Welcome to the new cyber battleground

SMART Fire & Safety 2025 Information Security

The Israel–Iran war has moved at a rapid pace in terms of kinetic warfare. What is also a new development is the speed at which this conflict rapidly expanded beyond traditional warfare, evolving into a complex cyber conflict. Both nations – and their proxy or hacktivist groups – are targeting critical infrastructure, finance, healthcare, telecoms, and public trust.

While Israel and Iran have been long-time cyber adversaries, the FortiRecon Dark Web Intelligence team had picked up an increase in chatter before the start of the physical conflict. Within hours of the conflict’s start, a major shift in activity occurred, indicating that preparations for a cyber battle were already underway. The team observed multiple hacktivist groups affiliated with both countries actively collaborating via Telegram channels and darknet forums to launch coordinated cyberattacks against government and private sector targets in the opposing countries. These groups were amplifying their campaigns by sharing targets and attack details.

On 21 June, the team was monitoring chatter between teams related to the downing of an Israeli drone and attacks on energy companies in the wider region, along with more mundane website defacements.

(Cyber) Generals gather in their masses

There has been a continuous stream of cyber activity linked to APT groups tied to Iran in recent months. However, over the last few weeks, the FortiGuard Threat Research team has observed several preparatory attacks from both sides of the conflict, indicating that both nations were on alert for what was to come. When the United States bombed Iran on 22 June1, targeting three nuclear facilities as part of an operation called Midnight Hammer. The strikes aimed to significantly disrupt Iran’s nuclear programme. This is when a significant uptick in activity began.

In this article, we examine some of the tactics we have observed in the lead-up to and during this conflict thus far. It is essential to be aware of this activity, as regardless of the direction from which an attack originates, we can expect the opposing side to employ similar techniques in response.

We also highlight the threats that all organisations, regardless of location, need to consider during times of heightened concern, including what you can do to better protect your organisation.


Table 1: Groups involved in cyber hostilities.

Trading cyber blows

In times of conflict, threat actors aligned with opposing sides often engage in digital retaliation, exchanging cyber blows. FortiGuard Threat Intelligence has identified several groups that have been particularly active during this period, primarily conducting website defacements and distributed denial-of-service (DDoS) attacks as part of ongoing cyber hostilities (see Table  1).

Destructive attacks on financial institutions

An anti-Iranian group, known as Predatory Sparrow, claimed a successful attack on Nobitex, one of Iran’s largest cryptocurrency exchanges, that wiped out $90 million in cryptocurrency and disabled online banking and ATMs2. This came after the same group claimed to have destroyed data at Iran’s state-owned Bank Sepah3, amid the increasing hostilities earlier in the week.

These kinds of crippling financial attacks demonstrate a shift in tactics aimed at harming both public infrastructure and confidence.

Infrastructure sabotage and industrial warfare

Iranian cyber groups like CyberAv3ngers4, a suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC), and affiliate groups such as Iran’s Ministry of Intelligence and Security’s (MOIS) MuddyWater5, have long been targeting water, energy, and industrial control systems in the U.S., Israel, and beyond6,7,8. Cyber Av3ngers claimed in a social media post on 30 October 2024, to have hacked ten water treatment stations in Israel through an attack on misconfigured Unitronics devices (with default passwords and internet access). However, it has not been publicly disclosed whether any equipment was impacted.

Pro-Palestine ransomware group Handala (named after a character created by Palestinian newspaper cartoonist Naji al-Ali, representative of the Palestinian resistance9) has targeted numerous victims from Israel10, including petroleum conglomerate the Delek Group and its Delkol subsidiary, Argentinian drone maker AeroDreams, Israeli construction firm Y.G. New Idan, and ISP 099 Primo Telecommunications.

In the past, the group has been observed to attack Israeli organisations with destructive wiper malware11. However, in the cases of AeroDreams, Y.G. New Idan, and Delkol, the objective appeared to be disruptive data leaking. Threat actors stated to Delkol, “Your fuel systems are exposed. and so are your secrets. Over two terabytes of classified data are no longer in your hands. Your fuel stations are vulnerable. If you’re smart, you’ll act now. Fuel up immediately, before you’re left with nothing but empty roads and silent jets.”

Infrastructure attacks against Iran have also been documented on numerous occasions. Notable examples include the 2021 cyberattack on the Iranian railway system12, attributed to the previously unknown Meteor wiper deployed by an unidentified threat actor. Earlier incidents include the sabotage of centrifuges at the Natanz nuclear facility13 and the widely known Stuxnet attack, which marked a significant milestone in the history of cyber warfare.

