Israel News
Israel’s Security Agency Warns: Iran Targeting Israeli Journalists’ Phones
The Shin Bet and National Cyber Directorate are warning of a new wave of Iranian phishing attempts targeting journalists and media professionals in Israel. Attackers pose as journalists in an effort to access sources, correspondence, work materials, and sensitive information.
(Photo: Nati Shohat, Flash90)The Shin Bet security agency and the National Cyber Directorate warned today (Sunday) of another wave of targeted phishing attempts by Iranian intelligence operatives, recently aimed at journalists and media professionals in Israel. According to a joint statement released by the agencies, the attempts are intended to obtain information in light of the latest political and security developments. The Shin Bet and the Cyber Directorate identified the activity and are working to prevent and thwart these attempts.
The method is based on making direct contact with journalists, mainly through WhatsApp or Telegram, while impersonating familiar figures and sometimes even other well-known Israeli reporters. The outreach is personally tailored to the target’s areas of work and interest and may include an offer to collaborate, an invitation to an interview, or a request to speak.
After establishing contact that appears credible, the attackers try to get the journalist to click a link presented as a meeting invitation. The link may lead to a spoofed page requesting Google account login details. In other cases, they try to lead the target to open malicious links or files that could allow their mobile phone to be taken over.
According to the Shin Bet and National Cyber Directorate’s assessment, Iranian intelligence operatives are using this method to obtain sensitive information related to security and political developments. Among other things, they are attempting to gain access to journalistic sources, correspondence, work materials, and additional information that could serve terrorist activity, espionage, intelligence gathering, and influence operations.
The threat, the agencies stressed, is not limited to the media world. Similar efforts are also aimed at targets in other fields, making heightened vigilance necessary for those involved in political, public, government, and security-related work.
In response to this wave of attempts, the National Cyber Directorate issued a series of recommendations for protecting accounts. First and foremost, it recommends verifying the identity of anyone who contacts you unexpectedly through another communication channel, especially if the message includes a link, file, or request for personal details.
It also emphasized that passwords or verification codes should never be entered through a link sent in a message - even when it is claimed that this is necessary to join a video call. In addition, users are advised to enable two-step verification on their primary accounts through an authenticator app, with particular emphasis on Google and WhatsApp, and to set up a recovery email address.
The Directorate also recommends regularly reviewing account logins and removing unfamiliar devices or connections. In the event of a suspicious attempt, it should be reported immediately to the organization’s security personnel and to the National Cyber Directorate’s 119 hotline.

