By Carl Windsor — Fortinet CISO

The Israel–Iran war has evolved beyond kinetic warfare into a complex cyber conflict. Both nations and their proxy or hacktivist groups are targeting critical sectors—finance, healthcare, telecoms, infrastructure, and public trust.

Even before the conflict escalated physically, FortiRecon detected increased chatter on the dark web, signaling cyberattack preparations. Within hours of the conflict’s start, coordinated attacks from affiliated hacktivist groups via Telegram and darknet forums surged.

(Cyber) Generals Gather in Their Masses

Before open conflict, cyber activity from Iranian-associated APT groups grew steadily. The situation intensified after U.S. airstrikes on June 22, 2025, targeting three Iranian nuclear facilities during Operation Midnight Hammer.

Trading Cyber Blows

As hostilities mounted, cyber retaliation followed. FortiGuard identified groups executing website defacements and DDoS attacks. Pro-Israel actors included Anonymous Italia, BlackWolves, and Team-Network-Nine. Pro-Iranian groups featured MadCap, Z-BL4CX-H4T, Cyber Islamic Resistance, and others.

Destructive Attacks on Financial Institutions

The anti-Iranian group Predatory Sparrow claimed an attack on Nobitex, Iran’s major crypto exchange, wiping $90 million in assets. CyberAv3ngers and MuddyWater also targeted Israel’s water and energy systems. In October 2024, CyberAv3ngers hacked ten Israeli water treatment stations via misconfigured Unitronics devices.
The pro-Palestinian ransomware group Handala attacked Israeli companies, including Delek Group and AeroDreams, shifting from wiper malware to data leaks. In their message to Delkol:


“Your fuel systems are exposed… Over two terabytes of classified data are no longer in your hands…”
Iran’s infrastructure has faced sabotage since the Stuxnet worm, with recurring threats of escalated consequences. The new focus on data leaks suggests a shift to psychological and financial damage.

Human-Based Methods

Iranian APTs like MuddyWater, APT33, and OilRig continue to target global sectors, especially in the Middle East and Europe. Their tactics involve spear-phishing emails with malicious PDFs, HTML files, and spoofed companies. In some cases, they use deepfakes to improve credibility.

U.S. and European firms—especially those linked to Israel—are increasingly collateral targets. On June 22, 2025, “Cyber Fattah” leaked data from past Saudi Games events. The Iran-linked 313 Team took TruthSocial offline in a DDoS attack.

Even before the war, Iranian actors had infiltrated critical infrastructure in at least one Middle Eastern country. The trend points toward wider geopolitical impact, beyond initial zones of hostility.
Multiple cybersecurity groups, including IT-ISAC and Food and Ag-ISAC, have issued warnings to U.S. entities, citing risks of retaliatory attacks, destructive malware, and supply chain compromise.

Disinformation and Psychological Warfare

Disinformation remains a powerful tactic—used from Roman times to Nazi propaganda. Today, cyber operations are interwoven with digital deception: fake missile alerts, leaked personal data, and AI-generated visuals. Some fakes are crude, such as doctored images of a supposedly downed U.S. B-2 bomber, which lacked crash details or realism.

Civilian IoT and Surveillance Exploitation

Movies like Enemy of the State exaggerate surveillance, but reality is closer than expected. Iran and Hamas exploit unsecured home cameras using unchanged default passwords. These allow hostile actors to spy on civilian environments.

Digital Censorship and Information Blackouts

Control of information is central to modern warfare. In mid-June, Iran imposed a 97% internet blackout following strikes. VPN usage spiked by 95% as citizens sought access to global information.
Blackouts are also used during protests, not just wars. Platforms like NetBlocks track these state-enforced outages.

How to Prepare for a Cyber Conflict

  1. Stay Informed
    Use ISACs or subscribe to FortiRecon’s Adversary Centric Intelligence.
  2. Train Staff
    Build a cyber-aware workforce through low- or no-cost training.
  3. Use MFA
    Multi-factor authentication prevents access even if login credentials are compromised.
  4. Automate Patching
    Set up automatic updates for all systems. Use AI to assist in patch management.
  5. Shield Legacy Systems
    Use compensating controls like IPS signatures or Fortinet’s OT Security Platform.
  6. Manage Passwords
    Deploy password managers and routinely change default settings on IoT devices.
  7. Reduce Attack Surface
    Audit internal and external assets. Use CTEM to assess risks.
  8. Defense in Depth
    Assume compromise. Segment networks, use Fortinet’s detection tools, and centralize logging.
  9. Back Up Your Data
    Ensure data recovery capabilities in case of compromise.
  10. Incident Response Planning
    Develop, test, and refine response strategies through regular drills.
  11. Build Partnerships
    Share intelligence, join ISACs, and collaborate with trusted vendors.
  12. Report Attacks Promptly
    Notify CERT teams and relevant law enforcement immediately.
    The cyber frontlines are no longer regional—they are global. As state and non-state actors wage digital war, readiness is not optional—it’s essential.