ShadowGraph Intelligence · 3 August 2026

The Fake Academics: A Likely Iran-Aligned Network Impersonating Real Israeli Scholars to Buy Meetings With Their Peers

Anatomy of a likely Iran-aligned impersonation network.

Masked persona portraits over the faces of five real named people, wired to a single hidden operator.

Someone stole the faces of five real Israeli scholars and public figures, their names and their photographs, and wore them to reach Israel's ministers, diplomats and journalists in their own inboxes. The pitch: $1,000 for a private Zoom about Israel. The catch: hand over your email, then “log in” to a page only dressed up as Zoom. These accounts sat dormant for more than a decade, then woke in 2026 to run one script from six countries, none of them Israel. Everything under the hood, the Persian keyboard behind the personas, the tradecraft, and selectors matching operations I have tracked before, points one way: likely Iran-aligned. They were still posting the day I wrote this. Here is the whole operation, tiered finding by finding. I say likely, not certain, and I name no state.

§ 01 · Executive Summary

A network of fake academics, buying its way into real rooms

What looks like six unrelated Israeli scholars is one hand wearing six stolen faces: aged accounts, reanimated after a decade of silence, running a single script to get into the same rooms as the people they impersonate. Here is the whole thing before I show you how I found it.

The bottom line

Five takeaways

  1. It impersonates five real, living people. A sociologist at the Hebrew University of Jerusalem, a former Knesset member, a Hudson Institute fellow, a television entertainer, and a former AIPAC chief executive all have a fake account wearing their name, and in Ambreen Ben-Shmuel's case her photograph and even her LinkedIn banner. Proven · named public figures
  2. It pays for access and says the price out loud. Personas circulate a Hebrew invitation offering $1,000 for every Zoom meeting about Israel to at least a dozen named recipients; a sixth account offers the same $1,000 in Arabic for war footage. Proven · verbatim template, multiple accounts
  3. It harvests email under a British research cover. Two personas repeatedly ask targets for their Gmail address specifically, always paired with a promised meeting link, attributed to “an international research project coordinated from Britain.” Proven · ~46 instances on one account
  4. The accounts are old, and were dressed to order. Five of six predate 2014 and sat silent for over a decade; the anchor's banner and avatar were installed 88 seconds apart, another persona's 5 seconds apart. This is acquired infrastructure, not organic growth. Proven · platform timestamps
  5. It was live the day I wrote this, and it is opaque by design. All ten accounts were posting at collection cutoff; none follows any other; six countries of location attribution, none of them Israel. The working language traces to Persian at probable confidence, a likely Iran-aligned signal, though I name no state as the operator. Probable · language + behavior

Method note: the network is built from account metadata and public posts via commercial social-media monitoring. Ten accounts is a floor. For scale, the largest single component in the relevant published platform takedown corpus is 360 accounts; enumeration here is not exhausted.

§ 02 · The Thread I Pulled On

The post that started it

It opens with a warning from a man who did not yet know the fake was already following him. Historian Aurele Tobelem flagged one of these accounts in public; I pulled on his thread, then measured everything myself.

The public warning I pulled on, posted 3 August 2026, 15:49 UTC.

Aurele Tobelem's public X thread warning that @Ambreen_7IL is a fake account impersonating Ambreen ben Shmuel of the Hebrew University of Jerusalem. @AureleTobelem on X · 3 Aug 2026 · view thread ↗
⚑ Handling note: these are leads, not SGI findings Lead

Tobelem is a prior investigator, not an SGI source. I credit him for the referral and I treat his conclusions as leads to be tested, never as my findings.

  • The malware claim stays a lead. SGI did not observe malware, a link, an attachment or any external domain in any public post by any network member. What I observed is the email harvesting that would precede such a delivery. I make no malware finding.
  • One of his facts was partly wrong. He said both accounts were Netherlands-based. Platform attribution returns Netherlands for one and the United States for the other. I report what I measured.
  • The irony worth stating: the fake account follows him. @AureleTobelem sits in the anchor's following list, and his own screenshot shows “Follows you.” He was a target before he was the reporter.
§ 03 · The Network

Six active personas, four dormant reserves

Reverse-enumerating the anchor's template selectors surfaced a family of accounts wearing borrowed identities. Six are active; four more sit dormant on a single stolen name. None follows any other.

