A Stressful Message from the Tax Authority: An Urgent Warning for Israeli Citizens

A new and particularly sophisticated phishing attack is trying to trap Israelis online. The fake messages threaten criminal proceedings and set a tough 72-hour ultimatum, but cyber experts warn of the real danger hidden inside.

Source
A Stressful Message from the Tax Authority: An Urgent Warning for Israeli Citizens
Photo: ICE / האקרים (צילום unsplash)

A new phishing attack has been circulating in Israel in recent days, attempting to trap citizens by impersonating the Tax Authority. As part of the campaign, emails are sent that appear to be official notifications, claiming that an investigation has been opened against the recipient on suspicion of tax offenses, with a threat of criminal proceedings if they do not act within 72 hours.

In the fake message, it is claimed that there is a suspicion of income concealment and the execution of artificial transactions for the purpose of obtaining tax benefits. Users are asked to download an "investigation report" via a link attached to the email, noting that the download is suitable for Windows computers only. According to security experts, this is one of the main signs of an attempt to introduce a malicious file to the victim's computer.

A check conducted by the Israeli cyber company BrandShield revealed that this is an impersonation containing several warning signs. Among other things, the message is not sent from an official government address, but from a foreign address, and the displayed email address includes a domain that does not belong to the State of Israel. In addition, unusual phrasing, spelling errors, dates in a format not accepted in Israel, and incorrect contact details were found.

The Tax Authority clarifies that official messages regarding documents or updates are not sent in a way that asks the citizen to download files via a link in an email. Usually, when there is an official document for the citizen, the referral is made through the personal area on the government website and not via an external link.

Most phishing attacks rely on a combination of three key elements: authority, intimidation, and urgency. Experts emphasize:

"When a threat of an investigation, a demand to act in a short time, and a link to download a file appear together, one must stop and not click."

Cyber experts note that recently there has been an increase in impersonations of government bodies and well-known companies, as the use of AI (artificial intelligence) tools allows criminals to create messages that look more professional and credible.

To avoid falling into the trap, it is recommended to carefully check the sender's address, avoid downloading files from unknown sources, and not enter links that appear in stressful messages. In the case of a message that looks like it was sent by a government body, the safe way is to enter the official website independently and not through the link you received.

The most important rule, according to security experts, is simple: a message that tries to make you act quickly through fear and threats is a clear sign to stop and check before any action.

Related News