TI-2026-034H โ€” Part 8 of "The Invisible Nation" series

The Playbook

Israeli Corporate Fraud as Infrastructure Maintenance: A 40-Year Pattern

THESIS: A documented pattern spanning four decades: Israeli intelligence-connected individuals and companies use cycles of fraud, bankruptcy, corporate restructuring, and acquisition to build, maintain, and obscure control of critical surveillance infrastructure. The fraud is not incidental โ€” it IS the mechanism by which ownership is obscured, liability is shed, and capability persists under new names.

Total documented fraud value: >$10 billion

Infrastructure dismantled: None of it

ERA 1: The Template โ€” PROMIS (1983-1991)

In 1983, Rafi Eitan โ€” Mossad operations chief, handler of convicted spy Jonathan Pollard โ€” visited the offices of Inslaw Inc. in Washington, D.C. Inslaw had developed PROMIS (Prosecutor's Management Information System) for the U.S. Department of Justice. It was a case management tool. Revolutionary for its time.

What happened next was documented by the House Judiciary Committee, by federal court findings, and by sworn affidavits from Ari Ben-Menashe (former Israeli military intelligence officer):

The PROMIS Operation

  • DOJ stole PROMIS from Inslaw (federal court finding)
  • Israeli intelligence modified the software with a covert backdoor enabling remote data extraction from any system running the compromised version
  • Robert Maxwell โ€” Czech-born British media baron, alleged Mossad agent โ€” became the worldwide distributor
  • PROMIS was sold to 40+ intelligence agencies, all unknowingly reporting to Israel
  • Maxwell also sold bugged PROMIS to Los Alamos and Sandia National Laboratories (U.S. nuclear weapons facilities)

The resolution: Maxwell "drowned" falling from his yacht Lady Ghislaine in November 1991. Named for his daughter โ€” who would later become the most famous associate of Jeffrey Epstein. Inslaw went bankrupt. The software's capability lived on under new names.

Maxwell's FBI file โ€” obtained through FOIA by MuckRock in 2017 โ€” contains withheld materials describing "Maxwell accessing an NSA database with information on tapping government databases." The file is getting more classified over time, not less.

TEMPLATE ESTABLISHED:

  1. Steal critical software from legitimate developer
  2. Add surveillance backdoor
  3. Use intelligence-connected businessman as distributor
  4. When exposed: distributor dies/disappears, original developer bankrupted
  5. Capability persists

ERA 2: The Telecom Penetration (1990s-2000s)

By the early 2000s, three Israeli-founded companies had achieved something unprecedented: complete coverage of the United States telecommunications infrastructure.

Comverse Technology โ€” The Wiretap Maker

Founded 1984 in Israel. CEO: Jacob "Kobi" Alexander, former Israeli military officer. Comverse built the CALEA-compliance equipment โ€” the literal boxes that execute lawful intercept wiretaps for U.S. carriers. They were inside every major telecom provider.

In a rare admission to Forbes, Retired Brigadier General Hanan Gefen, former commander of Unit 8200 (Israel's NSA), confirmed his organization's influence on Comverse, which "weights [sic] heavily."

In December 2001, Fox News correspondent Carl Cameron produced a four-part investigation documenting the penetration. Sources told Cameron that "while various FBI inquiries into Comverse have been conducted over the years," the inquiries had "been halted before the actual equipment has ever been thoroughly tested for the presence of a back door."

The investigation was subsequently removed from Fox News's website. It survives on Internet Archive.

The Comverse Fraud

  • 2006: Alexander charged with securities fraud (stock option backdating, $2.4B+ fraud)
  • Fled to Namibia with family and laundered millions
  • Lived in exile for 10 years
  • 2016: Returned to U.S.
  • 2017: Sentenced to 30 months (DOJ Eastern District of New York)
  • 2018: Transferred to Israeli prison, sentence cut by Israeli authorities

The fraud destroyed the company. But the capability survived: Comverse split into Verint Systems (surveillance/intelligence products) and NICE Systems (call recording). Verint continues to provide surveillance equipment to this day.

