Iran Accelerates Cyber Operations Against Israel

A picture published by Microsoft of the Iranian flag and above it digital symbols.
A picture published by Microsoft of the Iranian flag and above it digital symbols.
TT

Iran Accelerates Cyber Operations Against Israel

A picture published by Microsoft of the Iranian flag and above it digital symbols.
A picture published by Microsoft of the Iranian flag and above it digital symbols.

Since Hamas attacked Israel in October 2023, Iranian government-aligned actors have launched a series of cyberattacks and influence operations (IO) intended to help the Hamas cause and weaken Israel and its political allies and business partners, a report by Microsoft showed.

Iranian focus on Israel has intensified. The outbreak of the Israel-Hamas war saw 43% of Iranian nation-state cyber activity focused on Israel.

Many of Iran’s immediate operations after October 7 were hasty and chaotic – indicating it had little or no coordination with Hamas – but it nevertheless has achieved growing success.

The report also noted collaboration between Iran and a group affiliated with Hezbollah in Lebanon.

Iran will continue to test redlines, as they have done with an attack on an Israeli hospital and US water systems in late November.

As we look forward to the 2024 US presidential election, Iranian activities could build on what happened in 2020 when they impersonated American extremists and incited violence against US government officials.

Three phases of Iran’s cyber operations

Iran’s cyber-enabled operations in the Israel-Hamas war have moved through three phases since October 7.

Phase 1: Reactive and misleading

The first phase saw misleading claims from Iranian state media. One example was IRGC-affiliated Tasnim News Agency claiming that a group called “Cyber Avengers” had conducted cyberattacks against an Israeli power plant “at the same time” as the Hamas attacks. Cyber Avengers itself (also likely run by the IRGC) claimed to have attacked an Israeli electric company the evening before the Hamas attacks. However, its evidence was only some weeks-old press reporting of power outages “in recent years” and a screenshot of an undated disruption to the company’s website.

Phase 2: All hands on deck

Sometimes, multiple Iranian groups were targeting the same organization or military base in Israel with cyber or influence activity. This suggests coordination, common objectives set in Tehran, or both.

Iran’s 10 cyber-enabled operations against Israel in October marks a new high point. This was nearly double the previous high point of six operations per month in November 2022.

One example happened on October 18 when the IRGC’s Shahid Kaveh Group used customized ransomware to conduct cyberattacks against security cameras in Israel. It then used one of its cyber personas, “Soldiers of Solomon,” to falsely claim it had ransomed security cameras and data at Nevatim Air Force Base. Examination of the security footage Soldiers of Solomon leaked reveals it was from a town north of Tel Aviv with a Nevatim street, not the airbase of the same name.

Phase 3: Expanding geographic scope

In late November 2023, Iranian groups began expanding their cyber-enabled influence beyond Israel, targeting countries Iran perceives are supporting Israel. This aligned with the Iran-backed Houthis starting their attacks on international shipping.

On November 20, the MOIS-aligned cyber persona “Homeland Justice” warned of forthcoming cyberattacks on Albania. They later claimed credit for attacks on a range of Albanian organizations and institutions.

On November 21, the cyber persona “al-Toufan” targeted Bahraini government and financial organizations for normalizing ties with Israel.

By November 22, IRGC-affiliated groups began targeting Israeli-made programmable logic controllers (PLCs) in the United States, including taking one offline at a water authority in Pennsylvania on November 25. PLCs are industrial computers adapted for the control of manufacturing processes, such as assembly lines, machines, and robotic devices.

Since the outbreak of the Israel-Hamas war on October 7, Iran has increased its influence operations and hacking efforts against Israel. These attacks were reactive and opportunistic in the early days of the war but, by late October, nearly all of its influence and major cyber actors were targeting Israel.

Cyberattacks became increasingly targeted and destructive and IO campaigns grew increasingly sophisticated and inauthentic, deploying networks of social media “sockpuppet” accounts.

