Abnormal Security is tracking cybercriminals from an unusual location for business email compromises who are using sophisticated spoofing to spur payments for fake acquisitions.

A threat group based in Israel is behind attacks in recent weeks, according to a report from email security firm Abnormal Security. The concern’s new threat report tracked some 350 business email compromise exploits dating back to February 2021 perpetrated by the group.
While this is not the first time there has been an attack out of Israel, it is highly unusual. According to Abnormal, 74% of all attacks the firm analyzed over the past year were from Nigeria.
Mike Britton, the chief information security officer at Abnormal, said that while it is not unexpected that sophisticated threat actors would emerge from a skilled, innovative technology ecosystem, Asia, Israel — in fact the Middle East, generally — are bases for BEC attackers.
“Comparatively, countries in Asian and Middle Eastern are at the bottom of the list, with only 1.2% and 0.5% of BEC actors, respectively,” he said, adding a caveat: “Unfortunately, our research cannot definitively say the threat actors are Israeli — just that we have confidence they are operating out of Israel (Figure A).”
Figure A

Israel has typically been a target most recently of a series of DDoS attacks timed with the annual OpIsrael coordinated cyber attack campaign.
The study reported that, after Africa, the U.K. is the (distant) second-most prominent source of BEC attacks, accounting for 5.8% of attacks, followed by South Africa, the U.S., Turkey and Canada.
Britton said the sophistication of the attackers’ methods shows how cybercriminals, once relying on generic phishing campaigns, have had to adapt to organizations’ evolving defensive postures and employee training.
“Instead of generic phishing emails, we’re seeing the rise of highly sophisticated, socially engineered BEC attacks that can evade detection at many organizations,” he said.
According to the Abnormal study, the Israel-based attackers’ methods include:
Abnormal said the framework of the attacks involves internal and external message vectors — real people, spoofed, within and outside of the target organization — with the former frequently being the targeted company’s CEO (Figure B).
Figure B

“In some campaigns, once the attack has reached this second stage, the group asks to transition the conversation from email to a voice call via WhatsApp, both to expedite the attack and to minimize the trail of evidence,” said the firm.
The study said:
Britton said that, although the attackers are in Israel, the motivation is the same as with non-state actors: quick money. “What is interesting is that these attackers are based in Israel, which is not a country historically connected to cybercrime, and which has traditionally been a location where cybersecurity innovation is prevalent,” he said.
He said the firm has watched BEC attacks increase in severity with the amount of money requested being significantly higher than Abnormal has since in the past.
“Email has always been (and will continue to be) a lucrative attack vector for cybercriminals. Because of this, we will likely see threat actors continue to evolve their tactics, test new approaches, and become even more targeted and sophisticated in their attempts to compromise email users,” he said, adding that Slack, Zoom and Microsoft Teams are becoming more important as threat surfaces as attackers seek new entry points.
Beyond training potential human targets to know the signs of BEC exploits, Abnormal advocates automated defense that snags BECs before they reach a target by using behavioral AI to create a baseline for normative email traffic and can therefore ping anomalies early.
“To account for emerging threats across collaboration apps, consolidating visibility across all communications tools will significantly improve security teams’ ability to detect suspicious and malicious activity — no matter where attacks originate,” said Britton.
Karl is a lead writer on cloud security for TechRepublic, specializing in enterprise security risks, strategies, products, threats, trends and technologies for securing organizations. After graduating from Florida State University, he worked for the Tampa Tribune, and radio and TV stations in Tallahassee before moving to Boulder, Colorado. After receiving an MFA in dramatic writing from Brooklyn College he became a journalist and wrote for several years for publications covering the automotive, industrial chemical, internet tech and consumer marketing verticals. He has written for Adweek, Brandweek, The Chemical Market Reporter and MediaPost, and was also the public affairs officer at the NYU Tandon School of Engineering for six years prior to coming to TA.