A French Company, Only Popular in Israel: A Localized Phishing Campaign
- Home
- Threat Intelligence
- Localized Attacks
By Guy Ushomirsky, Factor Security Research · 22 Apr 2026
Most phishing campaigns cast a wide net. This one was narrow by design, and the narrowness itself was the giveaway. Factor's research team identified a phishing site impersonating a French company, built specifically to target French-speaking users in Israel — a combination unusual enough to warrant closer inspection.
-
A Real Company, Borrowed for the Occasion
The campaign centers on VD2E, a genuine French company specializing in green energy solutions (official site: vd2e.fr). The real site is minimal — company information and a way to schedule meetings, with no login and no field for personal data. That simplicity made it an easy shell for attackers to imitate convincingly: there was very little legitimate functionality to fake.
-
The Imposter Domain
The fake site was hosted at vdee.fr — a single-character swap from the real vd2e.fr, close enough to pass a quick glance at the address bar. Unlike the genuine site, the fake page had one purpose: collect a national ID number, presented in French text but asking specifically for a "Teudat Zehut" — the Hebrew term for an Israeli ID card. There was no other content on the page, just the form. The site also ran over unencrypted HTTP rather than HTTPS, a detail that would be unusual for any legitimate business handling personal data.
-
Traffic That Didn't Match the Brand
Traffic analysis using SimilarWeb showed that despite VD2E being a French company, the domain's traffic was concentrated almost entirely in Israel — a strong signal that the site had nothing to do with VD2E's actual business and everything to do with a targeted audience thousands of kilometers from the company it claimed to represent.
The traffic pattern over time reinforced the conclusion: two sharp spikes followed by a return to near-zero activity, consistent with a short-lived campaign launch followed by a shutdown or takedown, rather than the steady traffic of a real operating business.
-
Response and Takeaway
Once identified, the domain was flagged and blocked for protected users, and the case was referred to Israel's national CERT for further investigation. The campaign is a reminder that localization does not require a large-scale operation — a single-page form and a one-character domain swap were enough to build a plausible-looking trap for a specific population. Verifying the exact domain before entering any personal or national identification information remains one of the most reliable defenses against this pattern.

