NCC Group Warns Iran's Cyber Threat Has Gone Global
NCC Group has warned that cyber activity linked to the Iran conflict has intensified and spread well beyond the Middle East, with hacktivist operations growing in volume and reach while Iranian state-linked groups continue to operate despite domestic internet restrictions.

Digital world map overlaid with cyber threat indicators and Iran conflict-linked hacking activity warnings
NCC Group, the global cybersecurity firm, has warned that cyber activity linked to the ongoing Iran conflict has intensified and spread far beyond the Middle East. Organisations with ties to Israel or the United States remain at the highest levels of risk, but the threat has now extended to Western-aligned nations including Australia, Romania and Cyprus.
The firm's assessment paints a picture of a conflict increasingly being fought on two fronts: one military, one digital. NCC Group described the online space as a parallel battleground, where influence operations are expanding and AI-generated content is making it harder to verify what is real.
Weakened but Not Disabled
Iran's cyber posture has been degraded but not neutralised. The country's near-total internet blackout during the conflict was assessed as largely self-imposed — a deliberate move to control information flows — while core backbone connectivity remained in place. This means Iranian operators may still be able to leverage footholds already established in overseas networks, using infrastructure and front organisations based outside Iran to sustain or scale operations without relying on domestic internet access.
Groups linked to Iran's Ministry of Intelligence and Security (MOIS) were highlighted as retaining meaningful offensive capability. Chief among them is APT34, also known as OilRig — one of the most comprehensively documented Iranian threat actors. The group has a long track record of targeting government, energy, telecommunications, financial and chemical organisations, primarily across the Middle East but also in Europe, North America and parts of Asia. APT34's campaigns are characterised by a focus on long-term access and intelligence gathering over immediate disruption, with the group favouring stealth and persistence through a blend of open-source tools and custom malware.
NCC Group also noted that APT34 had shown signs of operational silence that could indicate covert pre-positioning rather than inactivity — a pattern that warrants close monitoring.
Handala and the Stryker Attack
The report examined the role of proxy and hacktivist groups that provide Tehran with plausible deniability. Prominent among them is Handala Hack, which NCC Group linked to the MOIS and which maintained one of the highest operational tempos among Iran-aligned actors during the conflict period. The group has been associated with attacks on Israeli and Gulf targets, as well as the high-profile cyber incident at medtech company Stryker — which NCC Group described as the most notable incident since the conflict began, though full attribution has not been independently corroborated by the company.
Also cited was MuddyWater, an MOIS-linked group that had reportedly already established footholds inside organisations in the US and Canada before the latest phase of the conflict. The researchers noted that existing intrusions would require only limited communication with operators inside Iran, making such groups considerably less dependent on domestic internet access than might be assumed.
A Threat That Has Gone Global
Distributed denial-of-service (DDoS) attacks, website defacements and data leak claims continued to dominate the hacktivist landscape, though data leak incidents made up a larger share of total reported activity during the latest review period. Hacktivist activity has not remained confined to Israel and its immediate neighbours — Western-aligned countries have also been targeted, with some incidents appearing designed to deliver a political message rather than cause lasting operational damage.
NCC Group cautioned that claims by hacktivist groups often form part of broader information campaigns and may exaggerate technical impact. The firm also pointed to warnings circulating online against US technology companies operating in Gulf states — messaging it assessed as designed to generate fear and disrupt business activity rather than signal an imminent credible threat.
Opportunistic Cybercrime Rising
Beyond state-linked and ideologically motivated activity, opportunistic cybercrime has surged in parallel with the conflict. NCC Group cited a significant jump in malicious traffic, including credential harvesting, automated scanning and botnet reconnaissance, with financial services, eCommerce, gaming and technology organisations particularly exposed.
For organisations assessing their own exposure, NCC Group said risk remains broadly tied to geography, commercial relationships and perceived political alignment. Those operating in Israel, or maintaining commercial or government ties with Israel or the US, are considered the most exposed. The UK's National Cyber Security Centre (NCSC) reinforced the warning, stating that Iranian state and Iran-linked cyber actors "almost certainly currently maintain at least some capability to conduct cyber activity.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.