
Iran Cyber Escalation Intensifies as Connectivity Fails and Hacktivists Rise
Following Feb 28, 2026 U.S.–Israel strikes, Iran’s cyber posture shifts amid severe internet outages that likely constrain state-aligned actors, while hacktivist groups and other threat actors expand globally with low-to-medium impact activities (DDoS, data leaks, phishing). Unit 42 observes active phishing via a malicious Android app and notes a surge in cyber activism tied to an “Electronic Operations Room.” Defensive guidance emphasizes offline backups, out-of-band verification, patching internet-facing assets, phishing awareness, IP geofencing, and robust incident response; multi-layer defense and ongoing updates from cyber authorities are advised as activity remains fluid.