Iran-Linked Cyberattacks Escalate in Volume and Global Reach, NCC Group Warns

A new NCC Group report finds that Iran-linked cyberattacks have grown in volume, geographic scope and actor diversity, with organisations tied to Israel or the US remaining at heightened risk — even as Iran's own domestic internet access remains heavily restricted.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
Digital threat map showing Iran-linked cyberattack vectors spreading across the Middle East and into Western nations in 2026

Digital threat map showing Iran-linked cyberattack vectors spreading across the Middle East and into Western nations in 2026

A new report from global cybersecurity firm NCC Group has found that hacktivism linked to the Iran conflict has escalated across multiple dimensions simultaneously — growing in volume, geographic scope and the diversity of threat actors involved. The report, titled Middle East Crisis: Cyber Update, paints a picture of a conflict that has firmly extended into the digital domain, with consequences that stretch well beyond the Middle East.

According to the report, Iran has succeeded in maintaining effective and adaptable offensive cyber capabilities despite severe domestic disruptions. Organisations operating in Israel, or those with commercial or governmental ties to the US or Israel, are assessed as remaining at the highest levels of risk — though that calculus may shift further if additional nations become directly or indirectly drawn into the conflict.

Degraded but Not Disabled

Iran's near-total internet blackout — implemented approximately three weeks before the report's publication — was primarily a self-imposed measure designed to control domestic information flows. Yet despite this, NCC Group assessed that Iran's cyber capabilities are "degraded but remain operational." Iranian operators are believed to retain access to footholds established in foreign networks prior to the blackout, as well as external infrastructure and front companies that allow operations to continue with minimal domestic connectivity.

The majority of state-linked activity has focused on high-visibility, low-impact operations designed to shape perceptions rather than cause meaningful disruption. Distributed Denial-of-Service (DDoS) attacks, website defacements and data leak incidents have dominated the threat landscape during this period.

APT34 and the Long Game

Targets of state-linked Iranian threat actors — particularly those connected to Iran's Ministry of Intelligence and Security (MOIS) — have primarily included Israeli government, military and infrastructure entities. Critical infrastructure and technology organisations in nations that have indicated support for Israel or the US — including Australia, Cyprus, Germany and Jordan — have also been in the crosshairs.

Among the most significant and well-documented of these groups is APT34, also known as OilRig. The group has a long track record of targeting organisations across government, chemical, energy, financial and telecommunications sectors in the Middle East, Europe, North America and parts of Asia. Its campaigns are defined by a focus on long-term access and data collection rather than immediate disruption. APT34 is known to conduct extensive reconnaissance and deploy spearphishing techniques to carry out credential harvesting and broader intelligence collection operations.

A Warning on US Cyber Readiness

The report also touches on a concern closer to home for American organisations. While the United States possesses the most technically advanced cyber capabilities of any nation state, NCC Group acknowledged that significant recent reductions at the US Cybersecurity and Infrastructure Security Agency (CISA) — the body responsible for cyber threat monitoring and notifying public and private sector entities about active operations — have raised questions about the nation's overall cyber readiness. Proposed budget cuts and staff departures have already seen CISA's workforce drop considerably from its earlier levels, with the agency's staffing falling to between 2,200 and 2,600 employees from around 3,700 at the start of the year. Tech Prescient

The combination of an emboldened and adaptable Iranian threat actor ecosystem and a potentially weakened domestic cyber defence posture in the US represents a compounding risk — one that organisations across both the public and private sectors will need to factor into their security strategies in the months ahead.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.