7 August 2026
This blog post explores the question of offensive cyber operations (“hacking”) in the context of the 2026 US-Israel-Iran war and uses that pretext to attempt a broader treatment of hacktivism and cognitive impacts as a cyberthreat. It’s not a geopolitical assessment nor a comprehensive threat-actor analysis, as these have both been thoroughly addressed and we wouldn’t be qualified to add more.
Instead, it dares to glance tentatively into the future and consider the role of Iranian state-aligned (“Establishment”) hacktivists, which we argue are likely to play an enduring and significant role during and beyond the conflict.
We spend some time therefore revisiting the history and formative experiences that have shaped Iran’s perspectives on conflict, and examine the country’s foundational views on the internet, cyberspace and information systems. This assessment helps justify our assertions regarding the likely role of hacktivism going forward.
We then examine the evolution and nature of modern hacktivism to understand what it means as a threat, especially to modern businesses, and why the threat will likely endure.
By expounding on a fundamental understanding of the cognitive nature of hacktivist attacks, we step beyond Iran and expand our analysis to consider cognitive effects more broadly and discuss why businesses should worry about these. Our hope is that this discussion will draw readers into a separate paper we’ve recently published that discusses cognitive threats and attacks in a wider sense and examines how businesses and institutions can develop strategies to defend against them.
Finally, we present a brief overview of cognitive attacks in general, the impacts they can have and the form they can take.
We conclude by arguing that most cyber-attacks have a cognitive element and should thus be considered alongside the other threats within the broader spectrum of cognitive weapons – but also that cognitive impacts, alongside technical and financial impacts, should be viewed as part of a “cohesive pressure system” that is imposing enormous cost on our societies and economies and demands a collaborative response.
The 2026 US-Israeli war against Iran began on February 28, 2026, when the US and Israel launched massive airstrikes targeting Iran’s nuclear and military facilities – described by US authorities as twice the scale of the 2003 “shock and awe” campaign[1]. The attack followed years of rising tensions over Iran’s nuclear program, ballistic missiles, and regional military influence, especially after the collapse of the 2015 Joint Comprehensive Plan of Action (JCPOA) and failed renegotiation attempts[2].
The immediate path to the 2026 war was shaped by a series of escalating military and diplomatic developments. Israel and Iran had already fought a twelve-day war in June 2025, during which the United States bombed Iranian nuclear facilities[3]. That same month, the International Atomic Energy Agency (IAEA) found Iran noncompliant with its nuclear safeguard’s obligations[4]. Resultant restrictions on inspections prevented the Agency from accessing several damaged facilities and verifying Iran’s enriched uranium stockpile[5]. The sanctions regime was reimposed in September 2025, further increasing pressure on Tehran and weakening diplomatic efforts. Still, US-Iranian negotiations continued until shortly before the February 2026 attack[6].
Iran’s nuclear activities remained a central source of concern, particularly its stockpile of enriched uranium and the reduced visibility of international inspectors. There was no officially reported evidence of a structured nuclear weapons program, but public US intelligence statements continued to signal doubts and concerns[7]. The conflict therefore emerged from a combination of military escalation, weakened verification, growing uncertainty over Iran’s nuclear capabilities, and the failure of diplomacy to produce a lasting agreement.
The US assault resulted in the death of Iran’s Supreme Leader Ali Khamenei, who was succeeded by his son, Mojtaba Khamenei.
Iran retaliated with ballistic missiles and drones, striking civilian and military targets, including US bases and Gulf oil infrastructure, and disrupting global trade routes, particularly in the Strait of Hormuz. By early April, authorities were reporting several thousand deaths across Iran and Lebanon, alongside casualties in Israel and the Gulf. More than a million people had reportedly been displaced in Lebanon, leading to widespread regional instability.