These operations carry tangible, real-world consequences. Disruptions to pumping systems and damage to physical facilities risk escalating from digital intrusions to full-scale critical infrastructure failures, posing threats to both safety and stability. The shift in Handala’s tactics suggests a broader intent beyond immediate disruption; the psychological impact on the population and the financial fallout from leaked data may also be key objectives, diverging from the purely destructive goals typically associated with wiper malware.

Iranian APTs, including MuddyWater, APT33, APT34/OilRig, and Rocket Kitten, continue to target a range of government and private organisations across sectors, including telecommunications, local government, defence, and oil and natural gas organisations in the Middle East, Asia, Africa, Europe, and North America14. These APTs target diplomats, defence officials, and academics in Israel and allied nations. Fortinet has observed the use of techniques including highly targeted spear-phishing, and the use of spear-phishing emails, with phishing links and PDF, RTF, and HTML attachments containing links to archives hosted on various file-sharing platforms, spoofed companies, and even deepfakes. These techniques are used to obtain initial access to networks for onward attacks.

Collateral damage and risks to global systems

U.S., European, and regional organisations, particularly those connected via Israeli supply chains, face potential collateral damage from misdirected or opportunistic attacks.

On 22 June  2025, the threat actors associated with the ‘Cyber  Fattah’ movement, coordinating via their official Telegram channel, leaked thousands of records containing information about visitors and athletes from past Saudi Games, one of the major sports events in the kingdom, and re-posted them on the English-language cybercrime forum DarkForums15.

Another Iran-aligned hacking group, 313 Team, claimed responsibility for taking the Trump family’s TruthSocial social media platform offline with a DDoS attack16.

Prior to the war, Fortinet’s FortiGuard Incident Response team identified intrusions into critical national infrastructure belonging to a Middle Eastern country perpetrated by Iranian actors17. It is expected that such attacks will continue, even after cessation of fighting, particularly those targeted at countries which may be perceived as having been directly involved in the war.

Multiple organisations, including the IT-ISAC and Food and Ag-ISAC, have issued warnings urging US organisations to prepare for retaliatory actions originating from Iran. These concerns centre on the growing risk of destructive malware deployment and supply chain compromise, as Iranian cyber operations extend beyond the initial conflict zones. The evolving threat landscape suggests this conflict is poised to spill far beyond traditional geopolitical boundaries.

Disinformation is not something new in politics and warfare, from Octavian’s trolling of Mark Anthony by calling him out as a drunk and womaniser on coins in 44BC to Lord Haw Haw broadcasting Nazi propaganda to the British from Germany in World War II.

Cyber operations and the use of digital propaganda now go hand in hand (false missile alerts, manipulated content, and the leaking of sensitive information to intimidate civilians and shape public perception). AI is making this even harder to identify, but that is not always successful, as the attempts at creating images of a downed American B-2 plane show. From issues with scale, the lack of crash marks, and the fact that the images show an intact plane after apparently being shot out of the sky, such efforts are easy for most to identify, but not for everyone.

As AI imaging and video generation tools continue to automate and improve, it will become increasingly difficult to distinguish between AI-generated content and reality.

Civilian IoT and surveillance system exploitation

Movies and TV shows, such as Enemy of the State and The Blacklist, have long depicted the (mis)use of cameras to track people’s movements. It is believed that both Iran and Hamas have been using this technique for several years, according to Gaby Portnoy of the Israel National Cyber Directorate18. But the reality is not as highly technical as is portrayed. It is primarily happening because people are not changing the default passwords set on their devices, leaving them open to hijacking and abuse.

Such attacks highlight the dangers of unsecured IoT devices becoming backdoors, providing reconnaissance intelligence into civilian environments.

Control of information flow during a war is vital, and one way to make sure the enemy is not using information against you is to cut off the flow. Iran imposed a near-total internet blackout mid-June (up to 97% usage drop) in response to strikes, triggering massive spikes in VPN usage (95% increase) by citizens seeking access to uncensored information19. This is not just limited to countries at war, as can be seen from the data posted by NetBlocks. Such information blackouts are also used for other purposes, such as suppressing strikes and union protests.

Regimes use such disruptions to isolate populations. However, such actions can also impede both civilian and military communications.

How to prepare for a cyber conflict

The Israel–Iran war exemplifies how digital warfare is now inseparable from kinetic conflict. It targets not only military systems, but also civilian, corporate, and cross-border networks, thereby amplifying risks worldwide. Defenders need a new approach, one that considers the impact a once-distant conflict can now have on our doorstep. This is no longer just an issue in the Middle East; today’s cyber battlefield has no borders.