The operation, on one timeline

From acquisition to exposure, 2011–2026account registrations · dormant reserves · 2026 activations · exposure

Each flag is a dated event from the collection. Acquisition is the years the accounts were registered (by their prior owners); staging is dormant reserves and the minute-level persona installs; operation is the 2026 activations; exposure is the two public warnings and the SGI open. Hover any point for detail.

The six active personas

Four dormant reserves, all on the Wurmser name

Four further accounts carry the Meyrav Wurmser identity and have never meaningfully posted. Two of them were created 544 seconds apart on the same afternoon. Reserves like these are the clearest sign an operation is built to be reconstituted.

§ 04 · The Five People Impersonated

Real people, wearing their names without consent

These five are real, living, findable people. They are victims of this operation, and I frame them that way. Nothing here implies anything about them; each appears only because a fake account stole their identity.

◆ No inference about anyone approached

Beyond these five, this report names a number of officials, diplomats and journalists the network contacted. Each is named only because the network approached them. Being targeted implies nothing about a person's judgment, conduct or affiliations, and nothing should be read into it.

§ 05 · How the Assets Were Acquired and Dressed

Old accounts, dressed to order

Authentic accounts accrete a persona over years. These were bought or seized, then dressed in minutes. The gap between when the account was born and when the persona was installed is the story.

Account creation year vs persona activation, per personafive assets sat 12 to 15 years before being repurposed

Each row is one persona. The left dot is when the underlying account was created; the right dot is when the persona was switched on in 2026. The connector is the dormancy gap. Five of the six accounts predate 2014.

Persona installation, timed to the second

The imagery that makes an account look like a person, banner and avatar, was installed in a single burst. Then the dressed account waited.

⚑ Five seconds is not a human Automation

Setting a banner and an avatar 5 seconds apart is not something a person does by hand: uploading, cropping and confirming two separate images takes far longer than that for anyone working through the app. A gap that small means the profile was dressed by a script, not a human clicking through settings. The anchor's 88-second install points the same way. This is one of the clearest automation tells in the whole set, and I flag it as exactly that.

They took the banner too, not just the name

The theft was not limited to a display name or a headshot. Side by side, the fake X account and the real person's LinkedIn carry the identical bird-mural banner: the operator copied the cover image, the profile photo, and the bio wholesale.

Fake  @Ambreen_7IL on X, wearing the stolen banner and photo.

The fake @Ambreen_7IL X profile: a bird-mural banner, a lectern photo of the real Ambreen Ben-Shmuel, a Hebrew bio, located in Israel, joined August 2012, 279 following and 13 followers. Fake account · @Ambreen_7IL on X

Real  Ambreen Ben-Shmuel on LinkedIn, the source of the theft.

The real Ambreen Ben-Shmuel's LinkedIn profile, showing the same bird-mural banner and a headshot that the fake @Ambreen_7IL account copied. Real profile · Ambreen Ben-Shmuel on LinkedIn
⚑ The acquired-asset residue

The anchor was created in August 2012 and has no recoverable post for 13 years and 7 months. Nine of its 13 followers are Brazilian, four sharing one surname, with a Brazilian news outlet still in the following list: the prior owner's social graph, left in place when the persona was swapped in. The same tell shows on @66andripped, a fitness-style handle sitting beneath a lobbying-executive persona.

Six jurisdictions, and the one that is missing

The platform attributes each account to a location. Every persona claims to be Israeli. Not one is attributed to Israel.

Location attribution across the six active personasthe absence of Israel is the point

Registration residue

  • @meyraav_wurmser registered through the Portugal App Store
  • @wurmser_me13986 registered through the United States App Store
  • Six jurisdictions of location attribution: Denmark, Germany, Sweden, United States ×2, Netherlands
  • None is Israel, though every persona claims to be Israeli

The anchor's own “About this account” panel: joined 2012, based in the Netherlands, verified only since July 2026, three username changes.

X 'About this account' panel for @Ambreen_7IL showing: joined August 2012, account based in Netherlands with a warning shield, verified since July 2026, 3 username changes last on March 2026, connected via Web. “About this account” panel · @Ambreen_7IL
§ 06 · The Proof of Coordination

The coordination, signal by signal

The accounts are deliberately kept unlinked: no persona follows any other. So coordination has to be proven from behavior, not the follow graph. Three signals do it, and a matrix lays out the overlap.

Nine shared signatures across the six active personas. A filled cell means the persona carries that signature. The purple cells on the bottom row mark the deliberate follow-graph separation, a finding in its own right, not a gap.