Following the opening attacks, the United States and Israel maintained a prolonged campaign against Iranian command structures, military forces and assets, and nuclear-related facilities, while Iran continued to launch ballistic missiles and drones against Israel, US bases, and military and civilian sites across the Gulf. Iran also restricted commercial passage through the Strait of Hormuz, prompting the United States to expand military operations intended to restore freedom of navigation[8]. At the same time, Hezbollah entered the conflict by attacking Israel from Lebanon, leading Israel to conduct extensive airstrikes and ground operations in southern Lebanon. The fighting expanded into Beirut and killed thousands of people, displaced more than one million Lebanese, and continued through repeated efforts to establish a ceasefire[9].
By June, Hormuz had become the central source of Iranian leverage and one of the principal subjects of negotiation. Iran’s ability to restrict traffic partially offset US–Israeli air superiority and changed the conflict from a campaign primarily focused on Iran’s leadership and nuclear infrastructure into a coercive struggle over maritime access, oil flows, port blockades and the terms of a settlement.
For a short time, the hostilities subsided, the world turned its attention to other things, and we hesitated about publishing this blog. In mid-June, the United States and Iran announced an interim framework intended to end hostilities, reopen the Strait of Hormuz and begin a 60-day process to address the nuclear and enriched-uranium stockpile, although the agreement’s interpretation was contested from the outset. The memorandum of understanding (MoU) was signed with US President Trump famously at the Palace of Versailles on 17 June.
Then, on 25 June, an Iranian drone attack on a commercial vessel using an alternative US-protected shipping route triggered renewed exchanges. By mid-July, the interim arrangement had effectively collapsed and major fighting had resumed. It continues still as we eventually do publish this blog.
Roots
Modern Iran understands itself as a Persian civilization whose identity is rooted in ancient imperial history and shaped in the 16th century through the institutionalization of Shia Islam, then consolidated into today’s Islamist political system following the 1979 revolution.
The current tensions between Iran, the United States, and Israel are no surprise. Over the past eight decades, Iran’s political system and strategic behavior have developed largely as a response to its experience of recurring external pressures, resulting in a state that considers itself to be isolated and under assault, and thus prioritizes autonomy, deterrence, and long-term resilience.
The roots of this current tension go back to World War II, when British and Soviet forces invaded Iran to secure supply routes, limit German influence, and protect critical oil infrastructure - which was then already dominated by British interests. Ultimately the invasion forced the abdication of the leader Reza Shah[10] and placed the country under Allied occupation. For Iran it was the repeat of an even older pattern in which Iran’s most valuable resources remained effectively under the control of foreign powers.
Coup & Revolution
This perception would later culminate in efforts to nationalize the oil industry in 1951. In response to that, the United States and United Kingdom supported a coup in Iran that removed Prime Minister Mohammad Mossadegh[11]. This entrenched an enduring perception among Iranian elites that Western powers would intervene in Iran’s internal affairs whenever their strategic interests are at stake.
After the coup, the rule of Shah Mohammad Reza Pahlavi, who reigned from 1941 to 1979, improved relationships with the West and deepened Iran’s alignment with the United States. With Western political and security support, the Shah pursued modernization and maintained a close strategic partnership with the US. But the period also brought domestic political repression and growing social inequality. By the late 1970s, widespread dissatisfaction culminated in the 1979 Islamic Revolution, which ultimately replaced the monarchy with a clerical-led republic under Ayatollah Ruhollah Khomeini. His new regime explicitly rejected Western influence and reoriented Iran’s identity around Shia Islam, independence, religious governance, and resistance to external domination. Following Khomeini’s death in 1989, Ali Hosseini Khamenei became supreme leader and consolidated political, military, and ideological authority over the following three decades[12].
