What is OpIsrael? An Annual Cyber Campaign Targeting Israeli Objectives
OpIsrael is a coordinated effort by hacker groups (hacktivists and others) from around the world, directed annually at Israeli targets in cyberspace. Their goal is to disrupt services, cause reputational and economic damage, and steal information. Attacks within this framework can take various forms, including:
- Distributed Denial of Service (DDoS): Attempts to crash websites and online services by flooding them with traffic.
- Website Defacement: Hacking into websites and changing their content to display political or offensive messages.
- Database Breaches: Attempts to steal sensitive information, business data, or personal details.
- Phishing Attacks: Sending deceptive emails or SMS messages aimed at stealing passwords and account details.
- Malware Distribution: Including Ransomware that encrypts files and demands payment for their release.
- Exploiting Vulnerabilities: Scanning for and exploiting known loopholes in unpatched systems and software.
The Importance of Vigilance and Information Dissemination
Effective defense requires cooperation and increased vigilance from every one of you. We ask managers and all team leaders to ensure these instructions are distributed to and understood by all employees across the organization.
Key Guidelines for All Employees for the Coming Days:
Be Suspicious of Unexpected Email and SMS Messages (Phishing)
* Carefully check the sender’s address: Does it make sense? Are there spelling errors?
* Do not click on suspicious links and do not open attachments from messages whose source or reliability you are unsure of. Hover your mouse over the link (without clicking) to see the actual destination address.
* Never provide passwords or personal details in response to a request via email, SMS, or phone call, even if it appears legitimate or urgent. Official entities will never ask you for your password.
* If you receive a suspicious email: Report it immediately to the IT department/Information Security team/Helpdesk.
Beware of Unsolicited Multi-Factor Authentication (MFA/2FA) Requests:
* If you receive a notification (on your mobile or via an app) asking to approve a login to any account (corporate or private) that you did not initiate at that moment – do not approve the request! This means someone else has obtained your password and is attempting to breach your account.
* Report this immediately to the relevant party in your company and change the password for that account as soon as possible.
Software Updates:
* On company computers: Operating systems and core software are updated by the IT team. Ensure your computer is connected to the network and receiving updates as required.
* On personal devices (phones, tablets, home computers): Ensure you regularly update the operating system, browser, and applications. These updates frequently close security vulnerabilities.
Downloading Applications:
Install software and applications only from official and trusted sources, such as the recognized Google and Apple app stores or original manufacturer websites. Avoid downloads from unknown sites.
Backups:
While the company backs up organizational data, it is recommended to ensure your important personal information (on private computers and mobile devices) is also backed up regularly in case of a malfunction or ransomware attack.
—
Additional Guidelines for IT and Security Teams:
In addition to the general instructions for employees, we recommend that IT and security teams take the following actions or verify their implementation during this period:
Protection of Backup Systems:
* Verify that organizational backup processes are running correctly and that backups are functional (via periodic restoration tests).
* Ensure backups are stored securely, preferably with at least one copy disconnected from the network (Offline/Air-gapped) or using Immutable Storage technology, if available.
* Ensure access to the backup systems themselves is restricted and closely monitored.
Geo-blocking:
* Evaluate and consider blocking access to organizational systems (especially management interfaces and sensitive services) from countries where there is no legitimate business need for access, or from countries known to be sources of malicious activity.
* Review and harden Firewall rules accordingly.
Increased Vigilance and Communication with the SOC:
* Heighten the level of alertness and monitoring across security systems (SIEM, EDR, IDS/IPS, etc.).
* Ensure the SOC team (internal or external) is aware of the sensitive period and prepared to respond quickly to anomalous events.
* Maintain effective communication and coordination channels between IT, Security, and SOC teams for rapid reporting and incident handling.
Your vigilance and cooperation are essential to maintaining the information security of us all. If you encounter any suspicious activity, please report it immediately to the relevant entity in your organization.
**