Skip to main content
isrl.com

Israel Warns of Tailored Phishing Traps on WhatsApp

The national cyber body says attackers are researching senior figures in government, academia and the media, then messaging them with bait built to fit.

The Israel.com Newsroom··2 min read·
Share
Illustration of a fishing hook dangling above a glowing smartphone on a desk, symbolizing a targeted phishing lure.

Illustration

Illustration, generated by an image model, not a photograph: a fishing hook dangling above a glowing smartphone on a desk, symbolizing a targeted phishing lure. It shows a setting of the kind this report describes. It is not a picture of the events reported, and no photograph of them is published here.

Israel’s national cyber authority warned of a rise in targeted phishing attempts arriving through messaging apps including WhatsApp and Telegram, in messages designed to look convincing because they impersonate well-known organisations. The warning, issued in late December 2025, said the attempts are aimed at senior officials and prominent figures in fields including academia, government and the media, and are tailored to each target’s known interests.

The distinction the warning draws is the important one. In ordinary phishing, an attacker sends the same lure to everyone and waits. Here, the notice said, the attacker does not distribute a random message but builds the approach on information gathering and prior planning, the technique the security industry calls spear-phishing.

Who issued the warning

The body behind it, referred to in the original release as the National Cyber Command, is the Israel National Cyber Directorate. It was created in December 2017 by merging the National Cyber Security Authority with the Israeli National Cyber Bureau and sits under the Prime Minister’s Office, with responsibility for civilian cyber defence and for running the national computer emergency response team, CERT-IL, which handles reports from the public and from companies around the clock.

How much of this Israel is seeing

The directorate’s own annual figures give a sense of the volume behind a warning like this one. In a report covered by Israel Defense in March 2026, the directorate said it issued roughly 2,480 alerts during 2025, about two and a half times the 2024 total, and that its 119 reporting centre received around 26,500 incident reports, up 55 per cent year on year. Phishing accounted for 52 per cent of the most common attack vectors. Reporting peaked in June, during Israel’s military operation against Iran, when the centre logged 3,650 reports, 75 per cent above the monthly average. The remaining traffic clustered around supply-chain compromises, unpatched systems, remote-access connections and internet-connected devices sitting on organisational networks.

What a tailored attack actually looks like

Public threat-intelligence work gives a picture of the tradecraft. Google’s Mandiant division, describing the Iranian group it tracks as APT42 and assesses to be working for the Islamic Revolutionary Guard Corps Intelligence Organisation, documented operators who spend weeks in friendly correspondence with a target before sending anything malicious. Their infrastructure included domains a character away from real news outlets (typo-squatted versions of The Washington Post and The Jerusalem Post among them) and cloned Google, Microsoft and Yahoo sign-in pages; where a fake two-factor page failed to capture a token, operators pushed authentication prompts at the victim until one was approved. Nothing in the Israeli directorate’s warning attributes the current wave to any particular actor.

What is still unclear

The warning did not say how many attempts have been detected, over what period, or whether any have succeeded. It named no impersonated organisations and no suspected origin for the campaign, and it did not set out what recipients are advised to do beyond treating unexpected approaches with suspicion.

Topicscyberphishingisraelsecurity

Sources and further reading

Every link below was opened and checked when this page was written. Official statements are marked as such: they are the subject's own account, not an independent one.

  1. ReportingGoogle Cloud / Mandiantcloud.google.com
    Uncharmed: Untangling Iran's APT42 Operations

    Documented spear-phishing tradecraft against Middle Eastern targets

  2. DataIsrael Defenseisraeldefense.co.il
    INCD Report: Israel Faced Record Cyber Threats in 2025 as Alerts Surged

    The directorate's 2025 alert, incident-report and phishing-share figures

  3. ReferenceWikipediaen.wikipedia.org
    Israel National Cyber Directorate

    What the directorate is, when it was formed and where it sits in government

How we checked this

The warning itself is the Israel National Cyber Directorate notice of 28 December 2025 as reported by The Press Service of Israel; no attacker, victim or volume has been added to it. The 2025 phishing and incident-report figures come from the directorate's annual report as covered by Israel Defense, and the description of tailored phishing tradecraft from Google Cloud's published threat research.

The account of the incident itself rests on the official statement and has not been independently confirmed by Israel.com. Where the statement is silent, this page says so rather than filling the gap.

Our sourcing and corrections policy →

The week from Israel, in one email

The stories that mattered, sourced and checked by the Israel.com newsroom. Free, weekly, one-click unsubscribe.

One list, unsubscribe in a click. See our privacy policy.

More in Security

All security

Latest

← All news