The revolution was quickly followed by a defining rupture in US-Iran relations. In November 1979, Iranian students seized the US embassy in Tehran, famously holding 52 American diplomats hostage for 444 days. The crisis not only destroyed diplomatic ties, but also consolidated power among revolutionary hardliners in Iran, embedding mutual hostility into the political systems of both countries.[13] Analysts suggest that “Western policymakers have severely underestimated the extent of Iran’s commitment to upholding and exporting 1979’s revolutionary ideology” across the region.[14]
Iraq & the Tanker Wars
Even before the resolution of the embassy saga, the Iran-Iraq War (1980–1988) proved decisive in further shaping Iran’s modern security doctrine. After Iraq invaded Iran, several Gulf monarchies provided Baghdad with extensive financial support, while the Soviet Union and France became important arms suppliers. The United States increasingly tilted toward Iraq after Iran recovered its occupied territory and carried the war into Iraq. This period also involved the infamous Iran-Contra affair[15]. Iraq’s chemical attacks and the weak international response became central elements of Iran’s historical memory.
Iran was placed in a prolonged and costly conflict that was marked by international isolation and exacerbated by the traumatic use of chemical weapons against Iranians. The war reinforced Iran’s perception of strategic vulnerability and spurred the development of unconventional defense capabilities like missile programs, paramilitary networks, proxy networks and the institutional expansion of the Islamic Revolutionary Guard Corps (IRGC)[16].
The “Tanker War” was a maritime phase of the Iran–Iraq War in which Iran and Iraq targeted oil tankers and commercial shipping in the Persian Gulf to undermine each other’s economic lifelines.[17] It’s a significant event in Iran’s history and worth taking a moment to note. Iraq initiated the campaign by striking vessels linked to Iranian exports, seeking to reduce Iran’s war financing, while Iran retaliated by attacking shipping associated with Iraq and its regional backers, notably expanding the conflict to neutral vessels. The campaign evolved into a broader strategy of economic attrition and coercion, with both sides employing missiles, aircraft, mines, and small-boat attacks to disrupt global oil flows and impose costs without decisive naval battles.[18] By the late 1980s, hundreds of vessels had been damaged or destroyed and external powers, including the United States, intervened to escort shipping and stabilize transit routes. The incident illustrated to Iran how limited, asymmetric maritime pressure could generate global economic and strategic effects disproportionate to the scale of direct military engagement.
Two further events made the Tanker War especially important in Iran’s strategic memory. In April 1988, the United States launched “Operation Praying Mantis” after an American warship struck an Iranian mine. US forces attacked Iranian offshore platforms and naval vessels, inflicting serious losses and demonstrating the risks Iran faced in conflict with a stronger power[19]. Three months later, the USS Vincennes shot down Iran Air Flight 655 over the Persian Gulf, killing all 290 people aboard[20]. The United States maintained that the civilian airliner had been misidentified during a tense military encounter, while Iran viewed the incident as evidence of American hostility and the lack of international accountability.
The Tanker Wars and related events thus reinforced Iran’s emphasis on deterrence, asymmetric warfare, and caution in direct confrontation with the United States. In the decades that followed, Iran has consistently sought to mitigate its conventional military disadvantages through asymmetric means, including cultivating regional alliances and non-state partners.
The nuclear program
Alongside its development of asymmetric military capabilities and regional partnerships, Iran also pursued greater strategic and technological independence through its nuclear program. Initially developed under the Shah with Western assistance, the program was disrupted after the 1979 revolution but gradually revived during the 1980s and expanded considerably in the 1990s and early 2000s, causing growing concern in Israel and the West.
By 2015, negotiations between Iran and world powers resulted in the Joint Comprehensive Plan of Action (JCPOA), under which Iran agreed to limit its nuclear activities in exchange for sanctions relief. The agreement produced a temporary easing of tensions, but the United States withdrew in 2018, and Iran subsequently reduced its compliance in stages, expanded uranium enrichment, and restricted international verification. The diplomatic framework deteriorated over several years, culminating in the reimposition of UN sanctions in September 2025. These developments increased concern about Iran’s nuclear capabilities, although they did not by themselves establish that Iran had begun an active nuclear weapons program[21].
Tensions escalate
The targeted killing of Iranian General Qassem Soleimani by the United States in 2020 further escalated tensions, bringing the two countries to the brink of direct conflict[22].
