Israeli entities are allegedly facing coordinated cyber threats across multiple domains, including a claimed massive data breach of the Israeli Institute for National Security Studies (INSS) and ongoing financial crime operations targeting Israeli credit card holders. The INSS breach claim, allegedly perpetrated by Sumud Cyber Command, represents a significant geopolitical cyber attack with potential intelligence implications, while multiple carding marketplaces are actively selling stolen Israeli credit card data. These developments indicate both state-aligned threat actors and financially-motivated cybercriminals are actively targeting Israeli interests, requiring immediate attention to critical infrastructure security and financial fraud prevention measures.
Israeli law enforcement arrested a 40-year-old cybersecurity specialist from Ashkelon on August 18, 2026, for allegedly deploying WindowsAudit RAT malware against at least 25 Israeli organizations, with potential victims numbering in the dozens or hundreds. The arrest represents a significant insider threat case where a trusted security professional allegedly exploited their position to conduct widespread corporate espionage. Concurrently, threat actor 'Fidel' is allegedly selling 150 full CVV records with complete PII from Israeli cardholders, sourced via network sniffing between July and early August 2026. These incidents highlight critical vulnerabilities in Israeli organizations' security posture, particularly regarding insider threats and payment card data protection. The WindowsAudit campaign's operational security failure—unencrypted Discord tokens—enabled threat intelligence researchers to map the attacker's infrastructure, demonstrating how even sophisticated attacks can be undermined by basic security oversights. Organizations must prioritize insider threat detection, network segmentation, and payment card data security controls.
Between August 28-31, 2026, multiple threat actors allegedly advertised the sale of compromised databases containing extensive personally identifiable information (PII) and financial data affecting Israeli citizens and residents, alongside victims from 40+ other countries. The most significant alleged breach involves a Tier 1 database with 600,000 complete identity records including full credit card details, with Israel specifically mentioned as having 10,000+ compromised records. Additionally, multiple underground marketplaces allegedly offered stolen credit card data (CC+CVV2) with Israeli cards included in their geographic coverage. These alleged incidents represent a coordinated criminal ecosystem facilitating identity theft, financial fraud, and unauthorized transactions targeting Israeli financial institutions and consumers. The timing and scale of these alleged offerings suggest an active and sophisticated threat landscape requiring immediate defensive measures.
Between August 26-30, 2026, multiple threat actors allegedly conducted cyber operations with Israeli nexus across three distinct activity clusters: (1) A Turkish nationalist hacktivist group claimed mass website defacement of 1,952 sites and DDoS attacks against Israeli government infrastructure including space.gov.il as part of a commemorative operation; (2) A carding operation advertised stolen payment card data explicitly targeting Israeli financial institutions among 60+ countries; (3) A proxy service provider offered anonymization infrastructure with Israeli endpoints that could facilitate malicious activities. These incidents represent a convergence of geopolitical hacktivism, financial cybercrime, and enabling infrastructure that collectively elevate risk to Israeli organizations across government, financial, and educational sectors. The timing coinciding with Turkish national commemoration suggests coordinated or opportunistic exploitation of geopolitical tensions.
Threat actors are allegedly conducting an active stolen credit card sales operation specifically targeting customers of Hapoalim, a major Israeli banking institution. The operation involves bulk stolen credit card data from multiple countries with pre-validated cards that allegedly bypass OTP verification and can be used with digital payment platforms including Apple Pay, Google Pay, and Cash App. This represents a significant financial crime threat to Israeli banking customers and international cardholders, with actors claiming validity rates and offering replacement guarantees to buyers. The timing and scope of this operation, combined with the specific targeting of an Israeli financial institution, makes this intelligence actionable for financial fraud prevention teams and customers of the affected bank.
On August 26, 2026, a threat actor allegedly offered for sale a comprehensive collection of compromised military data from over 14 countries, including Israel, for $10,000 USD. The Israeli Defense Forces (IDF) is explicitly listed among the targeted military organizations. This alleged breach represents a significant threat to Israeli national security, as the claimed dataset purportedly includes sensitive military intelligence covering personnel records, weapons systems, command and control infrastructure, cyber operations data, and defense infrastructure details. The timing and scope of this alleged compromise, affecting multiple nations simultaneously, suggests either a sophisticated coordinated operation or access to shared military intelligence systems. Israeli defense organizations should immediately assess potential exposure and implement enhanced security measures, as the actor claims to offer sample data and maintains active communication channels for potential buyers.
On August 26, 2026, threat actor MrDarkRoot allegedly advertised a large-scale sale of compromised military data from 14+ countries, including sensitive Israeli Defense Forces intelligence, for $10,000 USD. Concurrently, the Authorize marketplace was allegedly selling stolen credit card data (CC+CVV2) from multiple countries including Israel, sourced via sniffer tools. These incidents represent significant threats to Israeli national security and financial infrastructure. The military data breach allegedly includes personnel records, weapons systems, cyber operations data, and defense infrastructure details. The financial data compromise allegedly affects Israeli payment cardholders through fraudulent transaction risks. Both incidents demonstrate sophisticated threat actor capabilities in data exfiltration and monetization through underground marketplaces. Organizations should immediately assess exposure, implement enhanced monitoring, and coordinate with relevant authorities.
מה שונה בין משבר סייבר בתעשייה למשברי סייבר בגופים אחרים?
