Israel’s Shin Bet security agency and the National Cyber Directorate have thwarted 85 attempted Iranian cyberattacks in recent months, aimed at high-profile Israeli civilians and public servants, including security officials, politicians, academics, journalists, and media personalities.
According to a statement released Wednesday, Iranian operatives have dramatically increased their use of phishing tactics—posing as journalists, researchers, or professionals on WhatsApp, Telegram, and email, in order to extract sensitive login credentials from targets.
These credentials, once obtained, are used to access personal Gmail accounts, cloud-stored images, location data, and even passwords for other services, allowing hostile actors to map the routines, relationships, and vulnerabilities of key Israeli figures.
Shin Bet officials emphasized that the ultimate purpose of the cyber campaigns is to gather intelligence for physical attacks inside Israel, possibly using domestic operatives recruited and activated by Iran.
One common method involves fake invitations to Google Meet calls, where the victim is prompted to enter login credentials on a spoofed page, granting the attacker full access to their Google ecosystem.
Other attack vectors include:
- Fake mobile apps disguised as legitimate tools
- Malicious files disguised as research reports or approval forms, which install spyware once opened
A Shin Bet official warned:
“This is part of Iran’s ongoing war against Israeli society, and these attacks can be prevented with proper cyber hygiene—avoiding unknown links, staying alert, and never sharing credentials with unverified sources.”
Authorities urged the public, especially those in public roles, to remain vigilant and suspicious of unsolicited messages, and to report any suspicious communications to Israel’s cyber response centers.
The Shin Bet reaffirmed its commitment to preemptively detecting and neutralizing Iranian cyber operations before harm can be done.








