Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationoperational-disruptiongovernment-diplomatic-threatcritical-infrastructure-threat

Iran–Israel–US conflict triggers rapid hacktivist mobilization and elevated DDoS risk to government and critical infrastructure

Updated 2mo agoFirst seen Mar 10, 202610 sources

Cyber activity surged immediately following joint U.S.–Israel strikes on Iran (described as Operation Epic Fury), with reporting indicating a fast-moving “cyber swarm” of hacktivists and aligned collectives conducting disruption, influence messaging, and broad cyber claim activity within hours of the kinetic events. A day-by-day Telegram-focused timeline described early DDoS campaigns against Israeli government sites expanding into a wider coalition of pro-Iranian, pro-Palestinian, and Russian-aligned groups targeting additional regions and sectors, including Gulf states, Europe, and the U.S., with increasing attention on critical infrastructure; examples cited include claims of DDoS disruption against Israeli commercial, defense-adjacent, and energy-related entities (e.g., an oil company and an advanced defense firm), sometimes accompanied by third-party availability “verification” links.

U.S. state and local governments were separately warned by MS-ISAC to expect heightened “low-level” activity—particularly DDoS—in the wake of the Iran-related escalation, and were urged to harden internet-facing and cloud services (e.g., remediation of critical/cloud infrastructure, use of firewalls/CDNs, and reducing exposed employee/organizational data). In parallel, a critical-infrastructure-focused interview tied to an upcoming OT security summit reiterated that energy, water, pipeline, and ICS environments face persistent probing by state adversaries and that “low-cost entry” cyber operations can be used to test and disrupt mission-critical systems; while not specific to the Iran conflict, it reinforces the broader risk context for OT operators amid heightened geopolitical tensions.

Share:
Iran–Israel–US conflict triggers rapid hacktivist mobilization and elevated DDoS risk to government and critical infrastructure
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Mar 27, 20263mo ago

Iran-linked hackers threaten destructive attacks on U.S. water systems

By 2026-03-27, major Iranian-linked hacker groups were reported to have coordinated public threats warning of 'irreparable damages' to U.S. water systems. The development marked a more explicit and focused escalation toward U.S. critical infrastructure beyond earlier general OT/ICS rhetoric.

Major Iranian hackers unite, threaten ‘irreparable damages’ to U.S. water systems - Threat Beat
Mar 10, 20263mo ago

MS-ISAC warns U.S. state and local governments of possible Iran-linked intrusions

On 2026-03-10, the Center for Internet Security's MS-ISAC warned U.S. state and local governments to expect heightened low-level cyber activity from Iran, including possible DDoS intrusions, following the conflict escalation. It urged rapid remediation of critical and cloud infrastructure, use of firewalls and CDNs, and reduction of publicly exposed organizational data.

Mar 5, 20264mo ago

Governments and industry issue warnings on Iran-related cyber risk

By early March 2026, public warnings about elevated Iran-linked cyber threats were issued by authorities including the UK, Canada, Europol, and the U.S. Department of Homeland Security, alongside private-sector alerts. The advisories emphasized risks to government, critical infrastructure, cloud-dependent services, and organizations with Middle East exposure.

Mar 2, 20264mo ago

Hacktivist targeting expands across Middle East, Europe, and North America

In the days following the initial strikes, Telegram-based hacktivist activity spread beyond Israel to targets in Kuwait, Jordan, Saudi Arabia, Qatar, Oman, Cyprus, the UK, and the U.S. Reported operations included DDoS attacks, defacements, hack-and-leak claims, and increasing rhetoric around OT/ICS targeting of water, energy, and food systems.

Mar 1, 20264mo ago

Jordan reportedly foils Iranian OT attack on wheat silo system

A government-confirmed Iranian operational technology attack targeting Jordan's wheat silo management system was reportedly foiled during the early days of the conflict. The incident was cited as a notable example of attempted critical infrastructure targeting tied to the escalation.

Iranian drone strikes hit AWS facilities in UAE and Bahrain

On 2026-03-01, reported Iranian drone strikes targeted three AWS facilities in the UAE and Bahrain, disrupting cloud-dependent services across the Gulf and beyond. The incident highlighted the conflict's spillover from cyber activity into attacks affecting digital infrastructure availability.

Feb 28, 20264mo ago

Iran's national internet reportedly drops to about 1% connectivity

During the immediate aftermath of the strikes, Iran reportedly experienced a major internal internet disruption, with national connectivity falling to roughly 1% according to one source. Despite the outage, cyber operations and aligned online activity were said to continue via external infrastructure and proxy actors.

Iran-linked groups surge after joint U.S.-Israeli strikes on Iran

Joint U.S.-Israeli strikes on Iran on 2026-02-28 were followed within hours by a sharp rise in cyber activity, including service disruptions, influence messaging, hacktivist mobilization, and numerous incident claims. Multiple sources describe this as the opening cyber escalation phase of the conflict.

Feb 1, 20265mo ago

MuddyWater reportedly pre-positions access in North American organizations

Public reporting cited by multiple sources says MOIS-linked MuddyWater had been conducting pre-strike espionage and persistence activity since early February 2026, allegedly targeting organizations including a U.S. bank, a U.S. airport, a U.S./Canada nonprofit, and a software company operating in Israel. The activity reportedly involved previously undocumented backdoors including Dindoor and Fakeset.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

88 LINKEDOpen in app
Affected products
3 linked
TelegramAmazon Web ServicesSymantec
Organizations
45 linked
Amazon Web ServicesPalo Alto NetworksInformation Security Media GroupRed HatTaniumMAXCenter for Internet SecurityRadwareSnowflakeEsetNCC GroupINC ransomwareSaudi AramcoResecurityStrykerBroadcomBitdefenderBezeqGoogleSony Pictures EntertainmentStateScoopAlon Israel Oil CompanyCyprus Electricity AuthorityBank al EtihadJordanian Electricity Distribution CompanyTurpaz IndustriesISAR EngineeringWeLearnGoldtec TechnologiesAnglia Indoor KartingLimassol Airport ExpressJordan Silos CompanySaudi University of Business and TechnologyOron GroupPrima Park HotelBaran CompanyRamet-TromAmarel Ltd.Hellenic BankTCS CommunicationsE.M.I.T. AviationSwarmlyDubai PetroleumAl SafiCC Energy
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.