What the Middle East Conflict Reveals About the Mechanics of Major Cyber Crises

Threat Signal EP02 | Analysis by Alix Cocard, CTI Analyst, Citalid
Introduction
In late February 2026, the United States and Israel launched military operations Epic Fury and Roaring Lion against Iran. Within hours, a second theater opened in parallel: state-sponsored espionage, infrastructure sabotage, coordinated hacktivist campaigns, large-scale disinformation operations. A cyber confrontation whose effects did not stop at the borders of the Middle East.
That is what the second episode of Threat Signal documents in 30 minutes: who is acting, according to what logic, and why European organizations that consider themselves neither targets nor belligerents are nonetheless exposed.
A Conflict That Extends Far Beyond the Middle East
The launch of the American-Israeli military operations Epic Fury and Roaring Lion can be explained by the convergence of several structural factors: the persistent fear of Iran acquiring nuclear weapons, Tehran’s support for its regional proxies, Hamas, Hezbollah and the Houthis, despite their progressive weakening since 2023, and an internal Iranian instability that has worsened since December 2025.
Explore how Citalid maps and tracks the threat actors targeting your sector
EXPLORE THREAT EXPOSUREThis conflict is not an isolated episode. Direct and indirect confrontations between these actors have been frequent and documented for over two decades. Stuxnet, discovered in 2010 and attributed with high confidence to Israel and the United States, remains the historical reference point: the first malware designed for physical sabotage of industrial infrastructure, it contributed to shaping Iran’s cyber offensive capabilities. Recent discoveries suggest that sabotage operations actually preceded Stuxnet, most notably the Fast16 worm, identified in 2026 but believed to predate it.
What distinguishes the current cycle from previous episodes is its scale and duration. In the weeks leading up to the operations, the United States deployed its largest military force in the Middle East since 2003. However, the Iranian regime, structured around a so-called “mosaic defense” doctrine with decentralized command structures, has proven particularly resilient in the face of the elimination of senior officials. As a result, the Trump and Netanyahu administrations continue to contend with this strategy without having been able to permanently neutralize the regime.
Five Categories of Iranian Operations, One Coherent Logic
Since the beginning of the conflict, Citalid has identified five major categories of operations attributed to Iranian threat actors, which together form a coherent ecosystem rather than a set of disconnected actions.
Espionage campaigns target sectors of strategic interest to the regime, conducted both before and during the conflict, with the objective of intelligence collection.
Sabotage operations have mobilized approximately 70 hacktivist actors, primarily pro-Iranian, pro-Palestinian, and pro-Russian. These actors conducted DDoS attacks under the banners of the historic hacktivist campaigns #OpIran and #OpIsrael. The observed activity remains, however, below the levels recorded during the Twelve-Day War of June 2025, likely due to internet shutdowns imposed by the Iranian regime itself, which may have prevented some actors from operating from within Iran.
Destructive operations represent the most operationally concerning category, notably through the deployment of wipers (malware designed to permanently erase data stored in an information system). The attack against Stryker on March 11 is the most striking example: the pro-Iranian hacktivist persona Handala claimed to have deployed a wiper that erased over 200,000 internal systems, servers, and mobile devices.
Hack-and-leak operations combine the exfiltration of sensitive data with its public release, with the objective of destabilizing, humiliating, and applying pressure on the target. On March 27, Handala claimed to have compromised the personal email account of FBI Director Kash Patel, subsequently publishing private photographs and exchanges on social media platforms. No government data was disclosed. The objective was purely symbolic, carried out in retaliation for legal actions taken by the FBI against the threat actor just days earlier.
Disinformation campaigns illustrate a growing integration of artificial intelligence into Iranian propaganda production mechanisms: the Lego campaign, producing visual content ridiculing Trump and Netanyahu in a universal and highly shareable graphic universe, generated nearly one billion views in 50 days.
Finally, ransomware attacks, whose ultimate motivation, whether financial gain or destabilization, remains difficult to assess.
