Shin Bet and Israel’s cyber directorate warn Iranian operatives are phishing journalists on WhatsApp
A joint advisory issued Sunday describes impersonation of known reporters and fake video-call links, with no named actor, no target count and no malware — the capability described is social engineering, not intrusion.
On Sunday 16 August, Israel’s Shin Bet security service and the Israel National Cyber Directorate issued a joint statement saying they had identified a new wave of attempts by Iranian intelligence operatives to compromise Israeli journalists and media professionals. The tradecraft described is narrow and consistent: first contact over WhatsApp or Telegram rather than email; operatives impersonating known figures, in some cases other well-known journalists; messages tailored to the target’s specific beat, offering collaboration, an interview or a private conversation. The payload step is a link presented as meeting-scheduling or a video-call join, built to harvest credentials. The stated objectives are device compromise, account takeover and extraction of sensitive information. The agencies said journalists are not the sole target group, and that parallel attempts have reached people in political, public, governmental and security roles.
The INCD’s published mitigations indicate what the agencies think is failing: verify identity through a second channel; never enter a password or an authentication code after following a link, explicitly including links to join a video call; enable two-factor authentication through an authenticator app, with Google and WhatsApp named; report attempts to the directorate’s 119 hotline. What the statement does not contain matters as much. It attributes the wave to “Iranian intelligence operatives” without naming a service, a unit or a tracked actor, and assigns no APT designation. It gives no count of targets, no count of successful compromises and no campaign start date. Reporting in Haaretz, JFeed and The Yeshiva World is paraphrase of an unsigned institutional statement; no named Shin Bet or INCD official is quoted in any version located.
Assessment: A defensive advisory that names a target profession is itself an act of information policy. This one hardens journalists, and it simultaneously characterises Iranian capability as dependent on social engineering over consumer messengers rather than on zero-days, implants or a commercial spyware vendor. That characterisation may be accurate; it is also flattering to the defender. Note too that both agencies tied the tempo to “recent political and security developments in the region” without saying which — a link asserted rather than shown. Two things to watch and to distrust: any actor name that appears in the next 48 hours without evidence attached, and the claim circulating on machine-generated aggregators that Haaretz reporters specifically were targeted, which does not appear in the direct summaries.