Narus โ€” Room 641A

Founded 1997 in Israel by Ori Cohen. Narus made the equipment in the NSA's secret Room 641A at AT&T's facility at 611 Folsom Street, San Francisco.

Discovered by AT&T technician Mark Klein in 2003 (public 2006): a fiber-optic splitter copied all internet traffic into the secret room, where NarusInsight performed real-time analysis. Seven additional AT&T facilities with similar rooms were identified.

In 2010, Narus was acquired by Boeing โ€” a cleared defense contractor. The capability went from Israeli startup to U.S. military-industrial complex.

Amdocs โ€” The Metadata Layer

Founded 1982 by Morris Kahn and Boaz Dotan (former head of Israel's Department of Information). "Most directory assistance calls, and virtually all call records and billing in the U.S. are done for the phone companies by Amdocs Ltd., an Israeli-based private telecommunications company."

FBI counterintelligence opened an inquiry into whether Israeli agents used Amdocs to intercept telephone calls from the White House. The NYT reported in 2000: "Israeli Spy Inquiry Finds Nothing, Officials Say." The investigation was stopped โ€” not concluded.

FBI investigators were "particularly unnerved" to discover the Israeli subcontractor had obtained the FBI's "most sensitive telephone numbers."

THE TELECOM TRIANGLE (Operational Today)

CompanyAccess VectorStatus
Verint (ex-Comverse)Taps communications at VerizonActive
Narus (Boeing)Taps AT&T (Room 641A+)Active
AmdocsBilling/metadata for ALL carriersActive ($4.2B revenue)

All three remain operational. No backdoor was ever officially found because no investigation was allowed to complete.

ERA 3: The Privacy Capture (2010s-Present)

Teddy Sagi. Convicted of securities fraud in Israel, 1996. Served prison time. Then built a $5.6 billion empire.

Through his investment vehicle Unikmind Holdings (Jersey-registered), Sagi acquired majority control of Crossrider Ltd โ€” a company that made adware and malware. The co-founder: Koby Menachemi, a veteran of Unit 8200.

In 2018, Crossrider rebranded to Kape Technologies. Then began an acquisition spree unprecedented in the privacy industry:

The Kape Acquisitions

YearTargetPrice
2017CyberGhost VPN$10.4 million
2019Private Internet Access (PIA)$95.5 million
2019vpnMentor + Wizcase (review sites)Undisclosed
2021ExpressVPN$936 million
2022ZenMateUndisclosed

Total VPN investment: ~$1.04 billion. Users captured: 6+ million.

The Daniel Gericke Problem

ExpressVPN's Chief Information Officer, Daniel Gericke, was one of three former U.S. intelligence operatives who worked on Project Raven โ€” a surveillance operation conducted for the United Arab Emirates by DarkMatter. Project Raven hacked journalists, human rights activists (including Saudi activist Loujain al-Hathloul), and rival governments.

Gericke agreed to pay $335,000 and cooperate with the FBI as part of a Deferred Prosecution Agreement. ExpressVPN publicly confirmed they hired him knowing "the key facts relating to Daniel's employment history."

This is the person securing your VPN traffic. Hired by a company owned by a convicted fraudster. With Unit 8200 co-founders.

The Delisting

In 2024, Kape Technologies was taken private for $1.6 billion โ€” delisted from the London Stock Exchange. No more public filings. No more shareholder meetings. No more journalist questions at earnings calls.

A convicted securities fraudster's company โ€” with Unit 8200 founders and a CIA/DarkMatter-trained CIO โ€” now controls the internet traffic of millions of people who believe they have privacy. And there is no longer any mechanism for public scrutiny.

