Breaking· Security· Updated
Israel's Education Ministry Violated Privacy Law, Leaking Sensitive Data of Special Needs Students
Israel's Privacy Protection Authority ruled on Thursday, October 8, 2026, that the Ministry of Education violated privacy laws and information security regulations. The ruling follows an investigation into a major data leak that exposed the sensitive personal and medical information of approximately 21,000 special education students in the Haredi sector.
7 newsrooms · 2 languages · sinceWhat happened
- 01The Privacy Protection Authority ruled that the Ministry of Education violated privacy laws by leaking sensitive data of 21,000 Haredi special education students.
- 02The leaked data included identifying details, home addresses, religious affiliation, and specific medical information regarding the students' disabilities.
- 03In May 2024, ministry employees created an unprotected digital form for student placements, which generated the compromised data file.
- 04The data file was accessible via an open, password-free link sent to educational personnel and was widely distributed to unauthorized individuals.
- 05The authority identified multiple security failures, including poor permissions management, lack of data encryption, and missing security documentation.
- 06The Ministry of Education's international ISO certification did not exempt it from Israeli privacy regulations.
- 07No financial penalties were imposed on the ministry because the breach occurred before a legal amendment allowing for such fines.
The investigation was launched in March 2025 after media reports revealed that the data had been distributed online to unauthorized parties. The probe found that in May 2024, ministry employees created an unprotected digital form to streamline student placements. This form generated a data file containing identifying details, home addresses, religious affiliation, and specific medical information about the students' disabilities.
The file and form were accessible via an open, password-free link sent to educational institution personnel, allowing unauthorized individuals to access and widely disseminate the data. The authority cited multiple security failures, including deficiencies in permissions management, system operation, data encryption, and a lack of required security documentation.
Although the Ministry of Education claimed the breach was a specific malfunction in authorization settings and cited its international ISO certification, the authority rejected these arguments. No financial penalties were imposed because the breach occurred before a recent amendment to the law allowing for such fines.
Summarized by baba from the reports of 6 newsrooms. Updated
Latest report: i24NEWS. Read i24NEWS’s originalThe coverage
7 newsrooms on this story
Who covered it
- LeftNone
- Centre3
- Right1
- HarediNone
- ArabNone
- Other3