Iran’s activity quickly grew from nine Microsoft-tracked groups active in Israel during the first week of the war to 14, two weeks into the war. Cyber-enabled influence operations went from roughly one operation every other month in 2021 to 11 in October 2023 alone.

A 42% increase in traffic, in the first week of the war, to news sites run by or affiliated to the Iranian state. Even three weeks later, this traffic was still 28% above pre-war levels.

Iran’s objectives

Destabilization through polarization

Iran aims to exacerbate domestic political and social rifts in its targets, often focusing on the Israeli government’s approach to the 240 hostages taken by Hamas into Gaza and masquerading as peace-seeking activist groups criticizing the Israeli government. Israeli Prime Minister Netanyahu is the primary target of such messaging, often calling for his removal.

Retaliation

Many of Iran’s messaging and targets are explicitly retaliatory. The persona Cyber Avengers claimed it had targeted Israeli electricity, water, and fuel infrastructure in retaliation for Israel stating it would cut off electricity, water and fuel to Gaza and elsewhere referenced “an eye for an eye.”

Intimidation

Iran’s operations also aim to undermine Israeli security and intimidate Israel’s citizens and international supporters and threaten the families of Israeli army soldiers. Sockpuppet accounts spread messaging on X that the army “does not have any power to protect its own soldiers.” Other messaging, as in the example below, appears aimed at attempting to convince Israeli army soldiers to give up.

Undermining international support for Israel

Iranian Influence actors often include messaging that seeks to weaken international support for Israel by highlighting the damage caused by Israel’s attacks on Gaza.

Iran AI-generated attacks

In early December 2023, Iran interrupted streaming television services and replaced them with a fake news video featuring an apparently AI-generated news anchor. This marked the first Iranian influence operation Microsoft has detected where AI played a key component in its messaging and is one example of the fast and significant expansion in the scope of Iranian operations since the start of the Israel-Hamas conflict. The disruption reached audiences in the UAE, UK, and Canada.

Microsoft’s AI for Good Lab’s Iranian Propaganda Index (IPI) monitors the proportion of traffic visiting Iranian state and state-affiliated news outlets and amplifiers compared to overall traffic on the internet.

In the first week of the conflict, we observed a 42% increase. That surge was particularly pronounced in the United States and its English-speaking allies (UK, Canada, Australia, and New Zealand), which indicates Iran’s ability to reach Western audiences with its reporting on Middle East conflicts.

While this success was strongest in the early days of the war, the reach of these Iranian sources one month into the war remained 28% above pre-war levels globally.

Trends in Iranian influence operations

Impersonation is not new, but Iranian threat actors are now not just masquerading as their enemies but also their friends. Recent operations from Iranian groups have used the name and logo of Hamas’s military wing, the al-Qassam Brigades, to spread false messaging and threaten Israeli army personnel. It is unclear whether Iran is acting with Hamas’s consent.

Iran has managed to repeatedly recruit unwitting Israelis to engage in on-the-ground activities promoting its false operations. In one recent operation, “Tears of War,” Iranian operatives convinced Israelis to hang branded Tears of War banners using AI-generated images in Israeli neighborhoods, based on Israeli press reporting. A Tears of War banner with an image of Netanyahu that is likely AI-generated. The banner’s text reads “Impeachment now.”

Iran’s use of bulk text message and email campaigns has grown in order to enhance the psychological effects of their cyber-enabled influence operations. Messages appearing on people’s phones or in their inboxes have more impact than sockpuppet accounts on social media. Iran uses overt and covert IRGC-linked media outlets to amplify alleged cyber operations and, at times, exaggerate their effects. In September, after Cyber Avengers claimed cyberattacks against Israel’s railway system, IRGC-linked media almost immediately amplified and exaggerated their claims.



