Voice phishing simulations in Israel
Israel does not organise privacy law around lawful bases, so nothing about a voice phishing simulation here turns on picking one. It works from a closed list of infringing acts and a list of defences, and the provision that matters most is sharper than any of them: approaching someone for personal information to be processed in a database, giving false particulars and meaning to mislead them into handing it over, is a three-year offence. What the call is built to collect is therefore the whole design.
Phone numbers
Supplied by Callstrike
Local numbers in Israel, after a one-time approval.
Running a simulation
Permitted, and the script is the risk
A three-year offence turns on approaching someone for data with false particulars.
Consent
Weak as a ground, and still necessary
The regulator gives employee agreement little weight, then asks for a written policy.
Getting a phone number in Israel
One approval per country, with no documentation to gather.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days.
Israel is one of the few countries in this portal where the carrier publishes no documentation requirement on any number type offered here, so there is no register excerpt to chase and no evidence pack to assemble. Plan for the days rather than the paperwork: what you are waiting on is the country being enabled against your workspace, not a regulator reading a submission.
What does stand between you and a working campaign is the network rather than the file, and it is decisive. In September 2024 the ministry signed instructions taking effect immediately. An international service provider must block calls originating outside Israel where the caller identity is an Israeli fixed-line number. A mobile provider must block calls from outside Israel presenting a mobile number, with an exception only for its own customer who is roaming. And a service provider must not permit its subscribers to use numbers that have not been allocated for their use. Read together, the international route most campaigns default to simply does not complete, and a compliant Israeli provider cannot enable you to present somebody else's number. Israeli traffic originates on Israeli-allocated numbers or it does not arrive.
We would rather record a gap in the sourcing than paper over it. The ministry's announcement quotes the instructions it signed but does not name the amended instrument and gives no gazette citation, and we could not locate the published regulation text. The substance above rests on the ministry's own statement of the rules it made, and that is the limit of what we can show you.
- 01Ask for the country to be enabled for your workspaceYour administrator, in the Callstrike console.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Israel is assigned to youCallstrike
- 04Build and launch the campaignYour team
No regulatory documentation is required to hold a number here. The clearance step is Callstrike enabling the country for your workspace, with no forms to complete and no evidence to gather.
Is it lawful to run a simulation in Israel?
The position in short, before your counsel reads the detail below.
Yes, and the analysis runs differently from anywhere else on this site. There is no basis to select. The statute prohibits infringing another's privacy without their agreement, defines infringement as one of eleven enumerated acts, and then supplies defences, so the question is whether the campaign performs one of the eleven and, if it does, whether a defence holds. Four of the eleven can reach an exercise, and one of them predates synthetic voice by four decades: the use of a person's name, nickname, image or voice, for profit. Its gate is those last two words. The defences are more useful than they first look, covering good-faith acts done under a legal, moral, social or professional duty, or for the protection of a legitimate personal interest, or in the lawful course of an occupation and the ordinary course of work provided they were not done by public publication, and a threshold provision bars any action for an infringement of no substance. An authorised, documented, proportionate internal exercise is the shape those defences were drawn around, and the last one is a reason to keep the exercise internal rather than write it up publicly.
The provision that actually decides how the call is scripted is not about privacy in the abstract at all. An approach to a person to receive personal information for its processing in a database has to be accompanied by a notice stating whether giving the information is obligatory or voluntary and what refusing means, the purpose, who controls the database and how to reach them, who the information goes to and why, and the rights of access and rectification. That is a pretext call described backwards, and the amendment in force since August 2025 put two prices on it. Failing the notice is an administrative fine of fifty shekels multiplied by the number of people approached, doubling to a hundred where specially sensitive information was involved, with a thirty thousand shekel floor, so a two-thousand-person campaign is arithmetic rather than discretion. And giving false particulars in such an approach, meaning to mislead the person into handing the data over, is a criminal offence carrying three years.
The workable reading, and the one that should shape the script, is that both provisions bite on an approach made in order to process the information in a database. An exercise that records only that a person would have complied, and never captures or stores what they would have said, is a long way from the offence. An exercise that harvests a credential under a false identity and files it is not. Note also which statute you are reading about: the amending act was published in August 2024 and commences one year later, so anything describing Israeli privacy law from before August 2025 is describing something else.
