034A โ The Empty Column
Seven IPs. Zero Hits. The World's Most Capable Cyber Nation Leaves No Fingerprints.
Executive Summary
Our threat intelligence database contains 8,000+ attacker IPs from over 100 countries. We have published 30 forensic dossiers examining Chinese cloud providers (031), American hosting companies (032), and everything in between. Every country with significant internet infrastructure produces a measurable attack footprint.
Every country except one.
Israel โ home to Unit 8200 (the NSA's closest equivalent), NSO Group (Pegasus), Candiru, Paragon Solutions, Cellebrite, and over 500 cybersecurity companies that raised $3.8 billion in 2024 alone โ appears in our database with exactly 7 IPs and zero honeypot hits.
This is not a gap. This is a finding.
The Statistical Anomaly
To understand how extraordinary Israel's absence is, compare it to countries with similar or smaller populations:
| Country | Population | IPs in DB | Avg Threat | Honeypot Hits | Hits/IP |
|---|---|---|---|---|---|
| ๐ณ๐ฑ Netherlands | 17.9M | 375 | 44.3 | 2,715 | 7.2 |
| ๐ธ๐ฌ Singapore | 6.0M | 253 | 43.6 | 1,095 | 4.3 |
| ๐ง๐ฌ Bulgaria | 6.5M | 38 | 35.2 | 316 | 8.3 |
| ๐ฆ๐ช UAE | 10.0M | 33 | 22.1 | 74 | 2.2 |
| ๐จ๐ฟ Czech Rep. | 10.9M | 25 | 26.5 | 41 | 1.6 |
| ๐ญ๐บ Hungary | 9.6M | 19 | 30.3 | 9 | 0.5 |
| ๐ฑ๐ป Latvia | 1.8M | 12 | 39.2 | 61 | 5.1 |
| ๐ช๐ช Estonia | 1.4M | 10 | 43.2 | 65 | 6.5 |
| ๐ฎ๐ช Ireland | 5.3M | 7 | 60.4 | 76 | 10.9 |
| ๐ฎ๐ฑ Israel | 9.8M | 7 | 30.3 | 0 | 0.0 |
| ๐ฑ๐น Lithuania | 2.9M | 6 | 46.3 | 60 | 10.0 |
The Ireland Comparison
Ireland and Israel have identical IP counts in our database: 7. Ireland has half the population. Yet Ireland produces 76 honeypot hits. Israel produces zero. Same sample size, same database, same timeframe. The difference: 76 to 0.
Estonia โ a country of 1.4 million people โ has 10 IPs generating 65 hits. Lithuania โ 2.9 million โ has 6 IPs generating 60 hits. Latvia โ 1.8 million โ 12 IPs, 61 hits. The Baltic states, combined population 6.1 million, produce 186 honeypot hits from 28 IPs.
Israel, population 9.8 million, with the world's highest per-capita concentration of cyber capability: zero.
The Seven IPs: What They Are
The seven Israeli IPs in our database tell their own story โ not by what they are, but by what they aren't.
| IP | ASN | Provider | Type | Threat | Hits |
|---|---|---|---|---|---|
| 82.102.188.117 | 12400 | Partner Communications | Consumer ISP | 69 | 0 |
| 37.25.36.197 | 16116 | Pelephone Communications | Mobile ISP | 53 | 0 |
| 80.250.155.76 | 1680 | Cellcom Fixed Line | Consumer ISP | 52 | 0 |
| 130.185.96.125 | 16116 | Pelephone Communications | Mobile ISP | 10 | 0 |
| 2.55.70.124 | 12400 | Partner Communications | Consumer ISP | 10 | 0 |
| 185.181.10.136 | 204548 | Kamatera/CloudWebManage | Cloud Hosting | 10 | 0 |
| 185.191.204.254 | 35758 | HQServ Networks | Small Hosting | 8 | 0 |
No Hosting Infrastructure
Five of seven Israeli IPs belong to consumer and mobile ISPs โ Partner Communications, Pelephone, Cellcom. These are residential and mobile connections, not server infrastructure. They appear in threat databases because they were likely compromised endpoints โ infected home routers or phones โ not deliberate attack infrastructure.