Iran’s strategic rivalry with Israel intensified at the same time, primarily through indirect confrontation. Iran’s support for armed groups such as Hamas, Hezbollah, and The Houthis in Yemen, combined with Israel’s sustained campaign of airstrikes against diverse Iranian-linked targets, produced an ongoing “shadow war” across the region, while Iran’s continued advancement of missile and nuclear capabilities heightened Israeli security concerns
Iran’s Grand Strategy
Experts argue that Iran’s strategic behavior has evolved through this history to reflect an enduring emphasis on sovereignty, regime security, and resistance to perceived external coercion. As noted by Vali Nasr in “Iran's Grand Strategy”[23], Iran’s actions are best understood as part of a coherent long-term strategy shaped by past conflicts and a persistent sense of insecurity.
Of course, Iran’s strategic outlook has also been shaped by domestic insecurity. The Islamic Republic has faced recurring challenges from political reform movements, economic hardship, ethnic and regional tensions, and widespread protests, including the 2009 Green Movement, the demonstrations of 2019, and the “Woman, Life, Freedom” movement that began in 2022. But the current tensions between Iran, the United States, and Israel are not isolated developments, but the continuation of a political environment defined by mutual distrust, asymmetric competition, and periodic escalation.
Emerging from Iran’s experience during the Iran-Iraq War, came the idea of “Sacred Defense”, which the government presents as a war forced upon the country by outside powers. Within this narrative, Iran is not just defending its borders but also protecting its revolution and Islamic system. Drawing on the long history of foreign intervention and Shiite traditions that emphasize sacrifice and martyrdom, Sacred Defense blends religion with national identity. Over time, it has become a key part of how Iran understands security and thus supports a strategy that focuses on resilience, indirect conflict, and the use of regional allies to deter stronger adversaries.
As highlighted in the work of Vali Nasr, Ali Hosseini Khamenei’s significance lies in how he shifted Iran’s strategy from revolutionary fervor toward a long-term, pragmatic model focused on regime survival, strategic patience, and regional influence. Nasr describes Iran under Khamenei as pursuing a “grand strategy of resistance” that blends ideology with calculated statecraft, using alliances and indirect tools to outlast stronger adversaries. This was a subtle but important evolution from Khomeini’s more ideologically driven posture to a system that still drew on revolutionary ideas but applied them in a flexible, strategic way over time. Compared to Khomeini’s charismatic and doctrinal leadership, Khamenei governed in a more institutional and pragmatic way, relying heavily on the security apparatus and clerical networks to maintain control.[24]
Iranian leaders increasingly came to believe that threats should be confronted far from Iran’s borders before they could reach the country itself.[25] When the Syrian government of Bashar al-Assad faced collapse during the civil war, Iran viewed the conflict as a direct threat to its strategic depth, its alliance network, and its access to Hezbollah in Lebanon. Under the leadership of the IRGC Quds Force and Qassem Soleimani, Iran deployed advisers, proxy militias, and foreign Shia fighters from Iraq, Afghanistan, and Pakistan to sustain the Assad government and preserve what Iranian officials increasingly described as the “Axis of Resistance”. Over time, the Syrian war helped institutionalize “Forward Defense” as a central part of Iran’s strategic thinking, blending pragmatic security concerns with ideological narratives of resistance, sacrifice, and long-term regional influence.[26]
Partners and Proxies
Hamas and Palestinian Islamic Jihad
Hamas emerged in Gaza in 1987 as a Palestinian Sunni Islamist movement rooted in the Muslim Brotherhood. Relations with Iran developed during the early 1990s as both opposed Israel and the Oslo peace process, despite their religious and political differences. Iran subsequently provided Hamas with financial support, military training, weapons, rocket technology, and assistance in developing domestic production capabilities[27].
