Israeli army left 170 conscripts' details online for a week after a soldier flagged the exposure
TheMarker reports the data sat on soldier-built applications made with AI tools, and came down only after a journalist called. No adversary required.
TheMarker, the business section of Haaretz, reported at 14:19 local time on 23 August that the personal details of roughly 170 active-duty conscripts, alongside classified procedures and internal investigation materials, were exposed through websites and applications built by serving soldiers using AI tools. According to the outlet, a soldier who noticed the exposure alerted the army and received no response; the material was taken offline only after TheMarker approached the IDF. The report is single-sourced, paywalled and Israeli, and the army’s response is characterised by the outlet rather than quoted in the accessible portion of the piece. It is nonetheless the only cleanly new item in the desk’s window, and the only one where the mechanism is documented rather than inferred.
Assessment: This will be bundled into the Iran-attribution cycle and should not be. Nobody broke in. The exposure was produced by the defender’s own tooling — vibe-coded internal applications shipped without review by conscripts with access to classified procedure — and the control failure was the week of silence after a soldier raised it. That is a governance problem, not a threat-actor problem, and it is the pattern the desk expects to see repeat across militaries and ministries that have handed AI code generation to junior staff faster than they have written rules for it. The open question is whether the IDF now audits soldier-built applications, and whether this is the first such case this year or the third.