משבר סייבר בתעשייה מכיל סיכונים רבים המתווספים על האיומים הרגילים של זליגת מידע, אובדן הכנסות, פגיעה במוניטין וגניבה בסקטורים אחרים. בתעשייה ובמיוחד בזאת שיש בה חומרים מסוכנים, התרחישים מאוד מפחידים: אירועים סביבתיים, פליטה של חומרים מסוכנים, פעילות כימיות ופיזיולוגיות לא רצויות, תקלות במכשור כבד ורובוטיקה. כל אלה יכולים להוות סכנה ממשית לחיי אדם בתוך ומחוץ למפעל. סודות מקצועיים ופטנטים מאוד חשובים אך לא כחיי אדם שהם הסיכון הגבוה ביותר.
מעבר למחשוב הרגיל שנמצא בסקטורים אחרים, בתעשייה יש מערכות נוספות של בקרים, מכונות, פרוטוקולים. במשבר סייבר תוקפים ינסו לפגוע בתפעול עצמו. לכן משבר סייבר בסביבת תעשייתית משמעותה כסף ובריאות.
יש לזכור המערכות התעשייתיות לפעמים מיושנות ולא נבנו עם תשומת לב לאבטחת מידע ולסכנות סייבר חדשות. בשנים האחרונות המערכות עברו דיגיטציה ונפתחו ערוצי תקשורת אשר מכילים פגיעויות בין הממשקים הממוחשבים בענף למכשור הייעודי לכל מפעל.
מהם וקטורי התקיפה האפשריים ומיהם גורמי התקיפה?
מהשביעי באוקטובר אנו רואים עלייה משמעותית בניסיונות תקיפה נגד המשק הישראלי. לא חסרים לנו אויבים ויש רבים שמצטרפים ל”טרנד” של תקיפה נגד תשתיות ישראליות. ישנה טביעת אצבע של גופים איראניים בסיוע של טכנולוגיות רוסיות.
הווקטורים העיקרים לתקיפה מהווים ניסיונות חדירה מרשת המחשוב לרשת התפעולית. ניסיונות חדירה לרשת הפרטית הווירטואלית, פישינג והנדסה חברתית. לאור ריבוי ניסיונות תקיפה אלו חשובה מאוד המודעות בקרב העובדים. לרוב לעובדי התעשייה אין זיקה ממשית לתחום הסייבר לכן לארגונים יש צורך ממשי לעורר תרבות מודעת סייבר ולרתום את ההנהלה והעובדים לתהליך וכמו כן לבקר את התהלכים בהם משולבים העובדים.
בנוסף ישנה ייתכנות לתקיפות מערכות מבודדות כפי שחווינו בתקיפת הכור האיראני ובניסיון תקיפה על מערכות המים הישראל.
מהם הדגשים החשובים בהערכות למשבר סייבר בתעשייה?
תרחיש של משבר סייבר הוא עניין של זמן. חברות צריכות לצאת מהקונספט של “לי זה לא יקרה”. זאת לא שאלה של אם אלא מתי. בהתאם לכך חברות צריכות להתכונן מבעוד מועד לתרחישים אפשריים עקב משבר סייבר.
הארגונים צריכים לבחון תרחשים אפשריים שיקרו והבנה של ההשלכות התפעוליות שינבעו מתרחישים אלו ולהכין תכנית המשכיות עסקית מתאימה. כלומר, מה עושים בכל אירוע, איך מתמודדים, מהן החלופות ומהם דרכי החזרה לשגרה.
הכנה מראש תצמצם משמעותית את הנזק והבלגן שגורר אירוע. משבר סייבר הוא אירוע שמשלב חוסר ודאות ומעורר כאוס מוחלט, החלטות שבאות מלחץ ופאניקה לבטח יכשילו את ניהול האירוע. הכנה מראש של תוכנית ופרוטוקולים יכוונו את הארגונים להתנהלות הגיונית וברורה. הכנה משמעותה מזעור הנזקים, צמצום זמן ההתאוששות ומניעה בפגיעה במוניטין וחיי אדם.
בצד הטכנולוגי מומלץ להפריד את רשתות המחשוב מרשתות התפעול, לבצע סגמנטציה של רשתות ולהטמיע כלי ניטור ובקרה.
מהם הדגשים החשובים לניהול משבר סייבר בפועל? מהן הטעויות הנפוצות?
הדבר הגרוע ביותר לעשות הוא לחשוב שנגיע לגשר נתמודד איך לחצות אותו. כאמור משבר סייבר הוא תרחיש ריאלי במיוחד בתקופה בה אנחנו נמצאים. המחשבה שתמצאו חברה שתבוא להציל אתכם ממשבר ללא הכרות מוקדמת היא מוטעית מהיסוד.
ברגע משבר יש להתכנס במהרה ולפתוח חמ”ל שמתקשר בין המחלקות הטכנולוגיות והתפעוליות ולהתבסס על תוכנית המשכיות עסקית שהוכנה מבעוד מועד. יש לחבור לחברות לניהול משבר טרם פרוץ המשבר שיוכלו ללמוד את החברה ולהכין יחד עם הארגון את פרוטוקולי החירום הרלבנטיים.
המפתח הטוב ביותר להתמודדות עם המשבר הוא להתכונן אליו. תרגול תמידי של ההנהלה, הצוותים הטכנולוגיים, התפעולים וכלל העובדים יכשיר את החברה להתמודדות טובה יותר ברגע האמת.
מה הכי חשוב לזכור?
משבר סייבר הוא מציאות ראלית לכל ארגון תעשייתי, השאלה היא מתי ולא אם.
משבר סייבר בתעשייה מכיל איומים הקשורים בחיי אדם ולכן חובה להתייחס אליו בכובד ראש.
יש להשקיע במניעה, מודעות והכנה מראש.
הכנה מוקדמת יכולה לעזור להתמודד עם משבר בצורה הכי יעילה.
יש לבנות תהליכים מקדימים שאליהם נצמדים ברגעי אירוע.
חברה חיצונית לניהול משברים הכרחית.
Share