Scroll to top
Threat Intelligence Factor's research team tracks real-world phishing, impersonation and social-engineering campaigns as they happen. See All Reports →

A French Company, Only Popular in Israel: A Localized Phishing Campaign

By Guy Ushomirsky, Factor Security Research · 22 Apr 2026

Most phishing campaigns cast a wide net. This one was narrow by design, and the narrowness itself was the giveaway. Factor's research team identified a phishing site impersonating a French company, built specifically to target French-speaking users in Israel — a combination unusual enough to warrant closer inspection.

  1. A Real Company, Borrowed for the Occasion

    The campaign centers on VD2E, a genuine French company specializing in green energy solutions (official site: vd2e.fr). The real site is minimal — company information and a way to schedule meetings, with no login and no field for personal data. That simplicity made it an easy shell for attackers to imitate convincingly: there was very little legitimate functionality to fake.

  2. The Imposter Domain

    The fake site was hosted at vdee.fr — a single-character swap from the real vd2e.fr, close enough to pass a quick glance at the address bar. Unlike the genuine site, the fake page had one purpose: collect a national ID number, presented in French text but asking specifically for a "Teudat Zehut" — the Hebrew term for an Israeli ID card. There was no other content on the page, just the form. The site also ran over unencrypted HTTP rather than HTTPS, a detail that would be unusual for any legitimate business handling personal data.

  3. Traffic That Didn't Match the Brand

    Traffic analysis using SimilarWeb showed that despite VD2E being a French company, the domain's traffic was concentrated almost entirely in Israel — a strong signal that the site had nothing to do with VD2E's actual business and everything to do with a targeted audience thousands of kilometers from the company it claimed to represent.

    The traffic pattern over time reinforced the conclusion: two sharp spikes followed by a return to near-zero activity, consistent with a short-lived campaign launch followed by a shutdown or takedown, rather than the steady traffic of a real operating business.

  4. Response and Takeaway

    Once identified, the domain was flagged and blocked for protected users, and the case was referred to Israel's national CERT for further investigation. The campaign is a reminder that localization does not require a large-scale operation — a single-page form and a one-character domain swap were enough to build a plausible-looking trap for a specific population. Verifying the exact domain before entering any personal or national identification information remains one of the most reliable defenses against this pattern.

Localized phishing campaign concept