Former Hamat Security Chief Charged with Hundreds of Cyber Offenses
Miki Bar, the former information security manager for the Hamat Group, a home design and construction firm, has been indicted for conducting cyberattacks against 26 companies between 2019 and 2026. The state alleges these attacks caused approximately 1.5 million shekels in damages. The indictment, filed at the Rishon Lezion Magistrate's Court, reveals Bar primarily targeted women, including in their homes, using artificial intelligence to create malicious software. He developed two types of malware, "windows malware" and "wesearch malware," designed to infiltrate and control other computers, collect data, record keystrokes, track user activity, spread through organizational systems, disable defenses, alter operating systems, and steal cryptocurrency wallet information, persisting even after a computer was shut down.
Bar allegedly deployed these malware programs on the computers of 26 companies and the kibbutzim of Gazit and Kfar Menachem between February and August of the current year. He performed 2,400 actions using the windows malware and 1,300 actions with the wesearch malware. In April, the National Cyber Directorate contacted Bar out of concern that Hamat itself might be a target, unaware he was the perpetrator. This prompted Bar to develop the more sophisticated wesearch malware after realizing the attacks had been discovered.
The state claims Bar infiltrated the systems of organizations including Solagrin, RBS, Hamat, Atidim Association, Gindi, FBS Technologies, Blue Square Real Estate, and Yad2. His targets were typically women, and he photographed and documented them, including minors, often in non-intimate situations, incidentally capturing business activities. The state attributes hundreds of offenses to him, including illegal software operations, computer intrusion for illicit purposes, virus deployment, privacy violations, theft, and illegal software actions.
In its request to detain Bar until the proceedings conclude, the state cited evidence such as the malware found on his computer, his use of "Cloud" software for development, server links used to operate the malware, thousands of stolen files organized by victim name, communications from attacked companies and women he tracked, cyber investigator reports, and Bar's partial confessions. The indictment states Bar "inserted self-made malicious software into computers and copied from them, without the knowledge and consent of the users, extremely sensitive materials stored therein, including computer passwords, files written or saved on the computer, real-time screenshots of the user's activity on the computer, and additionally created through the computer documentation from the computer camera initiated by the respondent. Among the materials received from the victims' computers were also extremely sensitive personal materials of users of the attacked computers, particularly media files documenting women and minors in intimate situations."