Skip to main content
isrl.com

The Fake Investor, the Broken Zoom Link and an Israeli Startup

Israel's National Cyber Directorate said attackers built a credible investor profile, then used a bogus video-call link to plant malware on a company's computers.

The Israel.com Newsroom··3 min read·
Share
Illustration of a laptop with a dark, dead screen and glowing red webcam light on a desk in a dusk-lit startup office.

Illustration

Illustration, generated by an image model, not a photograph: a laptop with a dark, dead screen and glowing red webcam light on a desk in a dusk-lit startup office. It shows a setting of the kind this report describes. It is not a picture of the events reported, and no photograph of them is published here.

A large Israeli startup reported what Israel’s National Cyber Directorate called a “particularly sophisticated” cyberattack: an elaborate impersonation of a business meeting with an investor that ended with a malicious file being downloaded during a video call, computers taken over and sensitive information exposed. The account was issued through the Press Service of Israel on 3 August 2025.

According to the Directorate, the approach began with a flattering message from a supposed investor on a social network. The profile looked credible: a professional photograph, an investment history, an impressive business background. The correspondence moved quickly to arranging an online meeting, but instead of a legitimate video-call link the employees received one that looked like a Zoom link and instead downloaded a malicious file when clicked. When the call would not work, the attackers sent a second link and persuaded the staff to install software that would supposedly fix the Zoom problem, planting further malware on the company’s computers and on a mobile phone. No personal customer information was stolen, the Directorate said, but sensitive financial information was exposed.

This is a recognised attack pattern, and it has a shape

The sequence described (plausible investor, calendar invitation, spoofed meeting page, fake audio problem, “fix” that is really malware) matches a technique documented in detail by security researchers. The Hacker News reported in June 2025 on a campaign in which an attacker posing as an external contact sent a scheduling link that redirected to a fake Zoom domain; when the victim reported audio trouble during the call, they were sent a script disguised as an audio repair tool that quietly fetched a further payload while opening a genuine Zoom developer page as cover.

The pattern has since been mapped more fully. Google Cloud’s threat intelligence team published an analysis in February 2026 of a group it tracks as UNC1069, describing exactly this chain: contact through a compromised or fabricated account, a scheduling link to a spoofed meeting domain, an artificial-intelligence-generated video of a company executive to make the call convincing, a manufactured audio fault, and then “troubleshooting” commands that install the malware. The targets it listed were financial services and cryptocurrency businesses (payments, brokerage, staking and wallet infrastructure), along with software firms and their developers and venture capital firms and their staff.

Why the investor cover story works so well

The lure is well matched to its victims. An early-stage company expects unsolicited approaches from investors, expects to be flattered, and expects to move fast, which is why the Directorate’s warning stressed preparation rather than opportunism: attackers are upgrading their fraud methods with targeted phishing that includes prior research on the target, profiles built to look trustworthy, and fake domains registered months in advance.

What the National Cyber Directorate is

The Directorate is the Israeli government body responsible for defending civilian cyberspace, and it runs a reporting line, 119, for cyber incidents: the Times of Israel reported in October 2020 that some 10,000 Israeli citizens and organisations had called it over the preceding year to report hacked social media accounts, home routers, cameras and private email. The volume it handles has grown sharply since. Israel Defense reported in March 2026 that the Directorate issued roughly 2,480 alerts during 2025, two and a half times its 2024 figure, and that its emergency centre received about 26,500 incident reports, up 55 per cent year on year. Phishing accounted for 52 per cent of those incidents, ahead of influence operations at 13 per cent, account breaches at 11 per cent and system intrusions at 9 per cent.

What the report did not say

The Directorate did not name the company, the social network the approach came through, or the date of the attack. It gave no attribution to any group or country, did not say how many machines were compromised or how long the attackers had access, and did not say what became of the financial information that was exposed. It also did not say how the intrusion was eventually detected.

Topicscybersecuritystartupsphishingtechnology

Sources and further reading

Every link below was opened and checked when this page was written. Official statements are marked as such: they are the subject's own account, not an independent one.

  1. ReportingThe Hacker Newsthehackernews.com
    BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with macOS Backdoor Malware

    Technical account of the fake-Zoom-link and audio-fix technique

  2. ReportingIsrael Defenseisraeldefense.co.il
    INCD Report: Israel Faced Record Cyber Threats in 2025 as Alerts Surged

    National Cyber Directorate alert and incident volumes for 2025

  3. ReportingThe Times of Israeltimesofisrael.com
    10,000 Israelis have used 119 cyberhotline to report hacks

    What the Directorate's 119 reporting line is and who can use it

  4. ReferenceGoogle Cloud Threat Intelligencecloud.google.com
    UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

    Mapping of the fake-investor social engineering chain and its targets

How we checked this

The account of the attack and the Directorate's warning come from the Israel National Cyber Directorate report of 3 August 2025 as distributed by the Press Service of Israel; the company is unnamed and Israel.com has not verified the incident independently. The matching attack technique is documented by The Hacker News (June 2025) and Google Cloud's threat intelligence team (February 2026), and the Directorate's 2025 caseload figures come from Israel Defense.

Our sourcing and corrections policy →

The week from Israel, in one email

The stories that mattered, sourced and checked by the Israel.com newsroom. Free, weekly, one-click unsubscribe.

One list, unsubscribe in a click. See our privacy policy.

More in Security

All security

Latest

← All news