Iran-linked hackers sync cyber attacks with missile strikes
Get the Geopolitics newsletter
Daily geopolitics — wars, elections, sanctions, the diplomatic moves that move markets. Free.
- Iran-linked hackers sent Israelis fake bomb shelter texts synced to missile strikes, downloading spyware that accessed device cameras, locations, and all stored data — a "first"-of-its-kind digital-physical combo, per Check Point Research's Gil Messing.
- DigiCert has tracked nearly 5,800 cyberattacks from roughly 50 Iran-tied groups, mostly hitting U.S. and Israeli companies but also networks in Bahrain, Kuwait, and Qatar, with most attacks easily thwarted but still resource-draining.
- Iran-linked group Handala claimed responsibility for hacking Michigan-based medical device maker Stryker, citing retaliation for U.S. strikes that killed Iranian schoolchildren; separately, Halcyon researchers found a destructive ransomware attack on an unnamed U.S. healthcare firm using Iran-linked tools — with no ransom demanded, suggesting a destruction motive.
- A pro-Iran hacking group infiltrated an account of FBI Director Kash Patel on Friday, posting decade-old photos, a resume, and personal documents — a classic high-volume, low-impact move DigiCert's Michael Smith called "more of an intimidation tactic" than a strategic blow.
- AI-generated disinformation has amplified the conflict, with one deepfake image of sunken U.S. warships racking up more than 100 million views; Iranian state media has begun labeling real war footage as fake and substituting doctored images, per NewsGuard research.
- The State Department opened a Bureau of Emerging Threats last year to address AI and hacking risks, joining efforts already underway at CISA and the NSA, as Director of National Intelligence Tulsi Gabbard warned Congress that AI will increasingly shape both cyber offenses and defenses.
Why it matters: Halcyon's Cynthia Kaiser said the Stryker and unnamed healthcare attacks together "suggest a deliberate focus on the medical sector rather than targets of opportunity" — meaning U.S. hospitals and medical device makers now face intentional, escalating targeting from Iranian hackers, not random opportunism, even as roughly 50 Iran-linked groups run high-volume probes that drain defensive resources across the broader U.S. and Israeli private sector.