The relationship deepened after Hamas won the 2006 Palestinian elections and took control of Gaza in 2007. For Iran, Hamas created a source of military pressure close to Israel’s population centers and forced Israel to devote air-defense, intelligence, and military resources to its southern front. Its support also allowed Tehran to present itself as a defender of the Palestinian cause and to extend the Axis of Resistance beyond its mainly Shia allies.
Hamas should be considered an “Iran-backed partner”. It has its own Palestinian nationalist and Sunni Islamist objectives, maintains relationships with states such as Qatar and Turkey, and has taken decisions that conflicted with Iranian interests. Iran provides important financial, military, and technical support, but Hamas retains its own leadership and operational calculations. Nevertheless, its military role has formed an important part of Iran’s wider strategy of indirect pressure and Forward Defense against Israel[28].
Palestinian Islamic Jihad differs from Hamas in being a smaller and more narrowly military organization without Hamas’s comparable governing role or broad social and political network, while its financial, ideological, and military relationship with Iran has generally been closer and more dependent.
Iraqi armed groups
Iran-aligned Iraqi armed groups form another important part of the Axis of Resistance. Some, like the Badr Organization, trace their origins to Iraqi Shia opposition groups, while others (including Kata’ib Hezbollah, Asa’ib Ahl al-Haq and Harakat al-Nujaba) expanded after the 2003 invasion of Iraq and the later campaign against the Islamic State. Iran has provided these organizations with funding, weapons, training, and political support, allowing them to pressure US forces, support operations in Syria, help sustain Iran’s regional supply networks, and expand Tehran’s influence within Iraqi politics. However, their level of dependence on Iran varies considerably and they remain Iraqi organizations with their own leaders, constituencies, and political interests.
The Houthis
By the late 2010s, the Houthis were also commonly treated as part of Iran’s Axis of Resistance and served Iran’s Forward Defense by placing pressure on Saudi Arabia and threatening maritime traffic. The Houthi movement originated as a distinctly Yemeni movement and began an insurgency in 2004. Iran apparently began providing them with weapons support as far back as 2009, while the relationship deepened substantially after the Houthis seized Sana’a in 2014. Iran subsequently supplied missile and drone technology, components, training and political support, helping the Houthis develop the ability to strike Saudi Arabia, Israel and commercial shipping far beyond Yemen[29]. Their attacks after October 2023 strengthened this role well before 2026.
The Houthis occupy a distinctive place in Iran’s strategy of Forward Defense. Iranian weapons and support have helped the group develop missiles, drones and anti-ship capabilities, while its control of territory beside the Bab el-Mandeb gives the wider Axis of Resistance access to one of the world’s most important maritime routes. However, although the Houthis are significantly armed and influenced by Iran, they retain their own leadership, domestic ambitions and strategic priorities. Their role supports Iran’s strategy of indirect pressure and strategic depth, while remaining shaped by the Houthis’ own political interests and calculations[30].
The Houthis initially remained cautious during the 2026 war. They entered the confrontation more directly in late March by launching a missile towards Israel and later expanded threats and attacks against shipping and Saudi energy interests. Their position created the possibility of simultaneous pressure on Bab el-Mandeb as well as the Strait of Hormuz[31].
Hezbollah
Hezbollah has been Iran’s closest and most important regional partner since the early years of the Islamic Republic. The organization emerged among Lebanon’s Shia population following Israel’s invasion of Lebanon in 1982, when members of the IRGC deployed to the Beqaa Valley and helped organize, train, and arm several Lebanese Shia militant groups. These networks gradually developed into Hezbollah, which combined resistance to Israel with support for Iran’s revolutionary ideology and the principle of clerical rule associated with Ayatollah Ruhollah Khomeini[32].
Over the following decades, Iran provided Hezbollah with extensive funding, weapons, missile technology, training, and intelligence support. Hezbollah developed a large rocket and missile arsenal, fought Israel during the 2006 Lebanon War, and later deployed thousands of fighters to Syria in support of Bashar al-Assad’s government. For Iran, Hezbollah became a central element of Forward Defense by placing a powerful armed force close to Israel’s northern border[33].
