Israeli Cybersecurity Manager Indicted for AI-Powered Corporate Espionage

An Ashkelon cybersecurity manager has been indicted for using AI to plant malware in 26 major Israeli companies, spying on employees through webcams.

Ynet•Author: Meir Turgeman
Source •
Israeli Cybersecurity Manager Indicted for AI-Powered Corporate Espionage
Photo: Ynet / ( )

A shocking cyber-espionage case has unfolded in Israel following the indictment of Michael (Mيكي) Bar, a 43-year-old married father from Ashkelon and a senior information security manager. Investigators from the National Cyber Unit at Lahav 433 revealed that Bar used artificial intelligence, specifically manipulating the Claude AI model, to develop sophisticated malware. Over the past six years, he successfully breached the computer systems of 26 major Israeli companies, two kibbutzim, and private individuals.

The Investigation and False Assumptions

When the National Cyber Directorate (INCD) first detected suspicious cyber activity earlier this year, investigators initially feared a hostile state-sponsored attack, possibly originating from Iran, or a sophisticated ransomware operation aimed at extorting major Israeli corporations. However, a covert investigation led by Lahav 433 officers—including Chief Inspector Ariel Raveh, Master Sergeant Ravid Neuman, and Sergeant First Class Maayan Peri—traced the digital footprint back to Bar's IP address and email. To their astonishment, the prime suspect was not a foreign operative, but a trusted insider working in the cybersecurity sector.

During the raid on August 18, police executed live forensics at Bar's office and home, seizing volatile memory and computing devices. Investigators discovered that Bar had bypassed advanced security barriers by cleverly instructing the AI model to write malicious code without triggering its safety protocols. Once inside, the malware granted him remote access to company networks and personal laptops, allowing him to log keystrokes, steal credentials, and covertly activate webcams and microphones.

The Motive: Technical Drive vs. Voyeurism

During interrogations, Bar defended his actions by citing a "technological drive," claiming he was merely satisfying a curiosity to bypass secure computer systems without demanding ransom or trading stolen commercial secrets. However, forensic analysts flatly rejected this defense. Investigators found folders containing thousands of files, screenshots, and videos documenting female employees and minors in intimate settings, often spied upon while working remotely or even during hotel vacations.

"We didn't buy the narrative of a curious child playing in a playground," said SFC Maayan Peri. "He created bots that allowed him to watch women through their webcams in real-time, invading their most private spaces."

Although the indictment avoids sexual offenses, prosecutors detailed a massive breach of privacy alongside commercial espionage, noting that Bar extracted sensitive data, passwords, and banking information.

Industry Shock and Legal Proceedings

Legal representatives for Bar, attorneys Tamir Calderon and Rami Zoabi, welcomed the exclusion of sexual charges from the indictment, arguing that their client acted out of extraordinary technological capability rather than malicious intent to harm. Meanwhile, state prosecutors Elad Dayan and Havi Lerner from the cyber department submitted a request to detain Bar until the end of legal proceedings, emphasizing the severe risk posed by his advanced malware capabilities. Cybersecurity experts, such as Dr. Harel Menashri of HIT Holon, have criticized the lack of stringent background checks in Israeli tech firms, describing the incident as a classic case of "letting the cat guard the cream."

Related News