Drooid Logo
Back to story perspectives

Full Breakdown

Escalation of Cyber Warfare Amid U.S.-Israeli Strikes on Iran

3/4/2026, 1:29:02 AM

Overview of the Conflict

On February 28, 2026, the United States and Israel initiated a coordinated military offensive against Iran, termed Operation Epic Fury and Operation Roaring Lion, respectively. This marked the beginning of a significant escalation in hostilities, leading to Iran's multi-vector retaliatory campaign, which has included extensive cyber operations. Following the strikes, Iran experienced a drastic reduction in internet connectivity, dropping to between 1-4%, severely limiting its ability to coordinate cyber responses.

Iranian Cyber Response and Activities

In the wake of the military strikes, Iranian-aligned cyber groups have engaged in various operations. Notably, the hacktivist group Handala, linked to Iran's Ministry of Intelligence and Security, has claimed responsibility for multiple cyberattacks targeting Israeli infrastructure, including energy and healthcare systems. Other groups, such as APT Iran and the Cyber Islamic Resistance, have also been active, executing DDoS attacks and data-wiping operations against both Israeli and Western targets.

Despite the apparent mobilization of these groups, cybersecurity analysts have noted a significant decline in the effectiveness of Iranian cyber operations compared to previous conflicts. Reports indicate that many Iranian hacking groups have gone "dark," with only a fraction of the previously active entities continuing operations. This reduction is attributed to the severe internet blackout imposed by the Iranian government, which has hindered coordinated cyber responses.

Impact of U.S.-Israeli Cyber Operations

U.S. Cyber Command has played a critical role in the conflict, executing cyber operations designed to disrupt Iranian communications and command structures. General Dan Caine, chairman of the Joint Chiefs of Staff, confirmed that these operations effectively left Iranian forces unable to respond to the strikes. Analysts have described the U.S.-Israeli cyber campaign as potentially the largest in history, targeting critical infrastructure and government services within Iran.

The cyberattacks have included DDoS operations against Iranian news websites and the hijacking of popular applications to disseminate propaganda urging Iranian forces to surrender. These actions have compounded the challenges faced by Iranian cyber actors, who are now struggling to mount a cohesive response.

Criticism and Opposition

Critics of the U.S. and Israeli cyber strategies argue that the aggressive tactics may provoke further retaliatory actions from Iran and its allies. Some cybersecurity experts caution that the narrative surrounding Iranian cyber capabilities has often been exaggerated, potentially leading to miscalculations in response strategies. Additionally, there are concerns about the implications of such cyber warfare on civilian infrastructure and the potential for collateral damage.

Conflicting Reports and Gaps

While many reports indicate a significant decline in Iranian cyber activity, some sources claim that Iranian-aligned groups are still capable of executing targeted attacks, particularly against U.S. and Israeli interests. The discrepancy in reported capabilities raises questions about the true extent of Iran's cyber capabilities during this conflict.

Conclusion and Future Implications

As the conflict continues, the potential for further cyber escalation remains high. Experts warn that Iranian cyber actors may still attempt to leverage their capabilities against critical infrastructure in the Gulf and beyond. The ongoing situation underscores the evolving nature of warfare, where cyber operations play an integral role alongside traditional military engagements. The international community remains vigilant, anticipating possible retaliatory cyber actions from Iran as the conflict unfolds.