Hezbollah also developed deep political, social, and military influence inside Lebanon and therefore retains its own leadership, domestic constituency, and institutional interests. However, its ideological, financial, and military relationship with Tehran is considerably closer than Iran’s relationships with Hamas or the Houthis. Hezbollah has repeatedly coordinated its regional activities with the IRGC and has generally supported Iran’s wider strategic priorities in Israel, Syria, and the broader Middle East. It is therefore commonly described as Iran’s principal proxy, although it remains a Lebanese organization whose decisions are also shaped by local political conditions[34].
The Persistence and Limits of Forward Defense
As the Iranian leadership became increasingly dependent on the IRGC, the organization expanded far beyond its original military and security role and Iran’s push for a “resistance economy” created new opportunities for the IRGC to consolidate control over strategic sectors. Over time, this expansion strengthened the IRGC’s influence not only over the economy, but also across Iran’s broader political system.[35]
Soleimani’s 2020 killing removed the key architect of Iran’s regional proxy network, and analysts warned at the time that it would deepen Iran’s reliance on allied militias, retaliation, and long-term pressure against US interests.[36] Indeed, the killing of Soleimani and other figures appear to have reinforced Iran’s belief in forward defense rather than weaken it. Later Israeli strikes on senior IRGC commanders in Syria and Iran showed Tehran that its forward-defense network was vulnerable but also strengthened the regime’s argument that threats must be managed before they reach Iran’s borders[37]. In Vali Nasr’s framing, Iran’s grand strategy is built around resilience, strategic depth, and a “resistance” posture, and these killings likely pushed Tehran further toward decentralized proxy activity, calibrated retaliation, and a more urgent effort to preserve influence beyond its borders.[38]
By the beginning of 2026, however, Iran’s regional position had weakened considerably. Israel’s campaign in Gaza had severely degraded Hamas’s conventional military structure, while Israeli operations in Lebanon killed Hezbollah leaders like Hassan Nasrallah and damaged much of the group’s command structure and infrastructure[39]. The fall of Bashar al-Assad’s government in December 2024 deprived Iran of a key regional ally and disrupted the Syrian supply route used to move weapons and equipment to Hezbollah[40]. Israeli strikes inside Iran in October 2024 had already demonstrated Israel’s ability to reach Iranian air-defense and missile-production facilities directly[41]. These losses were followed by the June 2025 war, in which Israeli and US attacks damaged Iran’s air defenses, missile infrastructure, command networks, and nuclear facilities[42]. Together, these developments weakened the Axis of Resistance, reduced Iran’s strategic depth, and exposed important limitations in its policy of Forward Defense.
Despite Iran’s weakened regional position, the latest war appears to have reinforced the influence of the IRGC and the wider security establishment, if also forcing them to reconsider how the doctrines of Sacred Defense and Forward Defense should be applied. The losses suffered by Iran and its regional partners exposed the limitations of its former strategy, but did not remove the regime’s emphasis on resilience, strategic depth, and resistance to external pressure. The military effectiveness of Forward Defense had declined, even as its underlying doctrine became more deeply embedded in the Iranian security establishment. As Narges Bajoghli and Vali Nasr argue, “The new leaders are establishment actors: pragmatic, hardened nationalists operating with a clear-eyed assessment of Iran’s capabilities and vulnerabilities”[43]. This suggests that the institutions and security priorities of the Islamic Republic are likely to persist, even though they may be applied through a more pragmatic assessment of Iran’s capabilities and the limits of its regional influence.
Just as Iran’s modern identity and ideology have their origins in a long history state formation, foreign intervention and conflict, the nature of the current conflict has its roots in the enduring constraints and strategic opportunities created by geography.
