Iranian Intelligence Targets Israeli Journalists via Phishing

Iranian intelligence phishing campaign targeting Israeli journalists

Iranian intelligence agencies have intensified their efforts to compromise Israeli journalists. Threat actors aggressively target media personnel through WhatsApp and Telegram. Specifically, they impersonate familiar individuals to build trust. Afterwards, they offer interviews, collaborative projects, or exclusive materials.

A New Wave of Deception

The Israel Security Agency, known as Shin Bet, reported this alarming trend. The National Cyber Directorate also confirmed this new wave of phishing messages. Interestingly, Haaretz journalists recently encountered these sophisticated cyber attacks. According to the publication, attackers offered staff members compelling video recordings. These fabricated videos supposedly depicted events in the Persian Gulf and the Strait of Hormuz.

Malicious Links and Files

Consequently, the messages contained links that closely resembled legitimate Google Drive addresses. Upon clicking, the victim landed on a different website explicitly designed to steal credentials. In other instances, the attackers sent fake invitations to online meetings. These deceptive links opened a fraudulent Google login page. Furthermore, Israeli authorities discovered that the attackers distribute malicious files. If a victim executed such a file, the attackers could easily seize control of their mobile device.

Meticulously Tailored Cyber Attacks

The operatives meticulously tailor these malicious messages to the specific work of each journalist. Senders expertly disguise themselves as trusted acquaintances. Moreover, they offer materials on highly relevant political and military events. This personalized approach significantly increases the likelihood of success. Therefore, the recipient is much more likely to open the dangerous link or file.

Strategic Espionage Goals

Shin Bet and the National Cyber Directorate understand the primary objectives behind these attacks. Iranian intelligence clearly seeks to gather sensitive political and military intelligence. They also aim to access confidential journalistic sources, private correspondence, and work materials. Ultimately, they can use this acquired data for complex espionage and information operations. Additionally, this intelligence helps them identify potential recruitment targets within the media.

Historical Context of the Threat

The frequency of such malicious campaigns has surged dramatically since October 7, 2023. Previously, in June 2025, Israel uncovered another massive phishing campaign. This extensive operation targeted dozens of prominent journalists and public figures. Back then, the attackers impersonated former prime ministerial adviser Caroline Glick. They also posed as former Israeli ambassador to the US, Michael Oren.

The Handala Group Connection

Authorities also firmly link the Handala threat group to these ongoing attacks against Israel. In March 2026, the US Department of Justice officially indicted the Iranian Ministry of Intelligence and Security. American officials explicitly accused the ministry of managing the Handala group. They assert that the group concealed its true state affiliation. Instead, they posed as an independent hacktivist movement to publish stolen data during influence operations.

Essential Cybersecurity Recommendations

Consequently, the National Cyber Directorate strongly advises verifying the identity of any unexpected sender. Professionals must use an alternative communication channel for verification. This step is crucial if the initial message contains a link or file. Furthermore, users must never enter passwords or verification codes on unverified web pages.

Finally, the security agency recommends enabling two-factor authentication immediately. This protection is vital for Google, WhatsApp, and other critical accounts. Users should also configure a secure backup email address. Regularly reviewing the list of connected devices ensures long-term account security.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply