A network of fake academics, buying its way into real rooms
What looks like six unrelated Israeli scholars is one hand wearing six stolen faces: aged accounts, reanimated after a decade of silence, running a single script to get into the same rooms as the people they impersonate. Here is the whole thing before I show you how I found it.
Five takeaways
- It impersonates five real, living people. A sociologist at the Hebrew University of Jerusalem, a former Knesset member, a Hudson Institute fellow, a television entertainer, and a former AIPAC chief executive all have a fake account wearing their name, and in Ambreen Ben-Shmuel's case her photograph and even her LinkedIn banner. Proven · named public figures
- It pays for access and says the price out loud. Personas circulate a Hebrew invitation offering $1,000 for every Zoom meeting about Israel to at least a dozen named recipients; a sixth account offers the same $1,000 in Arabic for war footage. Proven · verbatim template, multiple accounts
- It harvests email under a British research cover. Two personas repeatedly ask targets for their Gmail address specifically, always paired with a promised meeting link, attributed to “an international research project coordinated from Britain.” Proven · ~46 instances on one account
- The accounts are old, and were dressed to order. Five of six predate 2014 and sat silent for over a decade; the anchor's banner and avatar were installed 88 seconds apart, another persona's 5 seconds apart. This is acquired infrastructure, not organic growth. Proven · platform timestamps
- It was live the day I wrote this, and it is opaque by design. All ten accounts were posting at collection cutoff; none follows any other; six countries of location attribution, none of them Israel. The working language traces to Persian at probable confidence, a likely Iran-aligned signal, though I name no state as the operator. Probable · language + behavior
Method note: the network is built from account metadata and public posts via commercial social-media monitoring. Ten accounts is a floor. For scale, the largest single component in the relevant published platform takedown corpus is 360 accounts; enumeration here is not exhausted.
This is one more thread pulled on the same fabric. I keep finding coordinated operations on X and taking them apart one at a time; two earlier ones are worth reading alongside this.
The post that started it
It opens with a warning from a man who did not yet know the fake was already following him. Historian Aurele Tobelem flagged one of these accounts in public; I pulled on his thread, then measured everything myself.
The public warning I pulled on, posted 3 August 2026, 15:49 UTC.
@AureleTobelem on X · 3 Aug 2026 · view thread ↗
Tobelem is a prior investigator, not an SGI source. I credit him for the referral and I treat his conclusions as leads to be tested, never as my findings.
- The malware claim stays a lead. SGI did not observe malware, a link, an attachment or any external domain in any public post by any network member. What I observed is the email harvesting that would precede such a delivery. I make no malware finding.
- One of his facts was partly wrong. He said both accounts were Netherlands-based. Platform attribution returns Netherlands for one and the United States for the other. I report what I measured.
- The irony worth stating: the fake account follows him. @AureleTobelem sits in the anchor's following list, and his own screenshot shows “Follows you.” He was a target before he was the reporter.
Six active personas, four dormant reserves
Reverse-enumerating the anchor's template selectors surfaced a family of accounts wearing borrowed identities. Six are active; four more sit dormant on a single stolen name. None follows any other.
The operation, on one timeline
Each flag is a dated event from the collection. Acquisition is the years the accounts were registered (by their prior owners); staging is dormant reserves and the minute-level persona installs; operation is the 2026 activations; exposure is the two public warnings and the SGI open. Hover any point for detail.
The six active personas
Four dormant reserves, all on the Wurmser name
Four further accounts carry the Meyrav Wurmser identity and have never meaningfully posted. Two of them were created 544 seconds apart on the same afternoon. Reserves like these are the clearest sign an operation is built to be reconstituted.
Real people, wearing their names without consent
These five are real, living, findable people. They are victims of this operation, and I frame them that way. Nothing here implies anything about them; each appears only because a fake account stole their identity.
Beyond these five, this report names a number of officials, diplomats and journalists the network contacted. Each is named only because the network approached them. Being targeted implies nothing about a person's judgment, conduct or affiliations, and nothing should be read into it.
Old accounts, dressed to order
Authentic accounts accrete a persona over years. These were bought or seized, then dressed in minutes. The gap between when the account was born and when the persona was installed is the story.
Each row is one persona. The left dot is when the underlying account was created; the right dot is when the persona was switched on in 2026. The connector is the dormancy gap. Five of the six accounts predate 2014.
Persona installation, timed to the second
The imagery that makes an account look like a person, banner and avatar, was installed in a single burst. Then the dressed account waited.
Setting a banner and an avatar 5 seconds apart is not something a person does by hand: uploading, cropping and confirming two separate images takes far longer than that for anyone working through the app. A gap that small means the profile was dressed by a script, not a human clicking through settings. The anchor's 88-second install points the same way. This is one of the clearest automation tells in the whole set, and I flag it as exactly that.
They took the banner too, not just the name
The theft was not limited to a display name or a headshot. Side by side, the fake X account and the real person's LinkedIn carry the identical bird-mural banner: the operator copied the cover image, the profile photo, and the bio wholesale.
Fake @Ambreen_7IL on X, wearing the stolen banner and photo.
Fake account · @Ambreen_7IL on X
Real Ambreen Ben-Shmuel on LinkedIn, the source of the theft.
Real profile · Ambreen Ben-Shmuel on LinkedIn
The anchor was created in August 2012 and has no recoverable post for 13 years and 7 months. Nine of its 13 followers are Brazilian, four sharing one surname, with a Brazilian news outlet still in the following list: the prior owner's social graph, left in place when the persona was swapped in. The same tell shows on @66andripped, a fitness-style handle sitting beneath a lobbying-executive persona.
Six jurisdictions, and the one that is missing
The platform attributes each account to a location. Every persona claims to be Israeli. Not one is attributed to Israel.
Registration residue
- @meyraav_wurmser registered through the Portugal App Store
- @wurmser_me13986 registered through the United States App Store
- Six jurisdictions of location attribution: Denmark, Germany, Sweden, United States ×2, Netherlands
- None is Israel, though every persona claims to be Israeli
The anchor's own “About this account” panel: joined 2012, based in the Netherlands, verified only since July 2026, three username changes.
“About this account” panel · @Ambreen_7IL
The coordination, signal by signal
The accounts are deliberately kept unlinked: no persona follows any other. So coordination has to be proven from behavior, not the follow graph. Three signals do it, and a matrix lays out the overlap.
Nine shared signatures across the six active personas. A filled cell means the persona carries that signature. The purple cells on the bottom row mark the deliberate follow-graph separation, a finding in its own right, not a gap.
One persona vouches for another Proven
The Zvika Hadar persona wrote to a target proposing a research project “with the collaboration of Yehudah Glick.” The Yehudah Glick persona in this same network began its own campaign six days later. One inauthentic account offering another as a credential is direct operational coordination, stated in public.
A corrupted string, shared verbatim Proven
Three accounts publish the identical Hebrew fragment לשוחח איתך ולשוחח עמך: “to talk with you and to talk with you,” the same phrase twice with two different prepositions. A machine-generation defect cannot be independently reinvented. Whole templates move verbatim between personas.
Across four sampled follow graphs, no persona follows any other persona. That is disciplined opsec: the operation keeps its assets unlinked so no single suspension unravels the set. It is precisely why the coordination case rests on the cross-vouch and the shared template library rather than on who-follows-whom.
Paid meetings, harvested inboxes, a British cover, a Zoom funnel
Strip away the personas and the behavior is consistent: buy a meeting, get a specific email address, invoke a research legend, move the target to a video call. The network states its own price.
The email requests always name one mail provider and always pair with a promised meeting invitation. One persona said it would ask “my secretary” to prepare the link; another told a target it speaks “only through Zoom.” A sixth account ran the same $1,000 offer in Arabic, but for a different commodity: new war footage. Same budget figure, two languages, three personas, two products.
The messages, in their own words
The load-bearing artifacts, each with its original script, a translation, and one line on why it matters. Where a public post exists, the card links to it.
The Zoom funnel, caught in the act
A targeted recipient shared with me the full direct-message thread they received from the Meyrav Wurmser persona, and the link it ended in. It is the clearest look yet at how an approach closes: a warm intro, a push to schedule, a refusal of any channel the operator does not control, and a single link the target is told to “log in” to.
The scheduling push. Note “9am British time,” the refusal of a WhatsApp call, and the pivot to Zoom.
DM thread · @meyraav_wurmser · provided by a targeted recipient
The link, and the target catching it. The persona sends zoom.siort.fit twice, insists “please log in,” then “I am waiting for you.”
DM thread · the phishing link and the recipient's takedown
The link is not Zoom Proven it was sent
- zoom.siort.fit is a subdomain of siort.fit, not a Zoom-owned domain. “zoom.” is dressing.
- The path was personalized to the target's name, which means the operator generates a URL per victim.
- The target was told to “log in” repeatedly, and the operator refused a real audio call and WhatsApp to keep them on that page.
- The recipient flagged the spelling errors in the invite and identified the impersonation without ever clicking. That instinct is the defense.
What the domain record shows Proven
- siort.fit registered 31 May 2026, in the operation's staging window; expires May 2027.
- Registrar NameCheap; name servers on a content-delivery network (Cloudflare), which hides the origin host.
- Registrant identity and location are masked by the registrar's privacy proxy. The “Capital Region / IS” in the record is that Iceland-based privacy service's own address, not the operator's, and not an attribution to any country.
Public WHOIS record · siort.fit
SGI observed no link in any public post by any network member. This one reached me only because a targeted recipient shared the DM they received. What is proven is that a persona sent a non-Zoom domain and demanded a login while refusing every other channel. Checked after the fact, that path returns NotFound and the bare domain serves a decoy, so the live page is gone and cannot be inspected. Calling it credential-harvesting is consistent with the behavior but unconfirmed, and “malware” stays the third-party investigator's lead, not mine. The operation's product is access, and this is the door it walks targets through.
The bare domain serves a throwaway decoy, “A new day, a fresh start,” over a stock photo. Real meeting infrastructure has no reason to hide behind one.
siort.fit root · decoy landing page · captured by a recipient
The personalized path now returns NotFound. Per-victim links that die after use are the signature of disposable phishing infrastructure.
zoom.siort.fit/<target> · returns NotFound after the fact
A single hand, working a shift
The personas are many; the operator behaves like one person on a schedule. A tool output pasted in unread, a persistent grammar failure, machine-speed posting, a fixed daily window, and a recurring email-selector pattern all point the same way.
The operator pasted a text-generation tool's Persian reply into a public post without reading it, 44 minutes into the anchor's campaign. It shows 1 View.
@Ambreen_7IL · 11 Jul 2026 · shows 1 View · view on X ↗
The Persian artifact Probable
The first line of that post is Persian, addressed to a tool: “If your goal is to convert this text into a shorter and more fluent tweet, it could be like this:” The Hebrew output is pasted beneath it, published unread.
It is corroborated by a persistent Hebrew grammatical-gender failure across the network: female personas writing of themselves in the masculine, and male recipients addressed in the feminine, including a single burst on 14 July where all six recipients were male and all six were addressed as women. That is the signature of generation from a language whose verbs do not inflect for speaker gender.
The operator's working language is Persian, which is consistent with an Iran-aligned operation and is how I characterize it, at probable confidence. I hold it at “likely Iran-aligned” rather than harder: Persian is spoken widely beyond Iran, the artifact could reflect a tool's interface locale, and alignment is not the same as proving which state, if any, runs the accounts.
This is automation, not typing Proven
The posting speed settles it. One account put out 13 posts in 431 seconds, twelve of them byte-identical; another sent 5 posts in 48 seconds. No person types and sends a dozen near-identical messages seconds apart. The accounts are being driven by a script.
Four documented bursts. The 26 July anchor burst put 13 posts out in 431 seconds, 12 of them byte-identical; the 7 July Wurmser burst put 5 posts out in 48 seconds.
A fixed shift, on a clock that is not Israel's Proven
Partial email selectors Lead
I have captured partial email selectors tied to three of the accounts. They stay masked here; what matters is not the addresses but the pattern they fit.
These masked selectors resemble ones I have recorded on other Iran-aligned sock-puppet accounts, including the network in my earlier Iran-aligned report. That resemblance points the same way as the Persian working language: consistent with an Iran-aligned operation, and a lead rather than proof. I am not publishing the addresses, and a masked fragment is a fingerprint, not an identity.
A regional collection requirement, drawn from who they follow
Convergent anchors are dense: several real accounts are followed by three or four separate personas. The composition of who the network follows and contacts reads like a collection brief, not a research audience.
Israel's political and security elite, its diplomatic corps worldwide, its press corps, plus Syrian figures (including the Governor of Damascus, also DM-solicited in Arabic), an Iran-axis analyst, and Azerbaijan-focused targets across two personas. Israel + Syria + the Kurds + Azerbaijan + Iran-watchers is a coherent regional collection requirement. I describe the shape; I do not name whose requirement it is.
The numbers are tiny. That is not the point.
If you measured this operation by reach, you would conclude it failed. You would be measuring the wrong thing. Its product is access, and access happens off the public surface.
Ten accounts is what my collection reached, not a measured network size; each new persona surfaced selectors that led to more accounts, and template selectors are now saturated, so further expansion needs platform-side data. Timelines are partial where lifetime post counts exceed recoverable posts (88 of 146 for the anchor); follow graphs are sampled (174 of 279); anything deleted before 3 August 2026 is invisible. Every count is a minimum. For scale, the largest single component in the relevant published platform takedown corpus is 360 accounts. No capacity-to-impact inference should be drawn: low reach does not mean low harm, any more than high reach would prove it. No account was accessed or taken over, no verification code was requested, received or entered, and no network member was engaged, messaged or replied to; collection was read-only against publicly visible data and lawful commercial sources. The direct-message captures and the meeting link in §07 were provided by a targeted recipient, not collected by SGI; by the time the link was checked it returned NotFound.
Four hypotheses, one honest ceiling
Two different questions get two different answers here: what the operation is doing is well evidenced; who runs it is not. I rank the explanations by fit and stop where the public data stops.
The South Azerbaijani accounts in the follow graphs are adversarial to Tehran, which cuts against a simple reading. It may indicate collection interest in a target of concern rather than alignment with it, since the Israel–Azerbaijan relationship is a standing preoccupation for that region's services. Both readings are available; this report does not choose between them. That is what keeping the ceiling at “structurally consistent with” means in practice.
The 21-account Iran-aligned network I mapped earlier was built to broadcast, reach in the millions. This one is built to stay quiet and buy access, one meeting at a time. Same playbook underneath, manufactured personas and a shared template library, opposite tactic on top. I am pulling these threads one at a time.
Live, unresolved signals
All ten accounts were live at cutoff. These are the signals I would re-query, each one a thing that would move the assessment if it changed.
Old accounts, real names, one hidden hand
A single public warning was the thread. Pulling it uncovered a coordinated impersonation network: aged accounts, dressed in the names and in one case the photograph of five real Israeli scholars, officials and public figures, working one script to buy meetings at $1,000 each, harvest email addresses under a British research cover, and move targets to a Zoom call. The coordination is proven from a cross-vouch and a shared, corrupted template library; the operator's working language traces to Persian at probable confidence, a likely Iran-aligned signal. I name no state, service or person as the operator, because the honest ceiling is “structurally consistent with,” and I hold the line there.
The most useful thing a reader can take from this is not the attribution I withhold, but the defense some targets already ran.
A due-diligence reply recurs about nine times in the corpus, from Israeli journalists interrogating the pretext. It is the practical model for anyone who gets an approach like this:
“Thank you for your approach and the invitation to participate in the research. I would be glad to receive more detailed information about the body responsible for the research, its objectives, participation conditions and relevant ethics approval, and clarification of how the interview and the compensation would work.”
Ask who is responsible, what the ethics approval is, and how the money works. A real project answers. This one asks for your Gmail.
What this report claims, and what it does not
This is an evidence-led account of a coordinated impersonation network and how I found it. I grade every finding by strength and keep proven facts apart from probable inference. I name no state, service or person. The attribution ceiling is “structurally consistent with” tradecraft described in published platform reporting; that is the whole claim. The operator is Persian-speaking and the operation is likely Iran-aligned, at probable confidence. The five impersonated people are victims, and everyone the network approached is named only because the network approached them. Every count here is a floor, not a census: ten accounts is what my collection reached, not a measured network size. No account was accessed or taken over.
An aged account, a borrowed name, a flattering research invitation and a cash offer are not, individually, proof of anything. Together they describe an operation built to buy a meeting and stay unaccountable. Ask for the responsible body, the ethics approval, and how payment works before you give anyone an email address or a calendar slot.
I am Travis Hawley. If an account approaches you claiming to be a scholar or an official and something feels off, or you want a network traced, reach out: shadowgraphintel.com/contact, @talk2trav on X, and @talk2trav on Instagram. And scrutinize whatever you read next, including me.
