Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-disruptiongovernment-diplomatic-threatcritical-infrastructure-threatoperational-disruption

Cyber and electronic-warfare activity escalates amid US–Israeli strikes on Iran

Updated 2mo agoFirst seen Mar 2, 20269 sources

Regional conflict following U.S.–Israeli strikes on Iran has been accompanied by heightened cyber and electronic-warfare activity affecting both military operations and civilian infrastructure. U.S. officials publicly acknowledged that U.S. Cyber Command, alongside space capabilities, conducted “non-kinetic” operations to disrupt Iranian communications and sensor networks in support of Operation Epic Fury, describing effects intended to degrade Iran’s ability to coordinate and respond; reporting also noted follow-on hack-and-leak style activity against Iranian-facing online properties (e.g., news sites and an app) and warned of potential retaliatory cyber activity by Iranian-aligned actors.

In parallel, maritime intelligence reporting described a sharp increase in GPS/AIS disruption (jamming/spoofing) impacting shipping around the Strait of Hormuz, with vessels appearing in false locations and maritime authorities warning of elevated risk to navigation and safety. Iran’s domestic crypto ecosystem also showed signs of stress consistent with conflict conditions and connectivity constraints: observers reported internet outages, exchanges moving into risk-containment modes (e.g., batching/suspending withdrawals), and temporary restrictions on the USDT–toman trading pair under central bank direction—collectively reducing liquidity and market activity rather than clearly indicating capital flight. Separate reporting on Pakistan’s TV broadcast hijacks and a DDoS incident affecting Russian government sites appear unrelated to the Iran conflict-driven activity described above.

Share:
Cyber and electronic-warfare activity escalates amid US–Israeli strikes on Iran
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Mar 2, 20264mo ago

Iranian media claims foreign network gear failed during nuclear-site strikes

On or before 2026-03-02, Iranian state media reported that Cisco, Juniper, MikroTik, and Fortinet equipment malfunctioned or disconnected during U.S. strikes on Iranian nuclear facilities. The report suggested possible hidden backdoors, implanted malware, malicious packet delivery, or supply-chain tampering as explanations for the failures.

Cisco, Juniper gear ‘malfunctioned’ just as US bunker busters hit Iranian nuclear sites: report - SDxCentral

US publicly acknowledges Cyber Command's role in the campaign

On March 2, 2026, Joint Chiefs Chairman Gen. Dan Caine publicly described Cyber Command and Space Command as 'first movers' in the operation against Iran. The remarks were characterized as the clearest public acknowledgement so far of Cyber Command's role in the second Trump administration's major military operations.

Jordan says it thwarted an Iranian cyberattack on wheat storage

Jordan reported blocking an Iranian cyberattack that targeted its wheat storage systems during the regional escalation. The disclosure highlighted spillover cyber activity beyond the immediate U.S.-Iran-Israel conflict.

Feb 28, 20264mo ago

Israeli-linked hacks target Iranian websites and app

After the attacks began, apparent Israeli digital operations defaced Iranian news websites and a religious calendar app with messages encouraging defections and resistance. The activity was described as part of the broader pressure campaign accompanying military strikes.

US Cyber Command and Space Command disrupt Iranian networks

As part of the U.S.-Israeli campaign, U.S. Cyber Command and U.S. Space Command conducted coordinated cyber and space operations against Iranian communications and sensor networks. According to Gen. Dan Caine, these non-kinetic actions degraded Iran's ability to detect, coordinate, and respond ahead of kinetic strikes.

GPS and AIS interference surges across Gulf shipping lanes

Since February 28, more than 1,100 ships across Iranian, UAE, Qatari, and Omani waters experienced GPS or AIS disruption, with some vessels falsely appearing inland on tracking maps. Windward identified about 21 new AIS jamming clusters, and shipping through the Strait of Hormuz nearly halted amid the interference.

Iranian exchanges temporarily halt USDT-toman trading

Under direction from Iran's Central Bank, multiple Iranian exchanges temporarily suspended the USDT-toman trading pair to slow fiat repricing during peak volatility. When trading resumed, thin order books and brief price dislocations were observed.

