Shin Bet and Israel National Cyber Directorate Warn of Iranian Phishing Attacks Targeting Journalists

Israel's internal security service, the Shin Bet, and the National Cyber Directorate announced on Sunday that they have identified a new wave of phishing attempts by Iranian intelligence operatives targeting journalists and media professionals in Israel. According to the statement, the goal of these attacks is to obtain information amidst recent political and security developments. The messages are primarily sent via WhatsApp or Telegram, often impersonating known figures or other journalists. In this method, attackers lure victims into clicking malicious links by offering interviews or collaboration opportunities. These links may lead to fraudulent pages designed to steal Google account credentials or contain malicious files that could grant attackers access to mobile devices, correspondence, and work documents. Israeli security officials noted that these efforts also target individuals in political, public, governmental, and security sectors. The National Cyber Directorate recommends verifying the identity of senders through alternative communication channels, especially when receiving unexpected messages containing links, files, or requests for personal information. Other security recommendations include enabling two-factor authentication on major accounts and periodically reviewing account connections to remove unrecognized devices.

