Full Breakdown
Escalating Cyber Warfare: Iran's Response to U.S.-Israeli Military Strikes
3/6/2026, 1:02:43 PM
Military Strikes and Cyber Disruption
On February 28, 2026, the Israel Defense Forces (IDF) conducted airstrikes targeting military installations in Tehran, including the headquarters of the Islamic Revolutionary Guard Corps (IRGC) and other key military divisions. Following these strikes, a significant disruption occurred within Iranian cyber operations, as computers linked to Iranian government-backed hackers disappeared from the internet. Cyber intelligence firm GreyNoise reported that several Iranian IP addresses went offline simultaneously, suggesting that these systems were either destroyed or disrupted due to the military action.
Decline of Iranian Cyber Capabilities
The ongoing conflict has highlighted a marked decline in Iran's cyber capabilities. Analysts noted that the number of active Iranian hacking groups has plummeted from over 130 during the 2025 military conflict with Israel to just 17. Despite the potential for retaliation, Iranian cyber groups have remained largely silent, with only a few claims of successful breaches against Israeli infrastructure, which have not been independently verified. This relative quiet underscores the degradation of Iran's cyberattack capabilities, as noted by Alexander Leslie, a threat analyst at Recorded Future Inc.
Internet Blackout and Counteroffensive Threats
In response to the military strikes, Iran has experienced a near-total internet blackout, with connectivity dropping to approximately 1% of normal levels. This blackout, consistent with Iran's wartime strategies, aims to mitigate the risk of inbound cyberattacks and prevent the exposure of sensitive information. Despite this, pro-Iranian hacktivist groups have begun signaling their intent to retaliate, threatening attacks on Western and Gulf critical infrastructure. Reports indicate that around 60 hacktivist groups are now engaged in cyber activities, with some collaborating with pro-Russian actors under the #OpIsrael campaign.
Targeting Critical Infrastructure
Recent claims from the pro-Iran group Handala suggest that they have compromised Israeli energy firms, asserting that "massive cyber attacks" are imminent. However, these claims lack substantial evidence, as no confirmed data leaks or operational disruptions have been reported. Cybersecurity experts warn that while the current impact of Iranian cyber operations appears limited, the potential for future attacks remains, particularly against vulnerable sectors in the U.S. and allied nations.
Official Statements and Responses
U.S. officials and cybersecurity firms are closely monitoring the situation, anticipating potential retaliatory cyberattacks from Iranian-aligned groups. Brian Harrell, former Assistant Secretary for Infrastructure Protection at the U.S. Department of Homeland Security, emphasized the need for heightened vigilance among infrastructure owners, urging them to implement robust cybersecurity measures.
Criticism and Opposition
Despite the apparent decline in Iranian cyber capabilities, experts caution that the risk to critical infrastructure remains significant. Annie Fixler from the Foundation for Defense of Democracies noted that many essential sectors in the U.S. are operated by small companies with limited cybersecurity resources, making them susceptible to attacks. This concern reflects a broader apprehension regarding the evolving nature of cyber warfare, where even limited successes against smaller operators can have substantial visibility and impact.
Conclusion
As the conflict between Iran and the U.S.-Israeli coalition escalates, the cyber battlefield is becoming increasingly complex. While Iranian cyber operations have been notably subdued, the potential for retaliatory actions persists, particularly as pro-Iranian groups seek to exploit vulnerabilities in critical infrastructure. The situation remains dynamic, with ongoing developments likely to shape the future of cyber warfare in this region.