One persona vouches for another Proven

The Zvika Hadar persona wrote to a target proposing a research project “with the collaboration of Yehudah Glick.” The Yehudah Glick persona in this same network began its own campaign six days later. One inauthentic account offering another as a credential is direct operational coordination, stated in public.

A corrupted string, shared verbatim Proven

Three accounts publish the identical Hebrew fragment ‏לשוחח איתך ולשוחח עמך‏: “to talk with you and to talk with you,” the same phrase twice with two different prepositions. A machine-generation defect cannot be independently reinvented. Whole templates move verbatim between personas.

◆ Why the separation is a finding, not an absence

Across four sampled follow graphs, no persona follows any other persona. That is disciplined opsec: the operation keeps its assets unlinked so no single suspension unravels the set. It is precisely why the coordination case rests on the cross-vouch and the shared template library rather than on who-follows-whom.

§ 07 · What They Are Actually Doing

Paid meetings, harvested inboxes, a British cover, a Zoom funnel

Strip away the personas and the behavior is consistent: buy a meeting, get a specific email address, invoke a research legend, move the target to a video call. The network states its own price.

$1,000
offered per Zoom meeting about Israel, sent to at least a dozen named recipients
~46
times one persona asked a target for their Gmail address specifically
Britain
the stated coordinator of the “international research project,” a cover legend reused across three personas

The email requests always name one mail provider and always pair with a promised meeting invitation. One persona said it would ask “my secretary” to prepare the link; another told a target it speaks “only through Zoom.” A sixth account ran the same $1,000 offer in Arabic, but for a different commodity: new war footage. Same budget figure, two languages, three personas, two products.

The messages, in their own words

The load-bearing artifacts, each with its original script, a translation, and one line on why it matters. Where a public post exists, the card links to it.

The Zoom funnel, caught in the act

A targeted recipient shared with me the full direct-message thread they received from the Meyrav Wurmser persona, and the link it ended in. It is the clearest look yet at how an approach closes: a warm intro, a push to schedule, a refusal of any channel the operator does not control, and a single link the target is told to “log in” to.

The scheduling push. Note “9am British time,” the refusal of a WhatsApp call, and the pivot to Zoom.

Direct messages from the Meyrav Wurmser persona: agreeing to '9am British time,' saying 'I am ready now, are you ready?', a missed audio call, the target offering WhatsApp, the persona replying 'WhatsApp does not work for me,' and the target suggesting 'Perhaps a Zoom at 11:30?' DM thread · @meyraav_wurmser · provided by a targeted recipient

The link, and the target catching it. The persona sends zoom.siort.fit twice, insists “please log in,” then “I am waiting for you.”

Direct messages: the persona sends 'https://zoom.siort.fit/...' with 'please log in' and 'Please try again,' then 'What is the problem? I am waiting for you.' The recipient replies that the Zoom invite contains spelling errors, that they believe the account is impersonating Meyrav Wurmser, and asks not to be contacted again. DM thread · the phishing link and the recipient's takedown

The link is not Zoom Proven it was sent

  • zoom.siort.fit is a subdomain of siort.fit, not a Zoom-owned domain. “zoom.” is dressing.
  • The path was personalized to the target's name, which means the operator generates a URL per victim.
  • The target was told to “log in” repeatedly, and the operator refused a real audio call and WhatsApp to keep them on that page.
  • The recipient flagged the spelling errors in the invite and identified the impersonation without ever clicking. That instinct is the defense.

What the domain record shows Proven

  • siort.fit registered 31 May 2026, in the operation's staging window; expires May 2027.
  • Registrar NameCheap; name servers on a content-delivery network (Cloudflare), which hides the origin host.
  • Registrant identity and location are masked by the registrar's privacy proxy. The “Capital Region / IS” in the record is that Iceland-based privacy service's own address, not the operator's, and not an attribution to any country.
A WHOIS record for siort.fit: registered 2026-05-31, expires 2027-05-31, registrar NameCheap, name servers dan.ns.cloudflare.com and arya.ns.cloudflare.com, registrant state Capital Region, country IS. Public WHOIS record · siort.fit
⚑ What I claim, and what stays a lead Payload = lead

SGI observed no link in any public post by any network member. This one reached me only because a targeted recipient shared the DM they received. What is proven is that a persona sent a non-Zoom domain and demanded a login while refusing every other channel. Checked after the fact, that path returns NotFound and the bare domain serves a decoy, so the live page is gone and cannot be inspected. Calling it credential-harvesting is consistent with the behavior but unconfirmed, and “malware” stays the third-party investigator's lead, not mine. The operation's product is access, and this is the door it walks targets through.