Behind the Hacktivists, the State: Four Layers of the Iranian Ecosystem
One of the most significant analytical contributions of this episode concerns the actual structure of the Iranian cyber ecosystem, which is composed of distinct actors and too often reduced to a monolithic bloc.
State structures at the top, comprising the Islamic Revolutionary Guard Corps (IRGC), which reports directly to the Supreme Leader, and the Ministry of Intelligence and Security (MOIS), under the authority of the President.
State-sponsored threat actors, operating under the direction of these two structures. They primarily conduct low-visibility espionage campaigns.
Hacktivist personas (including Handala, Ababil of Minab, and Homeland Justice) which publicly present themselves as independent actors, but for which converging evidence supports the hypothesis that they operate under the direction of state-sponsored threat actors.
Independent hacktivists, finally, aligned with Iranian interests and the regime’s ideology, without necessarily maintaining direct links with the authorities.
The distinction between hacktivist personas and independent hacktivist actors rests on several analytical criteria: the sophistication of the tools and infrastructure employed, targeting patterns consistent with the strategic objectives of the Iranian state, the timing of disclosures aligned with geopolitical events, and the deliberate selection of published data to maximize political and psychological impact. As Alix Cocard notes:
There is no single definitive indicator, it is a body of converging evidence that allows us to build and reinforce an attribution hypothesis.
Mustang Panda in 48 Hours: The Opportunism Lesson
A key strategic dynamic to factor in is that in times of conflict, or at minimum heightened geopolitical tension, opportunistic third-party actors will likely seek to exploit the situation to their advantage. Their objectives can be twofold: collecting intelligence on the intentions and capabilities of the belligerents, and/or indirectly supporting one of the parties.
A concrete illustration involves a Chinese state-sponsored threat actor. According to the American cybersecurity vendor Zscaler, Mustang Panda launched an espionage campaign targeting the Gulf region in less than 48 hours after the strikes began.
This speed of action is not incidental, and it is not an isolated case. It signals a deliberate intent to immediately capitalize on the context in order to collect intelligence from strategic institutions, at a moment when the security teams of targeted organizations are saturated and response capacities are constrained. These types of actors exploit this kind of context to conduct operations that would be significantly harder to execute under normal circumstances. This is a dynamic that CISOs must integrate into their threat models.
Three Risk Dimensions for Your Organization
The first question to ask security leaders and financial executives is the following: how does this conflict concretely affect your organization if it does not operate in the Middle East?
Alix Cocard identifies three distinct risk dimensions that allow this question to be answered without approximation.
The first is direct cyber risk: system compromise, service unavailability, data breaches, and remediation costs. These impacts can affect an organization because it operates in a sector of strategic interest, because it represents an entry point to a more visible target, or simply because it falls within the scope of a broad-spectrum campaign.
The second is indirect economic risk: disruption of supply flows, exposure of third-party vendors, or the breakdown of critical dependencies. A conflict of this nature does not follow a direct attack logic. The closure of the Strait of Hormuz by Iranian authorities since the beginning of the conflict illustrates perfectly how a geopolitical decision translates into economic consequences for organizations whose value chains depend on those flows.
The third is reputational risk: in this type of conflict, an organization can be impacted not only in its systems, but in its reputation, public image, credibility, and the trust of its stakeholders, particularly if data is exfiltrated and published as part of a hack-and-leak operation.
Key Takeaways
- Iran operates through an ecosystem structured in four layers, where hacktivist personas such as Handala likely serve as vectors for state operations, allowing the regime to maintain plausible deniability.
- In a conflict of this scale, opportunistic third-party actors capitalize on the saturation of security teams within hours, as illustrated by Mustang Panda in the Gulf.
- The risks for a European organization fall into three distinct categories: direct cyber risk, indirect economic risk via supply chain dependencies, and reputational risk via hack-and-leak operations.
Watch the Replay
Watch Alix Cocard’s full analysis of the Iran-Israel-US cyber conflict, the actors involved, and the implications for your organization.
