Iran — Cyber Threat Profile

Iran's cyber posture was reshaped by the February-April 2026 war with Israel and the United States, when coordinated cyber and kinetic strikes disrupted Iranian communications and cut national internet connectivity to roughly 1-4% for over 60 hours. Iran-aligned hacktivist groups and state-linked proxies have since been linked to retaliatory DDoS, defacement and infrastructure-probing campaigns against US and allied targets into mid-2026. This follows a June 2025 campaign by the Israel-linked Predatory Sparrow group, which struck Bank Sepah and the Nobitex exchange, destroying roughly 90 million dollars in crypto assets. Domestically, Tehran continues extensive internet filtering, including a nationwide blackout beginning 8 January 2026.

Latest Iran coverage

Threat actors targeting Iran

Most targeted sectors

Recent claimed incidents

Read the full analysis on IntelFusions