Shin Bet says Iranian operatives are posing as colleagues to reach Israeli reporters' phones
Israel’s security service and its national cyber directorate issued a joint warning on Sunday. It is an official statement, not a documented incident, and an automated risk-scoring site has already added details Haaretz never reported.
Israel’s Shin Bet security service and the Israel National Cyber Directorate issued a joint public statement on Sunday 16 August, saying Iranian intelligence operatives are approaching Israeli journalists on WhatsApp and Telegram while impersonating people the targets already know, offering interviews or proposing collaboration on projects. The stated objective is to compromise devices, take over accounts and obtain sensitive information. Haaretz reported the statement at 14:29 IDT the same day under its national security desk byline. What the retrievable material does not contain is any of the detail that would let an outside party test it: no count of targeted journalists, no named individual, no named threat cluster, no indicators of compromise, and no direct quotation from a named official at either body. The Files did not reach the primary Hebrew-language INCD notice.
A second “source” for the same story is circulating and should not be treated as one. A post on blog.rankiteo.com restates the Haaretz lede, then adds that the campaign “specifically targeted reporters from Haaretz, among others,” assigns a machine-generated “severity: 85” score, and characterises the episode as an “attack with significant impact with customers data leaks.” Neither the Haaretz-targeting detail nor the data-leak characterisation appears in the Haaretz text. The page carries visible raw Python dictionary fragments, the signature of an automated third-party-risk product rather than reporting. For scale, and with the caveat that these are the defending agency’s own intake numbers with no published methodology: INCD director general Brig. Gen. (res.) Yossi Karadi told Die Welt in late June that Israel logged roughly 1,600 hostile cyber incidents in June 2025 and about 4,800 in June 2026, and that the directorate handled more than 26,000 in 2025, a 55 percent rise on 2024.
Assessment: Two things are worth separating. The first is the announcement’s timing: states publish spearphishing warnings when they want a target community to change behaviour, or when an operation is already running and they have decided disclosure costs the adversary more than silence. Nothing released so far tells us which. The second is more durable. Machine-written risk-scoring pages now sit high enough in search results to function as corroboration for stories they have only paraphrased, inventing specificity — a named victim, a “data leak,” a severity number — that the original never claimed. Within a day that invented specificity becomes the version people cite. Treat Karadi’s counts the same way: an agency measuring its own inbox.