The single cloud IP (Kamatera/CloudWebManage) is registered as US-based (Kamatera Inc, US) despite being geolocated to Israel. It has zero honeypot hits.
Compare this to any other country we've studied: China had Alibaba, Tencent, Huawei cloud farms. The US had DigitalOcean, OVH, ColoCrossing server infrastructure. Germany had Contabo, Hetzner. Israel has consumer phone lines.
The Cyber Superpower That Isn't There
Israel is not a minor player in cyber. It is, by several measures, the world's most concentrated cyber power per capita:
- Unit 8200 โ Israel's signals intelligence corps, roughly NSA-equivalent but in a country with mandatory military service. Nearly 50% of founders whose companies were acquired for $1B+ are Unit 8200 alumni (Calcalist, 2025).
- $85 billion in Israeli high-tech exports in 2025 (Startup Nation Central). Cyber exits alone: $4.4 billion.
- Five US-listed Israeli cybersecurity companies collectively valued at $160 billion as of 2024 โ including Check Point, CyberArk, and the pre-exit Wiz.
- Over 1,400 Israeli intelligence veterans working in US Big Tech as of June 2025, with 900 from Unit 8200 alone (Drop Site News).
- Offensive cyber exports controlled directly by the Israeli Ministry of Defense via export licensing โ Pegasus (NSO), Predator (Intellexa, Israeli-founded), UFED (Cellebrite, sold to 150+ countries).
This is a nation that produces more cyber capability per square kilometer than anywhere on Earth. And in our 8,000+ IP threat intelligence database, it is statistically invisible.
Three Hypotheses for the Absence
Hypothesis 1: The Customer Model
China builds cloud infrastructure and tolerates the attacks that come from it. Alibaba doesn't sell Pegasus โ it sells VMs that attackers happen to rent. The infrastructure is the product, and abuse is an externality.
Israel builds the weapon and sells it to governments. NSO Group doesn't brute-force SSH servers โ it sells zero-click exploits to intelligence agencies. Candiru sells browser exploits to law enforcement. Paragon sells "ethical" interception to democratic governments. The tool is the product, not the service.
You don't find Israeli IPs in honeypot data because Israeli offensive cyber doesn't need honeypots. They're selling Pegasus at $500,000 per target, not spraying root:123456 across the internet.
Hypothesis 2: The Offshore Architecture
Even Kamatera โ Israel's only notable cloud provider in our data โ registers as "Kamatera Inc, US" across four ASNs with four different names: KAMATERA (AS36007), CLOUDWEBMANAGE-SC (AS396948), CloudWebManage-EU (AS41436), CLOUDWEBMANAGE-IL-FR (AS204548). An Israeli-founded company with 22+ data centers that appears in every registry as American.
This is not unique to Kamatera. Check Point (NASDAQ: CHKP) is incorporated in Israel but headquartered in both Tel Aviv and San Carlos, CA. CyberArk (NASDAQ: CYBR) trades on NASDAQ. Wiz was acquired by Google for $32 billion โ a US transaction. The Israeli cyber industry exports through US corporate wrappers.
If you're looking for "Israeli infrastructure" in BGP tables, you largely won't find it. It exists inside AWS, Azure, GCP, and US-registered entities.
Hypothesis 3: Operational Sophistication
The simplest explanation may be the most disturbing: you don't see Israeli cyber activity in honeypot data because you're not supposed to.
Unit 8200 doesn't train people to brute-force SSH with password lists. It trains them to find zero-days, write kernel exploits, and compromise targets without leaving network traces. The graduates who go into commercial cyber take those skills with them.
Our honeypot captures SSH brute-force attacks โ the digital equivalent of trying every key on a keyring. Israeli offensive capability operates at the level of picking locks you didn't know existed. The detection ceiling is different. Not higher โ orthogonal.
The Sophistication Ceiling
Consider what each ecosystem produces:
- Chinese infrastructure (031 series): 237 IPs brute-forcing SSH. Cost to operate: ~$500/month in cloud VMs.
