Skip to main content
Get our mobile app
Download on the App StoreGet it on Google Play

Cybersecurity Alert

Iran Targets Israeli Journalists in Phishing

Israel's Shin Bet security service and National Cyber Directorate warn of sophisticated attempts to compromise reporters' accounts and access sensitive information

Iranian Intelligence Targets Israeli Journalists in Phishing Campaign

Israel's Shin Bet security service and the National Cyber Directorate issued a warning Sunday about a new wave of phishing attacks by Iranian intelligence operatives targeting Israeli journalists and media professionals. The campaign aims to extract information amid recent political and security developments in the region, according to the agencies, which said they have identified the attempts and are working to prevent and thwart them.

The attacks typically involve contact with journalists primarily through WhatsApp or Telegram, with operatives impersonating familiar figures and crafting personalized messages tailored to the target's professional interests and beat. Common lures include collaboration proposals, interview invitations, or requests for conversations.

The messages are designed to establish seemingly credible contact and trick recipients into clicking links purportedly for scheduling meetings. These links actually lead to fake pages requesting login credentials for Google accounts, or direct users to open malicious links and files that can compromise mobile devices. In some cases, attackers impersonate well-known journalists to approach their colleagues.

Pretending to be Barak Ravid
Pretending to be Barak Ravid (Photo: Srugim)

"The assessment is that through this method, Iranian intelligence operatives are attempting to collect sensitive information related to security and political developments, gain access to journalistic sources, work materials, correspondence, and additional information that could serve Iranian intelligence for terrorism, espionage, intelligence gathering, and influence operations," the agencies stated. "These efforts are also being directed at targets in additional fields, and therefore heightened vigilance and awareness are required from all those currently engaged in political, public, governmental, and security activity."

  • The National Cyber Directorate recommended several protective measures for account security:
  • Verify the identity of anyone making contact through an additional communication channel, especially when receiving unexpected messages containing links, files, or requests for personal information
  • Never enter passwords or authentication codes following a link received in a message, even to join a video call
  • Enable two-factor authentication on all primary accounts using an authenticator app, particularly for Google and WhatsApp
  • Set up a recovery email
  • Conduct periodic reviews of account logins and remove unfamiliar devices or connections
  • Immediately report any suspicious attempts to organizational security personnel and to the National Cyber Directorate's 119 hotline.
Ready for more?

Join our newsletter to receive updates on new articles and exclusive content.

We respect your privacy and will never share your information.

Enjoyed this article?

Yes (21)
No (1)
Follow Us:

Unmissable content


Loading comments...

Also of Interest