THE KAPE PLAYBOOK:

  1. Convicted felon buys malware company
  2. Unit 8200 veteran co-founds it
  3. Rebrand (Crossrider โ†’ Kape)
  4. Acquire legitimate brands ($1B+ in VPNs)
  5. Hire intelligence operative as CIO
  6. Buy the review sites that rate your own products
  7. Take private โ€” escape all scrutiny
  8. 6 million users' traffic under intelligence-adjacent control

ERA 4: The Spyware Shell Game

NSO Group โ€” Pegasus Never Dies

Founded 2010 by three Unit 8200 alumni. Product: Pegasus โ€” a zero-click mobile exploitation tool that can compromise any smartphone without user interaction.

The financial history tells the story:

NSO Ownership Timeline

  • 2014: Sold to Francisco Partners (US PE) for ~$120M
  • 2019: Sold to Novalpina Capital (UK/Luxembourg PE) for ~$1B
  • 2020: Novalpina's LP investors rebel โ€” fund seized by advisory committee
  • 2021: US Commerce Dept places NSO on Entity List (sanctions)
  • 2023: Ownership โ†’ Luxembourg holding wholly owned by founder Omri Lavie
  • 2025: $168 million verdict to Meta (WhatsApp hack of 1,400 users)
  • 2025-2026: Acquired by US investors โ€” "American investment group invested tens of millions"

Throughout ALL of this: Pegasus remained operational. Governments continued deploying it against journalists, activists, and political opponents. The corporate shell changed five times. The weapon never stopped.

Paragon Solutions โ€” The Next Iteration

Co-founded by former Prime Minister Ehud Barak and Unit 8200 veterans. Product: Graphite โ€” zero-click extraction of encrypted messages from Signal, WhatsApp, and Telegram.

December 2024: Acquired by AE Industrial Partners (RED Lattice, US) for over $500 million. Delaware corporation established 2021, Virginia business certificate 2022. U.S. ICE director admitted authorizing spyware use โ€” then DHS denied any contract exists.

The same pattern: Israeli weapon โ†’ U.S. acquisition โ†’ U.S. government deployment โ†’ plausible deniability.

ERA 5: The Political Machinery

The fraud is not parasitic on the system. The fraud IS the system.

Case 4000 โ€” The Telecom-State Merger

Benjamin Netanyahu simultaneously held the offices of Prime Minister and Communications Minister from 2014 to 2017. He allegedly traded โ‚ช1 billion ($296 million) in regulatory benefits to Bezeq โ€” Israel's largest telecom company โ€” in exchange for favorable media coverage on Walla! (owned by Bezeq shareholder Shaul Elovitch).

The person regulating Israel's telecom infrastructure was simultaneously the person being bribed by its largest player. The regulatory capture was complete: there was no separation between state and telecom to capture.

Case 3000 โ€” Nuclear Submarines Through Bribery

Israel purchased three Dolphin-2 class submarines and four Sa'ar 6 corvettes from German shipbuilder ThyssenKrupp for $2.7 billion โ€” double the normal price. Miki Ganor, the Israeli agent for ThyssenKrupp, admitted to bribing senior Israeli officials to secure the contracts.

An official inquiry found "systemic failings that endangered state security." These are nuclear-capable submarines โ€” Israel's second-strike deterrent โ€” and they were acquired through systematic corruption. Yair Lapid called it "the worst corruption case in Israeli history."

The Dankner Pyramid

Nochi Dankner controlled IDB Holdings โ€” Israel's largest conglomerate โ€” through a four-tier pyramid structure that gave him control over โ‚ช15 billion in assets while owning only a small minority of shares. He controlled Clal Insurance, Bank Hapoalim, Cellcom, Super-Sol. Convicted of market manipulation. The Anti-Concentration Law was passed in 2013 specifically to prevent his model from recurring.

"I lost something that was never truly mine," Dankner admitted. He was also a board member of the Jewish Agency for Israel โ€” the state-diaspora apparatus.

