Iranian Intelligence Intensifies Phishing Attacks on Israeli Journalists

The Shin Bet and the National Cyber Directorate have identified a new wave of Iranian phishing attacks targeting journalists and media personnel in Israel. The goal is to obtain sensitive information amidst current political and security developments.

MaarivAuthor: Avi Ashkenazi
Source
Iranian Intelligence Intensifies Phishing Attacks on Israeli Journalists
Photo: Maariv / כרזה עם תמונתו של מוג'תבא חמינאי בטהרן | צילום: מג'יד אסגריפור/WANA, רויטרס

As part of a joint operation by the Shin Bet and the National Cyber Directorate, a new wave of attempts by Iranian intelligence agencies to target journalists and media personnel in Israel through phishing attacks has been identified. The objective is to obtain information against the backdrop of recent political and security developments. Both agencies are currently working to thwart these efforts.

In this targeted phishing method, journalists are contacted, mainly via WhatsApp or Telegram, by individuals impersonating familiar figures. The messages are tailored to the target's interests, such as offers for collaboration, interview invitations, or requests for conversation. The purpose is to establish a reliable contact and lead the target to click a link that directs them to a fake page requesting Google account credentials, or to open malicious files that can compromise mobile devices. In some cases, attackers impersonate well-known reporters.

It is estimated that Iranian intelligence is attempting to collect sensitive information related to security and political developments, gain access to journalistic sources, work materials, and correspondence. This information could be utilized for terrorism, espionage, intelligence gathering, and influence operations. These efforts are also being directed at targets in other sectors, requiring increased vigilance from all those engaged in political, public, and governmental activities.


An oil facility in Kuwait was damaged by an Iranian attack (Photo: social networks, use according to section 27a)


The National Cyber Directorate has provided several recommendations for account protection:

  1. Verify the identity of the caller via an alternative communication channel, especially when receiving unexpected requests containing links, files, or requests for personal details.

  2. Do not enter passwords or verification codes following a link received in a message, even to connect to a video call.

  3. Activate two-factor authentication on all major accounts (Google, WhatsApp) using an authenticator app.

  4. Set up a recovery email address.

  5. Perform periodic checks of account logins and remove unknown devices or connections.

"Report any suspicious attempt immediately to your organization's security authorities and to the 119 hotline of the National Cyber Directorate," the agency added.

Related News