When US and Israeli strikes darkened Iran's internet in late February, the silence was not an ending but a displacement — the conflict simply moved outward, carried by state proxies, hacktivists, and opportunistic criminals into the infrastructure of a deeply interconnected world. What emerged from the chaos was not a contained cyberwar but something more unsettling: a moment in which geopolitical crisis became both cover and catalyst for a shadow economy of digital harm, reaching hospitals, power grids, and ordinary people far from any battlefield. The lesson, as one senior cybersecurity offi
Cyber conflict spills beyond borders as geopolitical crisis fuels global attack surge
Cyber conflict doesn't end when the fighting stops
So when Iran's internet went down to almost nothing after those strikes, did the cyber operations actually stop, or did they just move somewhere else?
They moved. The state-backed actors and hacktivist groups didn't need Iran's internet to keep operating. They were already inside networks, already positioned. The attacks just shifted outward—targeting infrastructure globally.
But we should be careful here. We know attacks happened. We know they were tracked. But how much of this is directly linked to Iranian state actors versus opportunistic groups using the conflict as cover? The reporting attributes some activity to Iran-linked groups, but some is just "claimed" by hacktivists.
Fair point. So what made this different from previous cyber conflicts?
The scale and the targets. Over 150 hacktivist incidents in 48 hours. But more importantly, they went after critical infrastructure—power grids, water systems, medical facilities. Not just websites.
Right, but the Stryker Corporation attack—that's one confirmed case of real disruption. The probing of water and energy systems is flagged as a concern, but how many actual breaches happened? The reporting says "hackers have probed" but doesn't always distinguish between reconnaissance and actual compromise.
And the cybercriminals? They seem to be the real volume story here.
Exactly. Over 7,300 phishing URLs in a single month, targeting everyday people with scams about banks, utilities, government warnings. The chaos of geopolitical crisis becomes cover for financial crime.
Which is important, but also—those numbers are from Unit 42, one firm. We don't have a complete picture of global phishing volume. We know it spiked, but the exact scale is one firm's count.
What about the countries that aren't directly involved? India, Japan, Europe—how exposed are they really?
Very. Supply chains, shipping routes through the Strait of Hormuz, IT services vendors. A breach at one vendor cascades globally. India's energy imports pass through that strait, so any attack on Gulf infrastructure hits them.
The advisory from India's Data Security Council is real and recent. But "elevated cyber threats" is still somewhat abstract. We know the risk is there. We don't know if it's materializing yet.
So this doesn't end when the fighting stops?
No. Cyber operations can linger for years—probing, harvesting data, waiting. And now the tools are more accessible. AI is lowering the barriers to entry.
That's the forward-looking concern, and it's grounded in real trends. But we're also in a moment where we don't fully know what comes next. The reporting is honest about that uncertainty.
Il Polso
- Iran's internet collapsed to near-zero traffic after the strikes, yet cyber operations accelerated globally, with over 150 hacktivist incidents logged in the first 48 hours alone.
- Critical infrastructure — energy grids, aviation systems, industrial controls, and a US medical technology firm — came under coordinated attack, with wiper malware at Stryker Corporation delaying real surgical procedures.
- A parallel wave of financially motivated crime surged alongside state-backed operations, with more than 7,300 conflict-themed phishing URLs flooding nearly 1,900 domains in March, targeting everyday users through fake banks, charities, and government alerts.
- Second-order nations including India, Japan, and European states face mounting spillover risk through supply chain vulnerabilities, ransomware, and espionage — with India's energy imports and IT services sector flagged as particular weak points.
- Analysts warn that even a ceasefire changes only the rhythm of cyber conflict, not its persistence — as AI lowers barriers to entry and global crises hand low-skilled actors ready-made narratives for convincing attacks.
When US and Israeli strikes darkened Iran's internet in late February, the silence was not an ending but a displacement — the conflict simply moved outward, carried by state proxies, hacktivists, and opportunistic criminals into the infrastructure of a deeply interconnected world. What emerged from the chaos was not a contained cyberwar but something more unsettling: a moment in which geopolitical crisis became both cover and catalyst for a shadow economy of digital harm, reaching hospitals, power grids, and ordinary people far from any battlefield. The lesson, as one senior cybersecurity official put it, is that geographic distance offers no defence — and that in the digital age, war does not end so much as it changes rhythm.
When coordinated US and Israeli strikes hit Iranian military and nuclear targets in late February, Iran's internet traffic collapsed to between one and four percent of normal — the country effectively vanished from the global network. But the cyber conflict didn't vanish with it. It moved outward.