Officials: Torrential Rains in Kenya Kill 81 in March

Officials: Torrential Rains in Kenya Kill 81 in March
TT

Officials: Torrential Rains in Kenya Kill 81 in March

Officials: Torrential Rains in Kenya Kill 81 in March

Torrential storms that have triggered flash floods in Kenya have killed at least 81 people this month, authorities said Sunday, as rain continued to pound much of the country.

"The cumulative number of fatalities has unfortunately risen to 81," national police spokesman Muchiri Nyaga said in a statement.

"Additionally, flash floods have swept through several areas, displacing approximately 2,690 families and causing widespread destruction of infrastructure and property."

The capital Nairobi is the hardest-hit region, with 37 people killed, he said.

On Friday night, authorities called on residents to evacuate several slum neighborhoods downstream from the Nairobi dam, warning of an imminent risk of flooding as rising water levels threatened to breach the dam embankment, according to local media.

The dam has held so far.

Two people drowned overnight in floods in the town of Kiambu, just outside the capital, police told AFP.

Two also died as landslides hit the western village of Kasaka, burying numerous homes, reported private broadcaster Citizen TV.

The rain is forecast to continue until Tuesday.

Authorities called for "extreme caution".

The March rains have repeatedly turned Nairobi streets to raging rivers, flooding thousands of homes and businesses.

Critics have called for the resignation of Nairobi Governor Johnson Sakaja, who had vowed to improve the capital's drainage and road infrastructure when he took office in 2022.

Scientists say human-caused climate change is increasing the probability, length and severity of extreme weather events.

Studies indicate east Africa has been hit by more extreme rains and droughts over the past two decades.


1 Dead in Istanbul after Gas Explosion Collapses 2 Buildings

Police secure the way to a site where two residential buildings collapsed in Istanbul, Sunday, March 22, 2026. (AP Photo/Khalil Hamra)
Police secure the way to a site where two residential buildings collapsed in Istanbul, Sunday, March 22, 2026. (AP Photo/Khalil Hamra)
TT

1 Dead in Istanbul after Gas Explosion Collapses 2 Buildings

Police secure the way to a site where two residential buildings collapsed in Istanbul, Sunday, March 22, 2026. (AP Photo/Khalil Hamra)
Police secure the way to a site where two residential buildings collapsed in Istanbul, Sunday, March 22, 2026. (AP Photo/Khalil Hamra)

A natural gas explosion in Istanbul’s central Fatih district brought down two buildings on Sunday, killing one person.

Search and rescue personnel pulled out 10 injured who were hospitalized, including one in critical condition, according to a statement by the Istanbul Governor’s office.

The governor, Davut Gul, visited the site of the explosion and checked on survivors at the hospital.

One of the collapsed buildings had two stories, the other one.


Iran Threatens to Retaliate against Gulf Energy and Water after Trump Ultimatum

epa12835579 Liquefied natural gas (LNG) facilities in Ras Laffan Industrial City, in Ras Laffan, Qatar, 25 February 2026 (issued 20 March 2026). Qatar has said Iranian missile attacks on the Ras Laffan Industrial City have caused significant damage to the natural gas industrial complex, located approximately 80 km north-east of Doha. It is operated by Qatar Energy and employs around 115,000 people according to the company.  EPA/HANNIBAL HANSCHKE
epa12835579 Liquefied natural gas (LNG) facilities in Ras Laffan Industrial City, in Ras Laffan, Qatar, 25 February 2026 (issued 20 March 2026). Qatar has said Iranian missile attacks on the Ras Laffan Industrial City have caused significant damage to the natural gas industrial complex, located approximately 80 km north-east of Doha. It is operated by Qatar Energy and employs around 115,000 people according to the company. EPA/HANNIBAL HANSCHKE
TT

