Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationoperational-disruptionstate-sponsored-disruptiongovernment-diplomatic-threat

Cyber Operations Escalate Following US-Israeli Strikes on Iran

Updated 2mo agoFirst seen Mar 14, 20268 sources

Military strikes by the United States and Israel against Iranian targets on February 28, 2026 were followed within hours by a sharp escalation in cyber activity across the Middle East. Reporting describes widespread DDoS attacks, website compromises, defacements, and breach claims, with more than 150 hacktivist incidents reportedly claimed in the first two days of the crisis. Iranian connectivity was heavily disrupted, including outages affecting IRNA, while Tasnim News was reportedly compromised and displayed anti-regime messaging. The most affected sectors were identified as government, aerospace and defense, and technology, and regional states including Israel, Kuwait, Jordan, Bahrain, Qatar, and the UAE saw elevated cyber pressure.

The surge also expanded beyond immediate regional targets, with security reporting warning that the conflict was driving attacks against global commercial sectors such as travel, hospitality, and energy. One cited example was a March 11 claim by Handala, a hacktivist group alleged to have ties to Iranian intelligence, that it had conducted a large-scale data-wiping attack against medical technology company Stryker, allegedly destroying several terabytes of data. Additional reporting noted unconfirmed concerns that Iranian-linked actors could target the physical and digital infrastructure of major U.S. technology firms. The activity reflects a broader pattern of geopolitically motivated cyber operations acting as a force multiplier alongside kinetic conflict, rather than a standalone marketing or advisory narrative.

Share:
Cyber Operations Escalate Following US-Israeli Strikes on Iran
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Apr 17, 20262mo ago

SOCRadar says conflict enters persistence and reconnaissance phase

By April 17, 2026, SOCRadar reported 1,357 verified cyber incidents in the first month of the Iran war across more than 25 countries, 15 sectors, and over 40 threat groups. The firm assessed that the campaign had moved beyond overt disruption into a quieter phase marked by reconnaissance, pre-positioned access, and latent destructive risk if the ceasefire breaks down.

Iran War Cyber Threat Outlook: Conflict Phases and What Comes Next
Mar 25, 20263mo ago

Underground markets offer allegedly authentic stolen Iranian datasets

By March 25, 2026, ZenoX reported underground sales of allegedly stolen Iranian banking, civil, health, exchange, and business datasets linked to the conflict. The company said reviewed sample data appeared likely authentic, indicating monetization of compromised Iranian information beyond disruptive attacks.

Threat Intelligence: How Cybercrime Behaves in Geopolitical Conflict Scenarios - ZenoX - Artificial Intelligence for Cyber Security
Mar 12, 20263mo ago

Stryker disruption reported as week-two escalation

On March 12, 2026, reporting described disruption at Stryker as a key second-week development in the conflict. The incident was framed as retaliation by Handala and as evidence of escalation toward more destructive operations.

Mar 11, 20263mo ago

Handala claims large-scale data-wiping attack on Stryker

On March 11, 2026, the hacktivist group Handala claimed it had carried out a destructive data-wiping attack against Stryker. The claim said several terabytes of critical data were destroyed, and later reporting characterized the incident as a shift toward wiper-style attacks on a global enterprise.

Mar 3, 20264mo ago

Regional cybercrime and proxy activity broadens beyond state actors

By early March, reporting highlighted additional opportunistic activity tied to the conflict, including vishing scams in the UAE, ransomware extortion against an Israeli industrial machinery company, and intimidation campaigns by Handala Hack against Iranian-American and Iranian-Canadian influencers. This showed the conflict drawing in cybercriminal and proxy actors beyond traditional state-linked operations.

Malicious fake RedAlert app used in phishing campaign

Unit 42 identified an active phishing campaign using a malicious replica of Israel's Home Front Command RedAlert Android application. The app was designed to deliver mobile surveillance and data-exfiltration malware to targets.

Internet connectivity inside Iran drops to 1-4%

Severe internet disruption inside Iran reduced national connectivity to roughly 1-4%, according to Unit 42. The disruption was assessed as likely constraining the ability of Iran-based state-aligned actors to coordinate sophisticated cyber operations in the near term.

Mar 1, 20264mo ago

More than 150 cyber incidents claimed in first two days

Within the first 48 hours of the conflict, more than 150 cyber incidents were reportedly claimed by participating groups. The activity reflected a rapid surge in disruptive operations against government, finance, telecom, aviation, and critical infrastructure targets.

Feb 28, 20264mo ago

Retaliatory cyber campaign expands across the Middle East

Following the February 28 strikes, Iran-aligned actors and hacktivist/proxy groups began a multi-vector retaliatory cyber campaign. Reports describe DDoS attacks, hack-and-leak activity, destructive operations, and intrusions affecting targets in Israel and other regional states.

U.S. and Israel launch joint military operations against Iran

On February 28, 2026, the United States and Israel began joint military operations against Iran. Multiple sources describe this as the trigger for a broader cyber escalation tied to the conflict.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

95 LINKEDOpen in app
Affected products
3 linked
TelegramWindowsAmazon Web Services
Organizations
54 linked
FlashpointEsetCypherLeakMicrosoft CorporationAmazon Web ServicesStrykerSOCRadarCrowdStrikeSaudi AramcoCloudSEKGoogleCheck Point Software TechnologiesOrange CyberdefenseNvidiaIran InternationalPalo Alto NetworksRadwareHalcyonKasperskyHuawei TechnologiesFortinetProofpointConnectwiseGitHubNozomi NetworksSentinelOneGroup-IBSophosWebrootBONDHaaretzBezeqAteraTRM LabsBank MellatJordan Silos and Supply General CompanyJordan Silos CompanyE.M.I.T. AviationMekorotZenoX Threat IntelligenceLionicCAL CargoSeclookupImenSCA GroupKavimEl AlArkiaBank SaderatEgged TaavuraBank MelliOK ExchangeIsrairWWMT
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.