Iran's internet connectivity collapses and crypto activity drops

Following the February 28 strikes, internet connectivity in Iran fell by roughly 99%, and domestic crypto transaction volume dropped by about 80% between February 27 and March 1. Major exchanges stayed online but reduced withdrawals, thinned liquidity, and issued user risk guidance.

New Persian-language numbers station V32 begins broadcasting

About 12 hours after U.S. and Israeli strikes on Iran began, a new Persian-language numbers station designated V32 reportedly started transmitting nearly twice daily. The broadcasts used a classic covert-communications format, with a male voice reading random numbers after repeating the Persian word "tavajjoh" three times.

Someone is jamming a mysterious Persian shortwave spy signal - Boing Boing

US and Israeli strikes on Iran begin

On February 28, 2026, the United States and Israel initiated strikes on Iran, marking the start of a broader military campaign that coincided with cyber, electronic, and economic disruption across the region.

Jun 1, 20251y ago

Israel-Iran missile exchanges trigger major GPS jamming in the Gulf

During missile exchanges between Israel and Iran in June 2025, significant GPS interference was reported in the Gulf region, establishing a prior pattern of wartime navigation disruption affecting maritime traffic.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

48 LINKEDOpen in app
Malware
1 linked
Affected products
3 linked
FortiosScreenosNetscreen Firewalls
Organizations
37 linked
Juniper NetworksCisco SystemsFortinetMikrotikTom's HardwareTenableStrykerSpirent CommunicationsThe RegisterThe Wall Street JournalTechCrunchPalo Alto NetworksNobitexNetBlocksReutersRadio Free Europe/Radio LibertyTRM LabsGoogleCNBCAmerican Broadcasting CompanyRamzinexZedcexArab NewsInternet ArchiveWindwardAsiatechWallexBitpinTabdealAban TetherARY NewsGeo NewsSamaa TVThe Jerusalem PostThe Express TribuneDawnABP News
SOURCE COVERAGE

Sources

9 references tracked. Mallory keeps watching after this page renders.

9 SOURCESView all
Toms HardwareNews
Apr 22, 2026

Iran claims US exploited networking equipment backdoors during strikes - says devices from Cisco and others failed despite blackout in attack that 'indicates deep sabotage' | Tom's Hardware

tomshardware.com

Open source
ScworldNews
Apr 21, 2026

Iran alleges US cyberattacks; China amplifies claims | brief | SC Media

scworld.com

Open source
UnclassifiedNews
Apr 21, 2026

فارس: طی اتفاقی عجیب و هشدار دهنده، "جعبه‌های سیاه" آمریکایی در ساعت صفر حمله به اصفهان از کار افتادند/ این اختلال در شرایطی رخ داد که گیت‌وی‌های بین‌الملل عملاً مسدود بودند، بنابراین فروپاشی مذکور نشان از یک خرابکاری عمیق دارد/ سناریوی خطرناک، دستکاری در مبدأ تولید است؛ اگر فایل‌های نصبی قبل از ورود به ایران آلوده شده باشند، حتی تعویض سیستم عامل هم مشکل را حل نمی‌کند | سایت انتخاب

entekhab.ir

Open source
BoingboingNews
Apr 1, 2026

Someone is jamming a mysterious Persian shortwave spy signal - Boing Boing

boingboing.net

Open source
Wikipedia Cyber IncidentsNews
Mar 4, 2026

Cyberwarfare during the 2026 Iran war - Wikipedia

en.wikipedia.org

Open source
Sdxcentral CybersecurityNews
Mar 2, 2026

Cisco, Juniper gear ‘malfunctioned’ just as US bunker busters hit Iranian nuclear sites: report - SDxCentral

sdxcentral.com

Open source
Wired Com SecurityNews
Mar 2, 2026

Attacks on GPS Spike Amid US and Israeli War on Iran | WIRED

wired.com

Open source
Trm Labs BlogNews
Mar 2, 2026

How Iran’s Crypto Market is Reacting to Conflict | TRM Blog

trmlabs.com

Open source
The Record MediaNews
Mar 2, 2026

Cyber Command disrupted Iranian comms, sensors, top general says | The Record from Recorded Future News

therecord.media

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.