Regional cyber activity has increased following recent U.S.-Israeli kinetic strikes on Iranian targets, according to a report by FortiGuard Labs researchers Aamir Lakhani, Carl Windsor, and Derek Manky published March 24, 2026.

The report states that no confirmed large-scale, coordinated Iranian cyber retaliation directly tied to the strikes has been observed. However, FortiGuard Labs said the cyber domain remains active and warrants close monitoring.

What FortiGuard Labs Has Observed

Observed incidents include the compromise of Iranian applications and media platforms, notably the BadeSaba calendar app. Researchers also documented broadcast intrusions distributing psychological messaging and internet disruptions inside Iran.

In addition, Telegram-based claims of cyberattacks targeting Israel, Jordan, Afghanistan, and other regional entities have increased. FortiGuard Labs noted that indications of potential targeting of financial services and critical infrastructure have also emerged, though many claims lack technical validation.

Delayed Retaliation Remains a Risk

FortiGuard Labs researchers said Iranian cyber responses are not always immediate. Access to target systems is often established in advance, with execution occurring later, sometimes after public attention declines.

“Organizations that assume reduced risk due to the absence of immediate retaliation may be unprepared.”

FortiGuard Labs, Threat Intelligence Report, March 2026

The BadeSaba incident, researchers said, suggests backend access and possible pre-positioning. This reflects a pattern of early infiltration followed by delayed execution.

Threat Actors Exploit Geopolitical Noise

Periods of geopolitical escalation create high-noise environments that threat actors exploit through phishing campaigns, fake advisories, and spoofed software updates designed to distribute malware. Furthermore, such environments enable false-flag activity and complicate attribution.

Potential tactics identified by FortiGuard Labs include wiper malware targeting government or energy sectors, distributed denial-of-service attacks against financial institutions, and credential harvesting linked to conflict-related themes. Other risks include spoofed mobile apps, fake software installers, and website defacements.

The report also noted that geopolitical cyber operations may rely on covert coordination rather than public channels. Consequently, the absence of visible indicators does not confirm that no preparation is underway.

Recommended Actions for Organizations

FortiGuard Labs outlined several steps organizations should take to strengthen resilience. These include maintaining awareness of threat activity and leveraging intelligence-sharing platforms such as ISACs or services like FortiRecon.

Employee training is essential, alongside enforcing multi-factor authentication across systems, maintaining timely patching, and reducing attack surfaces. A defense-in-depth approach — including network segmentation, monitoring, and centralized logging — is also recommended.

Moreover, organizations should secure and test data backups, develop and rehearse incident response plans, and share threat intelligence with trusted partners. Prompt reporting of incidents remains essential, the researchers stated.

Regional Cyber Activity Outlook

FortiGuard Labs said current regional cyber activity is largely opportunistic and characterized by noise rather than confirmed coordinated attacks. However, researchers warned that more organized and targeted attacks may emerge in subsequent phases of the conflict.

Previous conflicts have shown that cyberattacks can extend beyond military targets to civilian, corporate, and cross-border networks. Organizations that strengthen their security posture now will be better positioned to respond to potential escalation, the report concluded.