Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationfinancial-sector-threatcritical-infrastructure-threatindustrial-control-system-vulnerability

Heightened Cyber Risk to US Financial Services and Critical Infrastructure Amid Iran-US Conflict

Updated 3mo agoFirst seen Mar 5, 20264 sources

US financial services and critical infrastructure operators have moved to heightened vigilance amid escalating Iran–US conflict, with industry groups and analysts warning that geopolitical shocks often correlate with increased cyber activity. Reuters reporting cited by teiss says US intelligence assesses Iran-aligned hacktivists could conduct low-level attacks against US networks—particularly DDoS—and that banks are increasing monitoring and resilience measures given the sector’s role in payments, clearing/settlement, and market infrastructure.

Separate threat research argues the conflict environment increases the likelihood of ICS/OT-focused activity, emphasizing that US critical infrastructure presents an attractive retaliation surface due to civilian impact and a large internet-exposed OT footprint. CloudSEK highlights rapid activation of numerous hacktivist groups after late-February 2026 strikes and points to prior public reporting on long-dwell intrusions and campaigns affecting ICS devices; a SecuritySenses episode similarly describes state-linked hacktivist activity targeting OT (including Unitronics PLCs) and broader spillover effects beyond the region. Other items in the set—an ISC/SANS guest diary on opportunistic scanning and a Dark Reading piece on higher attack volumes in Latin America—do not describe the Iran-related escalation and are not directly part of this specific event narrative.

Share:
Heightened Cyber Risk to US Financial Services and Critical Infrastructure Amid Iran-US Conflict
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 5, 20264mo ago

U.S. intelligence warns of likely low-level Iran-aligned cyberattacks

A U.S. intelligence assessment cited on 2026-03-05 said Iran-aligned hacktivists could carry out low-level attacks such as DDoS against U.S. networks. The warning contributed to elevated concern across the financial sector.

U.S. financial firms raise cyber alert level amid Iran conflict

By 2026-03-05, U.S. banks and other financial services firms were reported to be on heightened alert for possible cyberattacks as war involving Iran escalated. Industry groups and advisors increased monitoring and emphasized operational resilience in anticipation of Iran-aligned hacktivist activity.

Jun 1, 20251y ago

Retaliatory cyberattacks reportedly impact financial infrastructure

As the conflict evolved in June 2025, retaliatory cyber activity was said to affect financial infrastructure in addition to industrial targets. This marked an escalation from influence operations and OT targeting into the financial sector.

Unitronics PLCs and OT systems reportedly targeted worldwide

The same June 2025 campaign reportedly expanded to operational technology, including Unitronics PLCs used in water and industrial facilities. The effects were described as spreading beyond the Middle East, with U.S. water utilities among the targets and IT/OT connectivity and supply-chain weaknesses cited as attack paths.

Iran-linked hacktivists launch psyops and SMS spoofing campaigns

During the June 2025 escalation, groups including Cyber Avengers and Handala were reported to conduct psychological operations and mass SMS spoofing as part of coordinated influence and disruption activity. These actions were presented as state-linked hacktivist operations accompanying the broader conflict.

Operation Rising Lion triggers cyber escalation tied to Iran

In June 2025, a kinetic operation referred to as "Operation Rising Lion" was followed by a sharp cyber escalation that some analysts described as Iran's "12 days of cyber war." The campaign was framed as a hybrid conflict blending physical strikes with cyber operations.

Nov 1, 20233y ago

ICBC ransomware attack disrupts some U.S. Treasury trade settlements

In 2023, a ransomware attack on ICBC's U.S. broker-dealer unit disrupted settlement of some U.S. Treasury trades. The incident was cited as a prior example of how cyberattacks can affect financial market operations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Malware
1 linked
Organizations
7 linked
International Business MachinesDragosIndustrial and Commercial Bank of ChinaFinancial Services Information Sharing and Analysis CenterMorningstarLazardSecurities Industry and Financial Markets Association
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.