The Architecture: Why It Never Dies

Across forty years, four patterns repeat with variations. Each is optimized for a specific function:

THE FOUR PATTERNS

Pattern A โ€” Steal-Backdoor-Distribute-Kill:
Steal critical software โ†’ add backdoor โ†’ sell via intelligence-connected distributor โ†’ when exposed, eliminate distributor โ†’ capability persists. (PROMIS, 1983)

Pattern B โ€” Build-Fraud-Split-Persist:
Build surveillance company โ†’ achieve critical mass in US infrastructure โ†’ CEO commits massive fraud โ†’ company splits โ†’ surveillance arm continues under new name โ†’ FBI investigation halted. (Comverseโ†’Verint, 2006)

Pattern C โ€” Rebrand-Acquire-Delist:
Convicted felon buys malware company โ†’ rebrand โ†’ acquire legitimate brands ($1B+) โ†’ hire intelligence operatives โ†’ buy review sites โ†’ take private โ†’ no oversight. (Crossriderโ†’Kape, 2018-2024)

Pattern D โ€” PE-Leverage-Sanctions-Restructure-Sell:
Build weapon โ†’ sell to Private Equity โ†’ extract value โ†’ sanctions/collapse โ†’ restructure through holding companies โ†’ sell to US investors โ†’ weapon operational throughout. (NSO, 2010-2026)

The common thread: the capability always survives. The individuals serve minimal time or escape entirely. The investigations are halted for "diplomatic reasons." The money flows through jurisdictions that prevent tracing. And Unit 8200 alumni appear at every node.

FINANCIAL SUMMARY

EntityPeak ValueFraud/ScandalSurvived As
PROMIS/InslawDOJ systemStolen by DOJ/MossadStill deployed (modified)
ComverseS&P 500$2.4B fraud, CEO fledVerint + NICE
Amdocs$4.2B revenueFBI inquiry droppedStill handles all US billing
NarusRoom 641ANSA warrantless wiretapBoeing subsidiary
NSO Group~$1BUS sanctions + $168M verdictUS investor acquisition
Kape$1.6B takeoutCEO convicted fraudsterPrivate, 6M users

Connection to the Series

This is the financial engine behind everything documented in 034A through 034G:

  • 034A (The Empty Column): Israel's absence from honeypot data = the product model works perfectly
  • 034B (The Invisible Infrastructure): Kamatera's multi-entity pattern follows the Comverse playbook
  • 034C (The Privacy Empire): Kape IS the fraud-to-VPN pipeline
  • 034D (The Graduation Ceremony): Unit 8200 โ†’ startup pipeline FUNDED by these mechanisms
  • 034E (The Customer Model): NSO's PE shell game IS the customer model's financing
  • 034F (The Submarine Cables): Case 3000 submarine corruption = same network
  • 034G (The Complete Map): This is Layer 7 (financial/legal) of the seven-layer architecture

034H answers the question the entire series has been building toward: How is all of this paid for, and why does it never die?

The answer: the fraud IS the operating system. Each bankruptcy is a controlled demolition. Each delisting is a disappearing act. Each restructuring sheds liability while preserving capability. And the people who should investigate โ€” FBI, DOJ, FINRA โ€” stop every inquiry before it reaches the hardware.

Forty years. Same playbook. Different names. Same outcome: the capability survives, and the watchers remain invisible.

Primary Sources

Court Documents: DOJ EDNY (Alexander sentencing), House Judiciary Committee (PROMIS), Israel Police (Cases 3000/4000), US Commerce Dept (NSO Entity List), DOJ DPA (Gericke/Project Raven), Meta v. NSO ($168M verdict), Israel Anti-Concentration Law (2013)

Investigative Journalism: Wired/James Bamford (2012), Fox News/Carl Cameron (2001, censored), Reuters (Project Raven, 2019), Times of Israel, Haaretz, Forbes, MuckRock (Maxwell FBI file FOIA)

Corporate Records: Kape Technologies LSE filings (pre-delisting), NSO ownership chain (Francisco Partnersโ†’Novalpinaโ†’Luxembourg holdingโ†’US investors), Paragon Solutions (Delaware incorporation 2021)

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Invisible Nation โ€” 8 / 8 Next โ†’