Israeli soldiers built their own AI-assisted apps, and 170 conscripts' details ended up online
Haaretz reports that websites and applications built inside the IDF with AI tools exposed personal data on some 170 active-duty conscripts, along with classified procedures and internal investigation material — and that a soldier who reported it waited a week for a reply.
The account comes from a single named outlet. Haaretz’s Tech Roundup desk reported on 23 August that personal details of roughly 170 active-duty conscripts, together with classified procedures and material from internal investigations, were reachable through websites and applications that soldiers had built themselves using AI tools. A soldier who alerted the army to the exposure reportedly received no response for a week. The piece is paywalled, and this desk has not seen the finding independently confirmed by any other outlet, by the IDF Spokesperson’s Unit or by an Israeli regulator. What gives it weight beyond a single story is the framing Haaretz itself chose: it presents the case as “another leak,” implying a sequence rather than an incident.
This is not an adversary story, which is precisely why it is the more durable one. Nothing in the reporting requires an Iranian operator, a hacktivist front or a zero-day. It requires a conscript with a generative-AI coding assistant, a deployment nobody logged, and a reporting channel that did not answer for seven days. The adversary-side pressure on the same population is documented separately: Haaretz reported on 16 August that the Shin Bet had warned of Iranian intelligence attempts to compromise Israeli journalists' phones and accounts via WhatsApp and Telegram, and on 4 May that investigators reviewing Iran’s penetration of the Institute for National Security Studies were working through more than 100,000 emails and messages accumulated over a six-year campaign. Self-inflicted exposure and hostile collection are not competing explanations for a leak. They compound.
Assessment: Treat the 170 figure as Haaretz’s, not as an established count, until the IDF says something on the record — and note that no other outlet appears to be working the story, which is unusual for a number that specific. The question the desk would put to the army is not who took the data but how many such apps exist, who authorised them, and what the seven days of silence indicates about the intake process. Militaries currently write AI policy for models and prompts. The exposure surface here is the tooling: a soldier shipping a working web app in an afternoon, outside any accreditation regime.