• Geopolitical situational awareness: Understand who is targeting whom, with what tools, and why.

• Prioritise cybersecurity training: With proper training, your staff can better protect your organisation and become the first line of defence against cyberthreats. Create a cyber-aware workforce with low-cost or no-cost training.

• Enable multi-factor authentication (MFA): Even if a username or password is compromised, whether accidentally or intentionally, the user’s overall security is still maintained because actors cannot gain access to the second factor, such as tokens or biometric data, that is also required for access.

• Set up automated patching and updating: Despite years of guidance, this remains one of the top threats to network security and integrity. Regularly patching vulnerabilities is a fundamental measure to prevent exploitation by cybercriminals. It is imperative to keep all software, operating systems, and applications up to date with the latest security patches. Start by establishing a patch-management process to streamline updates and ensure timely implementation. Look to leverage AI and other systems to automate tedious patching tasks. While many legacy systems cannot be patched due to their continuous operation of critical processes, they can be shielded from vulnerabilities using compensating controls, such as targeted IPS signatures, to protect them from exploits.

• Manage passwords: Use password management tools and MFA to ensure passwords meet essential guidelines. These forms of security hardening will prevent compromised passwords from leading to compromised systems. Services that monitor online forums on the dark web, which sell stolen credentials, can also help ensure passwords are updated before they are exploited. Additionally, ensure that IoT devices, such as cameras, are patched and that default passwords are changed.

• Understand and reduce your attack surface: The first step to reducing your attack surface is to understand what you have got. Start by performing systems audits to find out what applications, hardware, and IoT devices are in your internal environment, and do not forget to look outside your organisation. It is always helpful to get an outsider’s POV on your network to assist with auditing your systems, identifying what is there, and determining who has access to what.

• Build defence in depth: Assume compromise will happen and build security resilience and rapid detection capability at every level.

o Segment your network to ensure that the impact of a breach is limited in scope, aiding in the rapid recovery of your network while maintaining business resiliency.

o Threat actors can often remain undetected in a network for months. The correct tools can reduce the mean time to detection from many days to a few minutes.

o Log all activity to a centralised SIEM solution and build an automated detection capability.

• Back up your data: Implement a robust data backup and recovery strategy to ensure data integrity and security. Regularly back up critical data and ensure that backups are stored in secure, off-network, isolated environments. Just as important is to test the recovery of your data to ensure that, in the event of a ransomware attack or data loss, your organisation can quickly recover essential information.

• Develop and test an incident response plan: Create a comprehensive incident response plan and related playbooks that outline the steps to take in the event of a cybersecurity incident. However, a plan sitting in a drawer is of little value. You also need to regularly test and update your plans to ensure their effectiveness. This includes conducting simulated exercises, such as tabletop drills, to enable key stakeholders to practice and refine their responses to various types of cyber threats.

• Build trust and partnerships: CISOs and IT teams must recognise that cybersecurity is a shared responsibility, and no single organisation has all the answers. One of the most critical components of a strong security posture is building global partnerships and actively sharing threat intelligence.

• Report incidents promptly: Timely reporting is essential.

[1] https://tinyurl.com/y5fbeck5

[2] https://tinyurl.com/8mpjvyhz

[3] https://tinyurl.com/2umay9zr

[4] https://attack.mitre.org/groups/G1027/

[5] https://attack.mitre.org/groups/G0069/

[6] https://tinyurl.com/5nthzun9

[7] https://tinyurl.com/2dvyv9fn

[8] https://tinyurl.com/z42ux5f5

[9] https://tinyurl.com/2k9676mr

[10] https://tinyurl.com/4dtjhr2j

[11] https://tinyurl.com/4u65kukx

[12 https://tinyurl.com/2zdbxpy3

[13] https://tinyurl.com/yezemc8u

[14] https://tinyurl.com/2wsuc32x

[15] Identified via FortiGuard Research delivered on the FortiRecon platform.

[16] https://tinyurl.com/5n8vfxsu

[17] https://tinyurl.com/5n8vfxsu

[18] https://tinyurl.com/yc77tna2

[19] https://tinyurl.com/yvep67pm




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Prompt injection is the new phishing
Information Security Security Services & Risk Management
AI security is heading in an uncomfortable direction following Microsoft’s research showing how prompt injection can be chained to remote code execution vulnerabilities in AI agent frameworks, including work involving Semantic Kernel

Read more...
Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.