Israel Warns of Tailored Phishing Traps on WhatsApp
The national cyber body says attackers are researching senior figures in government, academia and the media, then messaging them with bait built to fit.

איור
הכתבה המלאה עדיין לא נכתבה בעברית, ולכן היא מובאת כאן באנגלית.
Israel’s national cyber authority warned of a rise in targeted phishing attempts arriving through messaging apps including WhatsApp and Telegram, in messages designed to look convincing because they impersonate well-known organisations. The warning, issued in late December 2025, said the attempts are aimed at senior officials and prominent figures in fields including academia, government and the media, and are tailored to each target’s known interests.
The distinction the warning draws is the important one. In ordinary phishing, an attacker sends the same lure to everyone and waits. Here, the notice said, the attacker does not distribute a random message but builds the approach on information gathering and prior planning, the technique the security industry calls spear-phishing.
Who issued the warning
The body behind it, referred to in the original release as the National Cyber Command, is the Israel National Cyber Directorate. It was created in December 2017 by merging the National Cyber Security Authority with the Israeli National Cyber Bureau and sits under the Prime Minister’s Office, with responsibility for civilian cyber defence and for running the national computer emergency response team, CERT-IL, which handles reports from the public and from companies around the clock.
How much of this Israel is seeing
The directorate’s own annual figures give a sense of the volume behind a warning like this one. In a report covered by Israel Defense in March 2026, the directorate said it issued roughly 2,480 alerts during 2025, about two and a half times the 2024 total, and that its 119 reporting centre received around 26,500 incident reports, up 55 per cent year on year. Phishing accounted for 52 per cent of the most common attack vectors. Reporting peaked in June, during Israel’s military operation against Iran, when the centre logged 3,650 reports, 75 per cent above the monthly average. The remaining traffic clustered around supply-chain compromises, unpatched systems, remote-access connections and internet-connected devices sitting on organisational networks.
What a tailored attack actually looks like
Public threat-intelligence work gives a picture of the tradecraft. Google’s Mandiant division, describing the Iranian group it tracks as APT42 and assesses to be working for the Islamic Revolutionary Guard Corps Intelligence Organisation, documented operators who spend weeks in friendly correspondence with a target before sending anything malicious. Their infrastructure included domains a character away from real news outlets (typo-squatted versions of The Washington Post and The Jerusalem Post among them) and cloned Google, Microsoft and Yahoo sign-in pages; where a fake two-factor page failed to capture a token, operators pushed authentication prompts at the victim until one was approved. Nothing in the Israeli directorate’s warning attributes the current wave to any particular actor.
What is still unclear
The warning did not say how many attempts have been detected, over what period, or whether any have succeeded. It named no impersonated organisations and no suspected origin for the campaign, and it did not set out what recipients are advised to do beyond treating unexpected approaches with suspicion.
מקורות וקריאה נוספת
פתחנו ובדקנו כל קישור כאן בזמן כתיבת העמוד. הודעות רשמיות מסומנות ככאלה: זו הגרסה של הגורם עצמו, לא גרסה עצמאית.
- כתבותGoogle Cloud / Mandiantcloud.google.comUncharmed: Untangling Iran's APT42 Operations
Documented spear-phishing tradecraft against Middle Eastern targets
- נתוניםIsrael Defenseisraeldefense.co.ilINCD Report: Israel Faced Record Cyber Threats in 2025 as Alerts Surged
The directorate's 2025 alert, incident-report and phishing-share figures
- רקעWikipediaen.wikipedia.orgIsrael National Cyber Directorate
What the directorate is, when it was formed and where it sits in government
איך בדקנו את זה
The warning itself is the Israel National Cyber Directorate notice of 28 December 2025 as reported by The Press Service of Israel; no attacker, victim or volume has been added to it. The 2025 phishing and incident-report figures come from the directorate's annual report as covered by Israel Defense, and the description of tailored phishing tradecraft from Google Cloud's published threat research.
תיאור האירוע עצמו נשען על ההודעה הרשמית ולא אומת באופן עצמאי על ידי Israel.com. במקום שבו ההודעה שותקת, העמוד הזה אומר זאת במקום למלא את החסר.
מדיניות המקורות והתיקונים שלנו →השבוע מישראל, במייל אחד
הכתבות שהיו חשובות, עם מקורות ובדיקה של מערכת Israel.com. חינם, פעם בשבוע, הסרה בלחיצה אחת.
רשימה אחת, הסרה בלחיצה. קראו את מדיניות הפרטיות שלנו.
עוד במדור ביטחון
למדור ביטחון →הכתבות האחרונות
- טראמפ נשא דברים בלי קול אחרי שהרשתות באמריקה השביתו את סיקור הפול
- תקלה בכבל סיבים אופטיים שיבשה טיסות בחוף המזרחי של ארה"ב
- רשתות הטלוויזיה בארה"ב השביתו את מאגר הכתבים בבית הלבן, טראמפ נשא דברים בלי קול
- צה"ל תקף מטרות חמאס בעזה אחרי שכלי הנדסי נפגע ממטען
- ארה"ב נערכת להטיל סנקציות שיחסמו את בית הדין בהאג מעסקאות בדולרים
- כלי הנדסי של צה"ל נפגע ממטען סמוך לקו הצהוב ברצועה


