Verdict
bankhapoalim.co.il appears legitimate.
Our checks found nothing pointing to fraud. Ordinary care still applies when you pay or sign in.
| What this site appears to be | Hebrew-language corporate banking homepage describing Bank Hapoalim services: accounts, loans, credit cards, investments, FX, digital apps, fraud center, community initiatives and customer channels. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | None flagged itVirusTotal | Clear |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 30 years oldRegistered history | Clear |
| Web archive | Archived since 19961491 snapshots | Clear |
| Certificate | Encrypted connectionIssued by GlobalSign Atlas R46 DV TLS CA 2026 Q2 | Noted |
The page as captured
No screenshot is retained for this report.
Key findings
- Automated classification: Not Scam.
- Domain age: more than 10 years (registration continuity).
- Public web-archive history exists since 1996.
- No flags from the reputation services TrustSniffer consulted at assessment time.
Full analysis
Overview
This Hebrew-language website presents Bank Hapoalim’s retail and commercial banking services, including accounts, deposits, loans, mortgages, credit cards, foreign exchange, investments, capital-markets services, digital banking, and customer-support resources. Its apparent business model is conventional banking, generating revenue through interest margins, fees, and service charges.
Scam/Impersonation Risk
No contradictions were observed across the supplied evidence: there is no confirmed phishing, impersonation, blacklist, or conflicting legal-identity signal. The homepage is consistent with a mature corporate-bank presentation, with coherent banking content and no detected sensitive form, hidden form, wallet activity, cloaking, or suspicious script behavior. One external reputation classification was marked suspicious, but it was isolated, carried no malicious determination, and was not corroborated by the other available reputation or page-level signals; it therefore remains a limited reputational anomaly rather than evidence of a scam.
- The homepage identifies a corporate banking service and presents accounts, loans, deposits, credit cards, investments, foreign exchange, mortgages, digital applications, fraud support, branches, and customer channels; no page-level red flags were recorded.
- Behavioral inspection of the homepage recorded no login form, hidden form, password submission to an external destination, wallet connection, clipboard hijacking, cloaking, or suspicious inline scripts.
- Domain registration continuity: 1996 (~29.64 years old).
- Web-archive coverage: 1,491 snapshots spanning 1996–2026 (31 years tracked), with a maximum gap of 3 years.
Regulatory Verification Notes
The site’s apparent banking identity and service presentation are consistent with an established financial institution, but the real-world operator identity is not independently verified by the supplied evidence. The homepage content does not present a licensing authority or license number, so applicable banking authorization remains a disclosure and verification matter rather than a finding of misconduct. The site’s transport and hosting telemetry are technically coherent, while the isolated external suspicious classification should be treated only as a soft reputational signal. No matching third-party broker record was identified.
- The homepage is titled “Bank Hapoalim” and describes retail and commercial banking services, customer accounts, lending, payment products, investments, foreign exchange, and digital banking.
- No license authority or license number is presented in the supplied homepage and business-model content.
- Hosting telemetry identifies AS19551 operated by INCAPSULA - Incapsula Inc, US.
- TLS uses GlobalSign Atlas R46 DV TLS CA 2026 Q2 with DV validation, valid to 2026-09-24.
What to Verify Next
Before credential or payment interactions, an institution should independently confirm that the legal operator and applicable banking authorization correspond to the intended Bank Hapoalim entity, using an authoritative financial-services registry or an independently sourced institutional contact route. Account-entry and transaction activity should be initiated only through independently confirmed official channels, with applicable payment-protection and dispute procedures reviewed in advance.
- The homepage provides branch and customer-contact pathways that can be compared with independently sourced institutional details.
- The supplied page analysis found no sensitive form submission during observation, so the legitimacy of any later account-entry or transaction flow should be assessed separately at the point of use.
Summary Verdict
The overall posture is high trust and low risk, and the available evidence is consistent with an established, apparently legitimate website. This conclusion supports ordinary business engagement in principle, while the site’s real-world operator identity remains independently unverified.
Infrastructure Integrity
The website is protected by Incapsula CDN/WAF infrastructure, with the observed address functioning as a CDN edge endpoint and no origin candidate identified in the analysis. This managed edge architecture is a mitigating control that reduces direct exposure of the underlying service, but it is not, by itself, proof of institutional legitimacy.
Closing Assessment
Proceed with normal institutional diligence, independently confirming the intended operator and applicable protections before submitting credentials, initiating payments, or undertaking material financial activity.
Written analysis generated 2026-08-11 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
No rule findings contributed to this verdict.
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of bankhapoalim.co.il.
- The request stayed on bankhapoalim.co.il. It was not redirected to another domain. Clear
- The earliest public archive of this site is from 1996-12-19. Clear
- It is hosted on INCAPSULA, from a server in US. Noted
Domain intelligence
| Registrar | Not available |
|---|---|
| Hosting | INCAPSULA - Incapsula Inc, US |
| Country | US |
| Server IP | 45.60.207.1 |
| Name servers | Not available |
| SSL issuer | GlobalSign Atlas R46 DV TLS CA 2026 Q2 |
| SSL expiry | 2026-09-24 |
| Domain age | 29.64 years (continuous registration) |
| Domain expiry | Not available |
| Archive first seen | 1996-12-19 |
| Archive snapshots | 1491 |
| Reputation | VirusTotal: 0 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about bankhapoalim.co.il at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.