published 16.2 MB across 450 files attributed to science.co.il, the Israel Science and Technology Directory. The site is a public catalogue of Israeli research centres, universities, companies, associations and government bodies, organised by discipline. The itemised contents reflect that: embassy and bank contact details, university leadership emails and phones, venture fund and municipal contacts, and listings for government offices and ministers. Two categories stand apart from the published directory, namely a small set of visitor log entries with addresses, hosts and dates, and a handful of legal documents. The claim is unverified.

Size16.2 MB
Files450
Non public itemsFew
Actorweykofa

Post details

Targetscience.co.il
CountryIsrael
SectorPublic web directory
ListingFree download
Volume450 files, 16.2 MB
Stated sourceNot described
Observed
Actorweykofa

!What the post claims

  • 450 files, 16.2 MB
  • 91 embassy contact sets
  • 164 international banks
  • 12 volunteer organisations
  • 9 university presidents
  • 7 provosts
  • 8 vice presidents for research
  • 56 venture funds
  • 42 Israeli banks with codes
  • 29 company director listings
  • 30 ministers with party affiliations
  • 211 government offices
  • 252 cities
  • 53 municipalities
  • Emails, phones and fax numbers
  • 11 visitor log entries
  • 9 lawsuit documents
  • 2 court judgments

Screenshot

Forum post publishing science.co.il files, observed 2 September 2026.

Mapped techniques

The post describes no intrusion method. All entries are inferred from the artefacts, not stated.

  • Reconnaissance T1594 Search victim owned websites Inferred The great majority of the itemised contents corresponds to material the site publishes as its function, which is obtainable without any access to the server.
  • Collection T1213 Data from information repositories Inferred Visitor log entries and stored legal documents are not part of the public directory, so if genuine they came from the server rather than from the front end.
  • Exfiltration T1567 Exfiltration over web service Inferred Distribution runs through links posted in the thread.

Potential impact

Almost everything itemised here is information the site exists to publish, so the practical effect is convenience rather than disclosure: an attacker gets a tidy, pre sorted contact list for embassies, ministries, municipalities and university leadership instead of having to compile one. That still has value for targeted phishing against named officials, particularly where personal rather than role based addresses are included. The genuinely non public elements are a handful of visitor log entries and some stored legal documents, and those, not the directory content, are what would indicate the server itself was reached.

iStatus Unverified

The listing reads as an inventory of a website's contents rather than a database, with no tables, user accounts, credentials or record counts of the kind a compromised application produces. The "leaked" framing overstates what is described, since a public directory being copied is not the same as a directory being breached, and only the log entries and legal files would suggest otherwise. The account is new with no standing, and Dark Web Informer has not retrieved the files and is not linking them.

Dark Web Informer // Threat Intelligence

Latest