The bare domain serves a throwaway decoy, “A new day, a fresh start,” over a stock photo. Real meeting infrastructure has no reason to hide behind one.

The siort.fit landing page showing an innocuous decoy: the heading 'A new day, a fresh start' over a stock photo of a hiker on a mountain. siort.fit root · decoy landing page · captured by a recipient

The personalized path now returns NotFound. Per-victim links that die after use are the signature of disposable phishing infrastructure.

A browser showing the URL zoom.siort.fit/aurele.tobelem returning the text 'NotFound'. zoom.siort.fit/<target> · returns NotFound after the fact
§ 08 · The Operator

A single hand, working a shift

The personas are many; the operator behaves like one person on a schedule. A tool output pasted in unread, a persistent grammar failure, machine-speed posting, a fixed daily window, and a recurring email-selector pattern all point the same way.

The operator pasted a text-generation tool's Persian reply into a public post without reading it, 44 minutes into the anchor's campaign. It shows 1 View.

A public reply from @Ambreen_7IL whose first line is a Persian instruction addressed to a text-generation tool, with the Hebrew output pasted beneath it. The post shows 1 View. @Ambreen_7IL · 11 Jul 2026 · shows 1 View · view on X ↗

The Persian artifact Probable

The first line of that post is Persian, addressed to a tool: “If your goal is to convert this text into a shorter and more fluent tweet, it could be like this:” The Hebrew output is pasted beneath it, published unread.

It is corroborated by a persistent Hebrew grammatical-gender failure across the network: female personas writing of themselves in the masculine, and male recipients addressed in the feminine, including a single burst on 14 July where all six recipients were male and all six were addressed as women. That is the signature of generation from a language whose verbs do not inflect for speaker gender.

◆ Persian-speaking, likely Iran-aligned

The operator's working language is Persian, which is consistent with an Iran-aligned operation and is how I characterize it, at probable confidence. I hold it at “likely Iran-aligned” rather than harder: Persian is spoken widely beyond Iran, the artifact could reflect a tool's interface locale, and alignment is not the same as proving which state, if any, runs the accounts.

This is automation, not typing Proven

The posting speed settles it. One account put out 13 posts in 431 seconds, twelve of them byte-identical; another sent 5 posts in 48 seconds. No person types and sends a dozen near-identical messages seconds apart. The accounts are being driven by a script.

Documented posting bursts · posts against secondseach tick is one post; the bar is the window

Four documented bursts. The 26 July anchor burst put 13 posts out in 431 seconds, 12 of them byte-identical; the 7 July Wurmser burst put 5 posts out in 48 seconds.

A fixed shift, on a clock that is not Israel's Proven

The anchor's 24-hour posting band87 posts fall in a single 7-hour window across 16 active days
◆ The 13:32 tell

Partial email selectors Lead

I have captured partial email selectors tied to three of the accounts. They stay masked here; what matters is not the addresses but the pattern they fit.

◆ Consistent with, not proof

These masked selectors resemble ones I have recorded on other Iran-aligned sock-puppet accounts, including the network in my earlier Iran-aligned report. That resemblance points the same way as the Persian working language: consistent with an Iran-aligned operation, and a lead rather than proof. I am not publishing the addresses, and a masked fragment is a fingerprint, not an identity.

§ 09 · The Target Set

A regional collection requirement, drawn from who they follow

Convergent anchors are dense: several real accounts are followed by three or four separate personas. The composition of who the network follows and contacts reads like a collection brief, not a research audience.

★ What the composition implies

Israel's political and security elite, its diplomatic corps worldwide, its press corps, plus Syrian figures (including the Governor of Damascus, also DM-solicited in Arabic), an Iran-axis analyst, and Azerbaijan-focused targets across two personas. Israel + Syria + the Kurds + Azerbaijan + Iran-watchers is a coherent regional collection requirement. I describe the shape; I do not name whose requirement it is.

§ 10 · Reach, and Why It Is the Wrong Measure

The numbers are tiny. That is not the point.