Two provisions outside the privacy statute complete the picture and they point opposite ways. The anti-spam rule does not reach you, because advertising material is defined exhaustively in three limbs and an employer testing its own staff sends none of them, which also means the thousand-shekel-per-item exposure that makes Israeli marketing counsel nervous does not attach. But using a telecommunications installation in a manner capable of hurting, frightening, harassing, creating anxiety or annoying is an offence carrying three years and is not scoped to advertising at all. That is the one a badly designed exercise runs into, so calibrate the scenario and cap the retries. On synthetic voice the honest answer is that Israel has no duty: no statute, no disclosure obligation and no rule requiring a caller to announce that a voice is generated. What exists is a joint ministerial policy paper addressed to regulators, recommending sectoral rules, and it should not be described as a duty on a caller.
What your company needs to do
7 items, in the order you will need them.
- Design the call so nothing is acquiredIsrael-specificBoth the notice duty and the three-year offence attach to an approach made in order to process the information in a database. An exercise configured so that a disclosed credential cannot enter a database is not making that kind of approach, and being able to show the configuration is worth more than being able to argue about intent afterwards.
- Settle the notice question in advance, because the fine is arithmeticIsrael-specificFifty shekels for every person approached, doubling for specially sensitive information, with a thirty thousand shekel floor and no discretion in the formula. The regulator issued a fine for exactly this failure in August 2026. Record the decision you took about the statutory notice, and why, before the first call rather than in response to a complaint.
- Write the monitoring and testing policy, detailed rather than generalIsrael-specificThis is where the Israeli deliverable lives, and it is regulatory rather than legislative. The regulator wants a clear and detailed policy on the manner, scope and purposes of the monitoring, set so far as possible after consultation with employees or their representatives, kept before them on an ongoing basis and periodically refreshed. So far as possible is not a duty to consult, and we are not going to upgrade it into one, but it is what the body investigating a complaint expects to see.
- Fix the distribution list for call audio before you record anythingIsrael-specificKnowingly disclosing the content of a conversation obtained by monitoring to someone not authorised to receive it is a separate five-year offence, and the provision says in terms that it applies whether the monitoring was lawful or unlawful. Who may hear a debrief recording is a legal question here rather than an administrative one.
- Document the assurance purpose before the exercise runsIsrael-specificRecording with one party's agreement is outside the secret monitoring offence by definition, but a recording made for the purpose of committing an offence or a harmful act is pulled back in and treated as secret monitoring. The purpose has to be documented in advance and it has to be an assurance purpose, not reconstructed afterwards when someone characterises the programme uncharitably.
- Use an invented persona, and keep it clear of the profit limbOne of the eleven infringing acts is the use of a person's name, nickname, image or voice for profit, and its gate is that last phrase. A generic help desk is nobody's name or voice. Cloning a named executive puts you into an argument about a limb whose intentional breach is a five-year offence, for no gain in realism you could not get otherwise.
- Check whether your own regulator already requires thisFor insurers and pension and provident fund managers it is not an optional maturity exercise: the capital market authority circular requires social engineering, impersonation and phishing tests at least once a year, and has done since April 2017. For a bank the central bank directive requires awareness training and exercises of the response arrays, not testing of people. Look in the right regulator before assuming either way.
The controls that do the work
How Callstrike is configured, and which provision in Israel each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
This is the control the whole Israeli position turns on, because the sharpest provision here bites on acquiring the data rather than on placing the call. The three-year offence and the notice duty both attach to an approach made in order to receive personal information for processing in a database. The call ends the moment an employee begins to give up a credential, so the information the pretext asked for is never received and never enters a database, and the purpose element the offence is built on describes something the system is configured not to do. That is a statement about the facts rather than a claimed defence, which is the strongest form the answer can take.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The regulator replaces employee agreement with proportionality and transparency, and there is a separate three-year offence for using a telecommunications installation in a manner capable of frightening, creating anxiety or harassing. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, speaks to both at once: it is the difference between an exercise that leaves someone frightened and one that leaves them taught, and that difference is exactly what those two tests are measuring.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
The regulator's workplace guideline is blunt: an employee's agreement to an infringement of the right to privacy, including to collection or use of information by an employer, does not carry great weight, and the reason given is the power gap. So agreement is not the ground here. What the same guideline then demands is a clear and detailed policy kept before employees on an ongoing basis, which is a notice and transparency duty, and that is precisely what this produces: the dated evidence per employee that the policy was given, or a hashed copy of the policy with a signed and timestamped attestation of the scope it covers.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
The Israeli obstacle is the number rather than the law, and this route does not need one. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, so the three blocking instructions have no Israeli calling identity to act on and no international origination to refuse. Be precise about the limit: Israel imposes no synthetic-voice disclosure duty for the module to satisfy, and the privacy statute governs whatever either route collects, so the module is an answer to delivery and not to the script.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.