Yossi Amara, CEO of IT4U computer services, thought he was starting a regular, uneventful Sunday workday. Quickly, multiple customer complaints disrupted the routine, as they experienced difficulties connecting to their computer infrastructure. Amara began investigating the issue and noticed that through a third-party system used by the company, 133 megabytes of files were copied from a database of 100 gigabytes. "At first, it looked like a routine data transfer, so we had doubts," he explains. "It seemed like a relatively small amount of data, and it wasn't clear if it was a real threat or a false positive, but very quickly what seemed like a normal workday turned into a technological nightmare. We were hit by a massive cyber-attack of unprecedented intensity. The screens flickered with strange messages, the printers spat out pages with Hamas messages; it was already clear this was no passing glitch.".

"In the evening, at 8:30 PM, we received an alert from the cyber defense system that information was being transmitted to an IP address identified as a hostile attack surface. It turned out that we were facing hackers representing Handala, a group identified with Iran. The company I had successfully managed for a full decade was facing the greatest challenge it had ever experienced. At 10:00 PM, we received inquiries from additional clients who were having trouble connecting to their offices; some were unable to see their network drives. We began to take action, but moment by moment, the chaos intensified. I realized that to overcome this difficulty, I needed help.
What were the first steps you took?
"The first step was to stop the spread and establish a situation assessment. We blocked access to storage services, changed passwords on all critical systems, disconnected backups from the network, and blocked suspicious IP addresses. In parallel, we contacted the Cyber Directorate and the response team of Horizon who helped us to take control of the event as quickly as possible.".
How long did it take you to stabilize the system and return to normal?
"It was a race against time. Our team worked around the clock, alongside Horizon's experts. By Wednesday afternoon, after nearly four sleepless days, we managed to restore most services to our clients. These are businesses that depend on our infrastructure, so prolonged system downtime was out of the question.".
How did you experience the event from an organizational standpoint? What did you learn from it?
"Beyond the technological challenge, it was administratively and emotionally challenging. I admit it took me a moment to collect myself. It's a moment when you feel like everything is closing in on you – the responsibility, the consequences, the pressure – but I knew I had no choice but to act calmly, and that's not easy, not at all. I couldn't have won this battle alone. It required cooperation with IR experts and skilled response teams. Fortunately, the partners I chose for this journey, the cyber company, Ofek, from whom I purchase products, was the army that stood by my side when I was under attack. Therefore, choosing the right partner is critical.
"The second significant thing is the information security products you choose. Money is a consideration, but it shouldn't be the only one. When push comes to shove, you realize you need to work with the best solutions. In our case, Cove backup from N-able quite literally saved the company. This applies to any security product you choose – on the day of reckoning, you want to know you made the right choice. The incident highlighted for us the importance of smart backups, permission management, and the use of advanced systems for monitoring and response. The Cove platform allowed us to quickly restore data for all affected customers. Thanks to this, we were able to phenomenally minimize damage and prevent the loss of critical information.
"One more very important thing that I learned He stated that an IT company cannot be a cybersecurity company. There was some notion that if I sell products to clients, then I am also responsible for ensuring their organization is protected. Today, after the attack, I understand that I must clarify this point with clients.
This is a significant point that still affects many IT providers. Could you please elaborate?
"After the event, I realized there was a lack of clarity regarding product supply and cyber consulting services. A client buying a security product does not mean they have bought assurance that their business will be safe from any harm. If a client is unwilling to invest in a basic set of products that I believe in, I do not take responsibility for them. I also make that clear to them. Because ultimately, to maintain true security resilience, a certain standard must be met. And if I am to be the one held responsible, I must ensure that the foundation upon which I work is strong enough. I have learned to reflect this, I have learned to price it, and I have learned to turn it into a suite of cyber consulting services.
"Today, if my client wants to be truly protected, they can't just settle for purchasing security products – they also need a full suite of supporting services. This includes a response team that I know how to deploy in real-time, penetration tests that are essential for identifying vulnerabilities before hackers do, and raising employee awareness, because they are often the weak link in the security chain. It all starts with a clear standard – and if it's met, real resilience can be built. Following this realization, I now choose my clients. It might be surprising to hear, but not every business interested in my services becomes a client.
What steps have you taken to prevent similar attacks in the future?
"Immediately after the incident, we performed a comprehensive upgrade of our defense systems. We integrated solutions SentinelOne by N-able EDR, we upgraded the firewalls, added an RMM system for update management, and implemented Cove's cloud backup solution, which allows us to quickly restore data in case of an attack. In addition, we have started performing periodic penetration tests for all clients to identify vulnerabilities before hackers do.
What is the most important thing you learned from this event?
"The cyberattack that hit my company wasn't just a crisis event – it was a defining moment that clarified for me what truly matters in the world of information security. I learned that there's no room for compromise in two main areas: your partners and the products you choose. The right distribution company, as well as high-quality backup and security solutions, can be the difference between a swift recovery and complete collapse. I hope no one finds themselves in this situation – but if they do, it's best to be prepared.
Recommendations for strengthening cybersecurity
Amara shares several recommendations for any MSP looking to strengthen their clients' cybersecurity:
- Don't wait for an event, act in advance. Invest in monitoring, backup, and permission management systems before the incident occurs.
- Maintain a professional and available response team. Engaging with an IR firm or a rapid response service provider can save a lot of time and damage.
- Practice your team – Training employees and company management on how to act during an incident is critical to minimizing damage.
- Implement a robust and reliable system, such as COVE backup, as well as an advanced SOC Siem system – Following the incident, the company integrated the N-able Adlumin system, which enables rapid real-time threat monitoring and response. This is a critical step for any company that wants to elevate its cyberattack defenses.
Ofek Dist is a leading cyber consulting and distribution company, operating since 2006 and specializing in supporting IT providers and MSSPs in Israel. The company offers a unique combination of advanced information security products and professional consulting services, tailored to the complex needs of local organizations. Ofek's team of experts assists organizations in meeting regulations, improving organizational resilience, responding to cyber incidents, and raising employee awareness, while actively participating in professional training, conferences, and workshops throughout the country.