Meitav Trade Suffers Cyberattack, Exposing Customer Data
Meitav Trade, a subsidiary of the Meitav investment house, reported a significant data security incident that exposed personal details of its customers. The breach, discovered on Saturday, September 26, 2026, led to the sending of approximately 3,000 fraudulent SMS messages to customers requesting two-factor authentication.
The exposed information includes full names, identity card numbers, and bank account details. The company identified the vulnerability in an API interface of an external supplier, which was exploited by an unknown external party. This party managed to extract personal information from the accounts that received the authentication code messages. There were also unsuccessful attempts to alter the destination phone number for the authentication codes.
Meitav Trade immediately blocked access to the compromised interface. The company stated that customer funds and trading systems were not accessed, and no passwords, financial data, or identification documents were exposed. Meitav Investment House assured that the exposure was limited to the supplier's interface and did not affect other group systems or clients.
Following the disclosure, Meitav Trade's stock fell by over 5% at the opening of trading on the Tel Aviv Stock Exchange. The company has stated it will notify all affected customers. While the company believes the incident is over and does not expect significant damage, it cautioned that this assessment could change.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
Ask About This Article
Duki reads it, and every newsroom on the same story, then answers with sources.