Iran Launches Cyberattacks Following U.S. and Israeli Missile Strikes
Iran-linked hackers launched a cyber campaign against Israel and Gulf nations after coordinated U.S. and Israeli military strikes targeted Iranian territory.
Following coordinated missile strikes by the United States and Israel, Iran launched a cyberwar campaign targeting Israel, Persian Gulf nations, and other regional interests. State-sponsored hackers, including the group Cotton Sandstorm linked to the Islamic Revolutionary Guard Corps, deployed WezRat infostealers and WhiteLock ransomware against Israeli entities. The offensive also included distributed denial-of-service (DDoS) attacks and digital probing.
Cyber intelligence firms such as CrowdStrike, Recorded Future, and Check Point Software Technologies report a surge in reconnaissance activity. While pro-Iranian groups claimed a breach of a Jordanian grain silo company, analysts suggest Iran may be overstating its successes for psychological impact. Experts note that large-scale campaigns against U.S. government agencies have not yet been observed, though organizations tied to the U.S. military face elevated risks of spillover attacks.
The cyber threats arrive as the Cybersecurity and Infrastructure Security Agency (CISA) operates at approximately 38% staffing due to funding shortfalls at the Department of Homeland Security. Secretary Kristi Noem stated she is coordinating with federal intelligence and law enforcement partners to monitor and thwart threats to the homeland.