- American infrastructure (032 series): 1,028 IPs brute-forcing SSH. Cost: ~$2,000/month.
- Israeli offensive products: Pegasus costs $500,000 per target. Paragon exited at ~$1 billion. NSO was valued at $1 billion before US blacklisting.
These are not the same industry. One sells cloud compute by the hour. The other sells intelligence capability by the target. They share the word "cyber" and nothing else.
The Conspiratorial Layer
Questions That Data Cannot Fully Answer
Why does a country with mandatory military service and mandatory cyber training produce zero visible attack traffic?
Every Israeli citizen does military service. A significant percentage pass through intelligence units. Israel has the world's highest per-capita trained offensive cyber workforce. Yet zero of them leave fingerprints in global honeypot networks. Either the training is so good that no one makes amateur mistakes, or the operational infrastructure is deliberately designed to be invisible.
If 900+ Unit 8200 alumni work at Microsoft, Google, Amazon, and Palo Alto Networks โ where does their infrastructure run?
As of June 2025, Drop Site News documented 1,400+ Israeli intelligence veterans in US Big Tech. These individuals have deep access to the cloud platforms that host everyone's infrastructure. Israeli offensive cyber doesn't need its own ASNs when it has senior engineers inside every major cloud provider.
Why was Candiru acquired by a US "special operations-affiliated" investment firm?
In 2025, Integrity Partners โ described as affiliated with US special operations โ acquired the blacklisted Israeli spyware firm Candiru for $30 million. The assets were transferred to a new entity. When a US military-adjacent fund acquires Israeli spyware capability, the question isn't about Israel anymore.
Does Kape Technologies' control of 4 major VPNs + 2 review sites constitute infrastructure control?
Kape Technologies (formerly Crossrider, an adware company) now owns ExpressVPN ($936M), CyberGhost, Private Internet Access, and ZenMate โ plus vpnMentor and Wizcase, the review sites that recommend them. The co-founder served in Unit 8200. The investor was convicted of securities fraud. They control both the privacy tools and the editorial that directs users to them. This is a different kind of infrastructure โ one that shapes where traffic flows rather than where it originates.
Is zero evidence the strongest evidence of all?
In forensic intelligence, absence of expected data is itself a signal. When a nation that produces more cyber capability than any other per capita leaves zero trace in a database that captures thousands of IPs from far less capable nations, there are only two explanations: they're not participating, or they're too good to be caught. Neither explanation is comforting.
What This Series Investigates
The remaining letters in this series will examine:
- 034B โ The CloudWebManage Layers: Kamatera's 4 ASNs, 4 entity names, and 3 countries. How an Israeli-founded company becomes statistically invisible through US registration.
- 034C โ The Privacy Empire: Kape Technologies' journey from adware to VPN monopoly. Unit 8200 co-founder, convicted-fraudster investor, and editorial capture.
- 034D โ The Graduation Ceremony: The Unit 8200 โ commercial pipeline. NSO, Candiru, Paragon, Cellebrite. Military intelligence as startup incubator.
- 034E โ The Customer Model: Why Israel doesn't appear in attack data. The product IS the weapon โ you sell the gun, you don't pull the trigger.
- 034F โ The Infrastructure You Can't See: Where Israeli cyber companies actually host. AWS, Azure, GCP โ hiding inside the hyperscalers.
- 034G โ The Review Site Problem: When one company owns both the privacy tools and the publications that recommend them.
- 034H โ The Two Doctrines: China builds the cloud, tolerates the attack. Israel builds the tool, sells the attack. Same compromised internet, opposite architectures.
Methodology
This analysis draws on the LSN Threat Intelligence Platform (8,000+ IPs, 271K+ entity links, 30 published dossiers), AbuseIPDB, Shodan, GreyNoise, RDAP/WHOIS, OTX AlienVault, PeeringDB, and open-source intelligence from Startup Nation Central, Calcalist, Drop Site News, INCYBER, and other cited sources. Country comparisons use the same database, same timeframe, same methodology applied in the 031 (Chinese) and 032 (American) series. All seven Israeli IPs were verified through deep enrichment from 6+ independent sources.