Iran Names G42, Microsoft, Google and 16 Other Tech Firms as Targets — IRGC Warns of Strikes from 1 April

Iranian state media has named 18 technology companies — including UAE AI firm G42 and US giants Microsoft, Google, and Apple — as targets effective 1 April. Enterprises across the GCC operating on their cloud and AI infrastructure should treat this as an active threat.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
 Digital illustration of major technology company logos overlaid on a map of the Middle East with threat vector indicators

Digital illustration of major technology company logos overlaid on a map of the Middle East with threat vector indicators

Iranian state media has named 18 technology companies as targets in the region, with the Islamic Revolutionary Guard Corps (IRGC) warning that strikes will commence from 8 PM Tehran time on Wednesday, 1 April.

The list — published by the IRGC-linked Tasnim News Agency — includes Microsoft, Google, Apple, Meta, Oracle, Intel, HP, IBM, Cisco, Dell, Palantir, Nvidia, Tesla, JP Morgan, GE, and Boeing, alongside UAE-headquartered AI company G42 and Dubai-based cybersecurity firm Spire Solutions.

"These companies should expect the destruction of their respective units in exchange for each terror act in Iran," the IRGC statement read, warning employees to vacate their workplaces and describing the firms as "key institutions involved in terrorist espionage operations."

G42 is a UAE AI company headquartered in Abu Dhabi, backed by Mubadala, Microsoft, SilverLake, and the Dalio Family Office. It is a central pillar of the UAE's AI ecosystem, co-founding technology investment firm MGX alongside Mubadala, with investments and partnerships spanning OpenAI and Anthropic.

Spire Solutions is a Dubai-based cybersecurity company serving governments, financial institutions, telecoms, energy companies, and enterprises across the Middle East and Africa. Both companies have significant downstream relationships with GCC enterprise clients, making the threat relevant far beyond the named organisations themselves.

This is not the first time Iranian state-linked media has published targeting lists against US technology companies. In early March, a similar list named Google, Microsoft, Palantir, IBM, Nvidia, and Oracle. None were physically attacked at that time, though hackers believed to be linked to Iran breached medical technology firm Stryker.

The current warning follows a significant escalation. Iranian drone strikes in early March damaged Amazon Web Services data centres in the UAE and Bahrain, disrupting cloud services and exposing the physical vulnerability of technology infrastructure across the Gulf.

Iranian state media has been explicit about its reasoning. "As the scope of the regional war expands to infrastructure war, the scope of Iran's legitimate targets expands," Tasnim News Agency reported.

Many of the named companies operate regional offices, cloud infrastructure, and data centre operations across the Gulf. Enterprises running workloads on Microsoft Azure, Google Cloud, AWS, Oracle Cloud, or IBM platforms in the region face potential service disruption if physical infrastructure is targeted again.

Several US firms with Gulf offices have already asked employees to work remotely or limit travel. Some have activated contingency plans following earlier infrastructure disruptions linked to drone strikes and airspace closures.

Electronic warfare targeting GPS signals has also surged across the region, disrupting navigation systems used by aircraft, ships, and enterprise logistics operations — affecting an estimated 1,100 vessels in the Middle East since 28 February.

Organisations operating across the GCC should review cloud resilience plans and assess dependency on named providers. Activating multi-region or multi-cloud failover, where available, is an immediate priority. Staff located in or near named company offices across the UAE, Saudi Arabia, Qatar, and Bahrain should be moved to remote working arrangements without delay.

Incident reporting obligations to UAE TDRA, SAMA, and other regional regulators may be triggered if service disruption occurs. Legal counsel and CISO teams should be engaged now, ahead of any incident, rather than in response to one.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

GCC Threat Landscape 2026Cyber-Physical Security