The Fake Investor, the Broken Zoom Link and an Israeli Startup
Israel's National Cyber Directorate said attackers built a credible investor profile, then used a bogus video-call link to plant malware on a company's computers.

Illustration
A large Israeli startup reported what Israel’s National Cyber Directorate called a “particularly sophisticated” cyberattack: an elaborate impersonation of a business meeting with an investor that ended with a malicious file being downloaded during a video call, computers taken over and sensitive information exposed. The account was issued through the Press Service of Israel on 3 August 2025.
According to the Directorate, the approach began with a flattering message from a supposed investor on a social network. The profile looked credible: a professional photograph, an investment history, an impressive business background. The correspondence moved quickly to arranging an online meeting, but instead of a legitimate video-call link the employees received one that looked like a Zoom link and instead downloaded a malicious file when clicked. When the call would not work, the attackers sent a second link and persuaded the staff to install software that would supposedly fix the Zoom problem, planting further malware on the company’s computers and on a mobile phone. No personal customer information was stolen, the Directorate said, but sensitive financial information was exposed.
This is a recognised attack pattern, and it has a shape
The sequence described (plausible investor, calendar invitation, spoofed meeting page, fake audio problem, “fix” that is really malware) matches a technique documented in detail by security researchers. The Hacker News reported in June 2025 on a campaign in which an attacker posing as an external contact sent a scheduling link that redirected to a fake Zoom domain; when the victim reported audio trouble during the call, they were sent a script disguised as an audio repair tool that quietly fetched a further payload while opening a genuine Zoom developer page as cover.
The pattern has since been mapped more fully. Google Cloud’s threat intelligence team published an analysis in February 2026 of a group it tracks as UNC1069, describing exactly this chain: contact through a compromised or fabricated account, a scheduling link to a spoofed meeting domain, an artificial-intelligence-generated video of a company executive to make the call convincing, a manufactured audio fault, and then “troubleshooting” commands that install the malware. The targets it listed were financial services and cryptocurrency businesses (payments, brokerage, staking and wallet infrastructure), along with software firms and their developers and venture capital firms and their staff.
Why the investor cover story works so well
The lure is well matched to its victims. An early-stage company expects unsolicited approaches from investors, expects to be flattered, and expects to move fast, which is why the Directorate’s warning stressed preparation rather than opportunism: attackers are upgrading their fraud methods with targeted phishing that includes prior research on the target, profiles built to look trustworthy, and fake domains registered months in advance.
What the National Cyber Directorate is
The Directorate is the Israeli government body responsible for defending civilian cyberspace, and it runs a reporting line, 119, for cyber incidents: the Times of Israel reported in October 2020 that some 10,000 Israeli citizens and organisations had called it over the preceding year to report hacked social media accounts, home routers, cameras and private email. The volume it handles has grown sharply since. Israel Defense reported in March 2026 that the Directorate issued roughly 2,480 alerts during 2025, two and a half times its 2024 figure, and that its emergency centre received about 26,500 incident reports, up 55 per cent year on year. Phishing accounted for 52 per cent of those incidents, ahead of influence operations at 13 per cent, account breaches at 11 per cent and system intrusions at 9 per cent.
What the report did not say
The Directorate did not name the company, the social network the approach came through, or the date of the attack. It gave no attribution to any group or country, did not say how many machines were compromised or how long the attackers had access, and did not say what became of the financial information that was exposed. It also did not say how the intrusion was eventually detected.
Sources and further reading
Every link below was opened and checked when this page was written. Official statements are marked as such: they are the subject's own account, not an independent one.
- ReportingThe Hacker Newsthehackernews.comBlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware
Technical account of the fake-Zoom-link and audio-fix technique
- ReportingIsrael Defenseisraeldefense.co.ilINCD Report: Israel Faced Record Cyber Threats in 2025 as Alerts Surged
National Cyber Directorate alert and incident volumes for 2025
- ReportingThe Times of Israeltimesofisrael.com10,000 Israelis have used 119 cyberhotline to report hacks
What the Directorate's 119 reporting line is and who can use it
- ReferenceGoogle Cloud Threat Intelligencecloud.google.comUNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering
Mapping of the fake-investor social engineering chain and its targets
How we checked this
The account of the attack and the Directorate's warning come from the Israel National Cyber Directorate report of 3 August 2025 as distributed by the Press Service of Israel; the company is unnamed and Israel.com has not verified the incident independently. The matching attack technique is documented by The Hacker News (June 2025) and Google Cloud's threat intelligence team (February 2026), and the Directorate's 2025 caseload figures come from Israel Defense.
Our sourcing and corrections policy →The week from Israel, in one email
The stories that mattered, sourced and checked by the Israel.com newsroom. Free, weekly, one-click unsubscribe.
One list, unsubscribe in a click. See our privacy policy.
More in Security
All security →Latest
- Houthi forces reported streaming into Yemen's port city of Mocha
- Israel says three Hamas weapons depots destroyed in strikes across Gaza
- Advisers warned Trump the Iran war could outlast his presidency
- Iranian agency reports explosions near Jask and the port of Sirik
- Drone sirens sound in Galilee Panhandle, then declared a false identification
- Netanyahu visits Mount Hermon inside Syria; Damascus calls it illegal