Even as Iran went dark, state-backed actors, proxy groups, and independent hackers continued operating across borders. Within days, researchers documented a sharp surge in global threat activity: websites defaced, government platforms taken offline, a religious app with five million downloads hijacked to broadcast anti-regime messages, and Iranian state media disrupted. CloudSEK tracked more than 150 claimed hacktivist incidents in the first 48 hours. Western intelligence suggested the operations were designed to degrade Iran's ability to respond — limiting communications and disrupting command systems.
The targets quickly expanded beyond media and government sites. Researchers identified attacks on industrial control systems used in manufacturing and utilities, with more than 5,600 internet-connected devices globally running vulnerable software. The US cybersecurity agency flagged attempts to exploit programmable logic controllers — components that quietly automate water supply and power grids. In March, an Iran-linked group deployed wiper malware against Stryker Corporation, a US medical technology firm, disrupting operations and delaying procedures.
Running alongside these state-linked campaigns was a parallel surge in financially motivated crime. More than 7,300 conflict-themed phishing URLs appeared across nearly 1,900 domains in March alone — fake charities, crypto scams, spoofed banks and airlines. Attackers used urgency and fear to slip past detection, targeting everyday users through mobile-first campaigns. The US Federal Trade Commission flagged fraudsters posing as bank officials warning of Iran-linked transactions, fake military romance scams, and sham relief funds.
The overlap was not accidental. Iran had long relied on a blend of formal cyber units and loosely affiliated proxy groups — a model offering extended reach with plausible deniability. Some groups paired intrusions with psychological operations, leaking personal data to amplify pressure. Meanwhile, the risks spread far beyond the Middle East. India, Japan, and several European states faced elevated exposure through supply chain disruptions, ransomware, and espionage. India's energy sector — heavily dependent on Gulf imports — and its IT services industry were specifically flagged as potential cascade points.
Analysts cautioned that a ceasefire would not end the threat. Cyber operations could quietly persist — probing systems, harvesting data, waiting. With artificial intelligence lowering technical barriers and global crises providing ready narratives, even low-skilled actors could mount convincing attacks. The US-Iran conflict made visible something already underway: modern war is not only destructive, it is generative — creating new actors, new incentives, and risks that rarely stay on the battlefield.
When Iran's internet nearly vanished in late February—dropping to just 1 to 4 percent of its normal traffic after coordinated US and Israeli strikes on military and nuclear targets—the country didn't simply lose connection. It effectively disappeared from the global internet, according to network monitoring data tracked by cybersecurity researchers. But the cyber conflict didn't stop. It moved outward.
Even as Iran went dark, operations continued across borders, carried out by state-backed actors, proxy groups, and independent hackers who didn't need a functioning domestic internet to keep working. Within weeks, researchers documented a sharp spike in global threat activity tied to the conflict—coordinated campaigns by dozens of hacktivist groups, waves of phishing attacks, scams, and disruptive intrusions targeting organisations far outside the Middle East. What emerged wasn't a contained cyberwar. It was something more complex: modern geopolitical crisis functioning simultaneously as both cover and opportunity for a shadow economy of cybercrime, where attacks kept moving even when countries themselves went offline.
The cyber offensive began almost in parallel with the February 28 military strikes. Websites were defaced. Government platforms went down. BadeSaba, a religious app with more than 5 million downloads, was hacked to display messages urging users to abandon the regime. Iranian state news agency IRNA was taken offline. The IRGC-linked Tasnim website faced disruptions and message alterations. The scale suggested coordination beyond isolated incidents. Western intelligence sources indicated the cyber operations aimed to disrupt Iran's ability to mount a response—limiting communications and degrading command systems. According to cybersecurity firm Palo Alto Networks' Unit 42, the conflict quickly pulled in both state-backed actors and loosely aligned hacktivist groups. CloudSEK tracked more than 150 claimed hacktivist incidents between February 28 and March 1, largely involving denial-of-service attacks, website defacements, and data breach claims. Researchers also observed Iranian-aligned actors conducting reconnaissance and initiating denial-of-service attacks before the strikes even landed.
This surge built on an already expanding baseline of global cyber threat activity. According to the World Economic Forum's Global Cybersecurity Outlook 2026, 77 percent of organisations globally reported a rise in phishing and fraud, while 73 percent of individuals experienced cyber-enabled crime. The average number of weekly cyberattacks per organisation had more than doubled in recent years, from 818 to 1,984. Breaches now moved from initial access to data exfiltration in under 72 minutes in some cases. Into this landscape, the US-Iran conflict landed.