Iran Threatens to Retaliate against Gulf Energy and Water after Trump Ultimatum

epa12835579 Liquefied natural gas (LNG) facilities in Ras Laffan Industrial City, in Ras Laffan, Qatar, 25 February 2026 (issued 20 March 2026). Qatar has said Iranian missile attacks on the Ras Laffan Industrial City have caused significant damage to the natural gas industrial complex, located approximately 80 km north-east of Doha. It is operated by Qatar Energy and employs around 115,000 people according to the company.  EPA/HANNIBAL HANSCHKE
epa12835579 Liquefied natural gas (LNG) facilities in Ras Laffan Industrial City, in Ras Laffan, Qatar, 25 February 2026 (issued 20 March 2026). Qatar has said Iranian missile attacks on the Ras Laffan Industrial City have caused significant damage to the natural gas industrial complex, located approximately 80 km north-east of Doha. It is operated by Qatar Energy and employs around 115,000 people according to the company. EPA/HANNIBAL HANSCHKE

Iran said on Sunday it would strike the energy and water systems of its Gulf neighbors in retaliation if US President Donald Trump follows through with a threat to hit Iran's electricity grid in 48 hours, escalating the three-week-old war.

The prospect of tit-for-tat strikes on civilian infrastructure could deepen the regional crisis and rattle global markets when they reopen on Monday morning, Reuters reported.

Air raid sirens sounded across Israel from the early hours of Sunday, warning of incoming missiles from Iran, after scores of people were hurt overnight in two separate attacks in the southern Israeli towns of Arad and Dimona.

The Israeli military said hours later that it was striking Tehran in response.

Trump threatened overnight to "obliterate" Iran's power plants if Tehran did not fully reopen the Strait of Hormuz within 48 hours, barely a day after he talked about "winding down" the war. He made the new threat as US Marines and heavy landing craft are heading to the region.

Iran's Parliament Speaker Mohammad Baqer Qalibaf wrote on X that critical infrastructure and energy facilities in the Middle East could be "irreversibly destroyed" should Iranian power plants be attacked.

Iran's powerful Revolutionary Guards said it would also mean the shipping lane where a fifth of global oil and liquefied natural gas normally transits along Iran's southern coast would remain shut.

"The Strait of Hormuz will be completely closed and will not be opened until our destroyed power plants are rebuilt," the Guards said in a statement.

"President Trump's threat has now placed a 48-hour ticking time bomb of elevated uncertainty over markets," said IG market analyst Tony Sycamore, who expects stock markets to fall when they reopen on Monday.

Oil prices jumped on Friday, ending the day at their highest in nearly four years.

Markets already under severe strain from blockaded shipping were further rattled last week when Israel attacked a major gas field in Iran, and Tehran responded with strikes on neighbors Saudi Arabia, Qatar and Kuwait, raising the prospect of damage hindering energy output even if tankers resume sailing.

Iranian attacks have effectively closed the Strait of Hormuz, causing the worst oil crisis since the 1970s. Its near-closure sent European gas prices surging as much as 35% last week.

"If Iran doesn't FULLY OPEN, WITHOUT THREAT, the Strait of Hormuz, within 48 HOURS from this exact point in time, the United States of America will hit and obliterate their various POWER PLANTS, STARTING WITH THE BIGGEST ONE FIRST!" Trump posted on social media around 7:45 p.m. EDT (2345 GMT) on Saturday.

Iranian media quoted the country's representative to the International Maritime Organisation as saying the strait remains open to all shipping except vessels linked to "Iran's enemies".

Ali Mousavi said passage through the waterway was possible by coordinating security and safety arrangements with Tehran.

Ship-tracking data shows some vessels, such as Indian-flagged ships and a Pakistani oil tanker, have negotiated safe passage through the strait. But the vast majority of ships have remained holed up inside.

Iran's Khatam al-Anbiya military command headquarters said on Sunday if the US hit Iran's fuel and energy infrastructure, Iran would attack all US energy, information technology and desalination infrastructure in the region.

Striking major Iranian power plants could trigger blackouts, crippling everything from pumps and refineries to export terminals and military command centres.