If you measured this operation by reach, you would conclude it failed. You would be measuring the wrong thing. Its product is access, and access happens off the public surface.

◆ Method & limitations: a floor, not a census

Ten accounts is what my collection reached, not a measured network size; each new persona surfaced selectors that led to more accounts, and template selectors are now saturated, so further expansion needs platform-side data. Timelines are partial where lifetime post counts exceed recoverable posts (88 of 146 for the anchor); follow graphs are sampled (174 of 279); anything deleted before 3 August 2026 is invisible. Every count is a minimum. For scale, the largest single component in the relevant published platform takedown corpus is 360 accounts. No capacity-to-impact inference should be drawn: low reach does not mean low harm, any more than high reach would prove it. No account was accessed or taken over, no verification code was requested, received or entered, and no network member was engaged, messaged or replied to; collection was read-only against publicly visible data and lawful commercial sources. The direct-message captures and the meeting link in §07 were provided by a targeted recipient, not collected by SGI; by the time the link was checked it returned NotFound.

§ 11 · Assessment

Four hypotheses, one honest ceiling

Two different questions get two different answers here: what the operation is doing is well evidenced; who runs it is not. I rank the explanations by fit and stop where the public data stops.

⚑ The contradiction I am not smoothing over

The South Azerbaijani accounts in the follow graphs are adversarial to Tehran, which cuts against a simple reading. It may indicate collection interest in a target of concern rather than alignment with it, since the Israel–Azerbaijan relationship is a standing preoccupation for that region's services. Both readings are available; this report does not choose between them. That is what keeping the ceiling at “structurally consistent with” means in practice.

★ The same fabric, a different thread

The 21-account Iran-aligned network I mapped earlier was built to broadcast, reach in the millions. This one is built to stay quiet and buy access, one meeting at a time. Same playbook underneath, manufactured personas and a shared template library, opposite tactic on top. I am pulling these threads one at a time.

§ 12 · What to Watch Next

Live, unresolved signals

All ten accounts were live at cutoff. These are the signals I would re-query, each one a thing that would move the assessment if it changed.

§ 13 · The Takeaway

Old accounts, real names, one hidden hand

A single public warning was the thread. Pulling it uncovered a coordinated impersonation network: aged accounts, dressed in the names and in one case the photograph of five real Israeli scholars, officials and public figures, working one script to buy meetings at $1,000 each, harvest email addresses under a British research cover, and move targets to a Zoom call. The coordination is proven from a cross-vouch and a shared, corrupted template library; the operator's working language traces to Persian at probable confidence, a likely Iran-aligned signal. I name no state, service or person as the operator, because the honest ceiling is “structurally consistent with,” and I hold the line there.

The most useful thing a reader can take from this is not the attribution I withhold, but the defense some targets already ran.

★ The reply that works, from a target who asked the right questions

A due-diligence reply recurs about nine times in the corpus, from Israeli journalists interrogating the pretext. It is the practical model for anyone who gets an approach like this:

“Thank you for your approach and the invitation to participate in the research. I would be glad to receive more detailed information about the body responsible for the research, its objectives, participation conditions and relevant ethics approval, and clarification of how the interview and the compensation would work.”

Ask who is responsible, what the ethics approval is, and how the money works. A real project answers. This one asks for your Gmail.

§ · Note on Scope

What this report claims, and what it does not

◆ Note on scope

This is an evidence-led account of a coordinated impersonation network and how I found it. I grade every finding by strength and keep proven facts apart from probable inference. I name no state, service or person. The attribution ceiling is “structurally consistent with” tradecraft described in published platform reporting; that is the whole claim. The operator is Persian-speaking and the operation is likely Iran-aligned, at probable confidence. The five impersonated people are victims, and everyone the network approached is named only because the network approached them. Every count here is a floor, not a census: ten accounts is what my collection reached, not a measured network size. No account was accessed or taken over.

★ Before you accept an invitation from a stranger online

An aged account, a borrowed name, a flattering research invitation and a cash offer are not, individually, proof of anything. Together they describe an operation built to buy a meeting and stay unaccountable. Ask for the responsible body, the ethics approval, and how payment works before you give anyone an email address or a calendar slot.

I am Travis Hawley. If an account approaches you claiming to be a scholar or an official and something feels off, or you want a network traced, reach out: shadowgraphintel.com/contact, @talk2trav on X, and @talk2trav on Instagram. And scrutinize whatever you read next, including me.