Netanyahu Advisor's WhatsApp Data May Have Reached UAE Authorities
Translated & summarized from Vesty by baba
The story in 5 lines · by baba
- Netanyahu advisor's personal WhatsApp connected to UAE service.
- Service gained unencrypted access to all messages and media.
- UAE laws may allow authorities access to the data.
- Code published on GitHub revealed security vulnerabilities.
- Advisor used personal account, not a dedicated work account.
An advisor to Israeli Prime Minister Benjamin Netanyahu, Yoni Urikh, who is involved in the 'Qatargate' affair, connected his personal WhatsApp account to a service operated by a company based in the United Arab Emirates. This connection granted the service access to all messages and media files in his account in unencrypted form. According to the Israeli business publication Calcalist, this correspondence could have been accessed by UAE authorities due to local laws. The issue came to light after Urikh published the code for a media monitoring tool he developed on the GitHub platform. This tool, which he built using an AI model, tracked real-time mentions of Netanyahu and his wife, sending notifications to specific WhatsApp groups. The code, initially made publicly available in an open repository, contained sensitive information, access tokens, and identifiers for WhatsApp groups, potentially exposing group members' identities, phone numbers, and message content.
Following an inquiry by the newspaper Haaretz, Urikh's GitHub page access was restricted. However, the code had already been copied and distributed by users who found it before the article's publication. Cybersecurity experts who examined the code highlighted the significant security and privacy risks created by Urikh's actions. They explained that such third-party tools, often used for managing large numbers of groups or automated messaging, gain full, unencrypted access to WhatsApp accounts, including the ability to send messages and manage contacts.
Urikh reportedly used the service 'ultramsg' to send notifications. This service connects to WhatsApp by scanning a QR code, similar to linking a new device. Once connected, it can read and send messages, manage groups, and automate tasks. A cybersecurity researcher told Calcalist that Urikh connected his personal WhatsApp account, not a dedicated work account, meaning all his correspondence was accessible to ultramsg in unencrypted form. Given that Urikh communicates with high-ranking officials, his messages could contain sensitive or classified information.
Further concerns arise from ultramsg's terms of service, which permit sharing collected data with third parties and store information on Amazon servers for 120 days, even if messages are set to auto-delete. The primary risk, however, stems from the service's UAE base. Unlike stricter privacy laws in Western countries, UAE laws are less stringent, potentially compelling companies to share data with authorities without user consent. Security agencies in the UAE may access account data and message content without a warrant. Therefore, Urikh's correspondence, accessed by ultramsg, could have been made available to UAE authorities without his knowledge, the publication concluded. Urikh did not respond to Calcalist's request for comment.
Read the original at VestyMentioned
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