What distinguished this moment was the scope and the targets. Beyond websites and media systems, the early cyber campaign appeared to target deeper infrastructure. CloudSEK said attacks likely combined denial-of-service campaigns, electronic interference, and network intrusions targeting energy, aviation, and government systems. In late March, Unit 42 identified activity linked to a group known as Cyber Av3ngers, targeting industrial control systems used in manufacturing and utilities—specifically software from Rockwell Automation, the kind that quietly runs factories and energy grids. Researchers identified more than 5,600 internet-connected devices globally using such systems. The US Cybersecurity and Infrastructure Security Agency flagged attempts to exploit programmable logic controllers—small but critical components that automate everything from water supply systems to power grids. In March, an Iran-linked group deployed wiper malware against Stryker Corporation, a US-based medical technology firm, disrupting operations and delaying procedures. That kind of disruption translated directly into real-world consequences—postponed surgeries, interruptions in essential services.
But the bigger shift was happening outside state-backed operations. Alongside these attacks, cybersecurity firms tracked a parallel surge in financially motivated cybercrime, often piggybacking on the chaos. Unit 42 recorded more than 7,300 conflict-themed phishing URLs across nearly 1,900 domains in March alone—fake charity drives, crypto scams, spoofed telecom portals, banking sites. Attackers impersonated airlines, law enforcement, and government systems, using increasingly polished techniques to slip past detection. Much of this activity targeted everyday users, especially through mobile-first attacks. The playbook was familiar: urgency, fear, and just enough plausibility. A bank alert. A utility warning. A government notice. The US Federal Trade Commission flagged similar trends—fraudsters posing as bank officials warning of Iran-linked transactions, fake military romance scams, sham charities.
This overlap between state conflict and criminal opportunity wasn't accidental. Cybersecurity analysts noted that Iran had increasingly relied on a mix of formal state-linked cyber units and loosely affiliated hacktivist or proxy groups—a model that allowed extended operations while maintaining plausible deniability. Unit 42 identified dozens of such groups active in the current conflict, carrying out everything from denial-of-service attacks to data leaks and infrastructure probing. Some, like the Handala Hack group, paired cyberattacks with psychological operations—leaking personal data or issuing threats to amplify pressure. The World Economic Forum reported that 91 percent of large organisations were already reworking their cybersecurity strategies in response to geopolitical instability.
The risks extended far beyond the Middle East. CloudSEK noted that second-order countries—those not directly involved—were increasingly exposed. That included major economies such as India, Japan, and several European states. The risks spanned espionage, ransomware, supply chain disruptions, and disinformation. In a tightly connected global system, vulnerabilities didn't stay contained. Companies across finance, energy, and transport had been targeted. Disruptions to shipping routes, particularly through the Strait of Hormuz, were starting to ripple into global trade. In India, a March 2026 advisory by the Data Security Council warned that sectors ranging from energy and finance to IT services could face elevated cyber threats. With a large share of India's energy imports passing through the Strait of Hormuz, any cyberattack on Gulf infrastructure or shipping systems could worsen supply disruptions and hit domestic markets. The IT services sector was flagged as a potential weak link—where a breach at a single vendor could cascade across global clients. Financial institutions faced renewed exposure to ransomware and supply-chain attacks. As Sami Khoury, Senior Official for Cybersecurity at the Government of Canada, told the World Economic Forum: geographic distance offered no defence.
Unlike conventional warfare, cyber operations could linger long after fighting stopped. Alexander Leslie, a senior adviser at Recorded Future, told The New Yorker that the ceasefire didn't end cyber conflict; it changed its rhythm. Cyber operations could quietly probe systems, harvest data, and wait for the next opening. And increasingly, those openings weren't limited to states. The tools of cyberwar, once tightly held by governments, were now far more accessible. With artificial intelligence lowering technical barriers and global crises offering ready-made narratives, even relatively low-skilled actors could mount convincing attacks. The result was a threat landscape that was more crowded, more chaotic, and harder to predict. War, in this sense, was no longer just destructive. It was generative—creating new actors, new incentives, and new risks. And as the US-Iran conflict showed, those risks rarely stayed on the battlefield.
Citazioni salienti
Cyber isn't usually the decisive weapon on its own; it's a force multiplier— Tal Kollender, former Israeli military cyber-defence specialist, to the BBC
The ceasefire does not end the cyber conflict; it changes its rhythm— Alexander Leslie, senior adviser at Recorded Future, to The New Yorker