We’ve previously referenced the analysis of the American geopolitical analyst Peter Zeihan[44] in our work on European sovereignty and the end of the Pax Americana[45], and we’re going to do it again here. Zeihan’s perspectives are not universally accepted, but his long-standing analysis on the role of geography in the modern geopolitical reality may help inform our thoughts on the likely progress of the conflict.
The Strait of Hormuz stands as the world’s most critical oil chokepoint, directly linking Persian Gulf producers to global markets, particularly in China, India and Japan. Zeihan’s analysis across three books since 2017[46] suggests that Iran holds a unique but paradoxical position. While Tehran holds the strategic capacity to disrupt global oil flows by closing the Strait, such an action would also sever its own economic lifeline.
Zeihan posits that the US shale revolution meanwhile has reduced American reliance on Middle Eastern oil and thus contributes to a gradual retraction from its historic role as the guarantor of global maritime security. This retreat would leave a power vacuum, exposing Europe and Asia to heightened vulnerability should the Strait be blocked. Unlike Saudi Arabia and the UAE, which have pipelines through which some oil may be transported, Zeihan argues, Iran lacks significant alternative export routes, making any closure of the Strait economically damaging to its own interests. Saudi Arabia and the UAE have some pipeline capacity that can bypass Hormuz, but Iran lacks a comparable large-scale alternative export route. While Iran’s ability to constrict the Strait remains a potent geopolitical tool, its use would signal desperation, reflecting a collapse of both global order and Iran’s own strategic options.
Zeihan predicted that in a post-American global order, disruption in the Strait could trigger a severe oil crisis, particularly for China, which depends heavily on Middle Eastern imports. The resulting energy shock would force nations to secure their own supplies, likely sparking regional conflicts and economic instability. The US shale revolution has reduced American dependence on imported Middle Eastern oil and, in Zeihan’s view, weakened the strategic incentive for Washington to be guarantor of global trade. American consumers and businesses remain exposed to global energy prices, but this does spark US arguments that Europe and Asia should bear a greater share of the costs of protecting the routes.
The ongoing US-Israel-Iran war is viscerally demonstrating this structural vulnerability in an active global crisis. Since early 2026, the conflict has severely affected tanker traffic through the Strait, with the result that oil flows fell from around 20 million barrels per day before the war to an average of 2.7 million barrels per day early in the year[47], triggering what the International Energy Agency describes as the largest energy shock in modern history. Oil prices have responded sharply, tracking the ebbs and flows of the contest. In response, Donald Trump has signaled a potential shift in US strategic posture, suggesting that other governments should “go get their own oil”[48] and implying that responsibility for securing the Strait should fall to those most dependent on it. The result presents as further fragmentation of the post-Cold War security framework, in which the security and free trade implicitly underwritten by US naval power is no longer guaranteed.
The geography of the conflict also extends beyond Hormuz. The Houthis, controlling much of Yemen’s Red Sea coast, possess missiles, drones and anti-ship capabilities that allow them to threaten traffic near the Bab el-Mandeb, which connects the Red Sea with the Gulf of Aden on the route between Asia and Europe through the Suez Canal. Houthi attacks since late 2023 have caused shipping companies to divert vessels around the Cape of Good Hope, increasing journey times and costs and placing pressure on global shipping capacity.
The Houthis resumed attacks against Israel following the beginning of the 2026 war and later threatened shipping and Saudi interests near the Bab el-Mandeb. Iranian officials also described a proposed security belt extending from Hormuz to Bab el-Mandeb. Together, these developments created the possibility of simultaneous pressure on two major maritime chokepoints, with Iran acting directly in Hormuz and the Houthis potentially applying indirect pressure in the Red Sea.
The USA and Israel together can arguably boast the most formidable offensive cyber capabilities in the world. Some Israeli reports even claim the war with Iran has seen the “largest cyberattack in history”, with impacts on critical infrastructure, official news sites, and security communications systems[49]. More evidence of the US/Israeli cyber operation and its impacts are emerging daily. On the other end of the conflict a recent RUSI report reminds us that “Iran hosts patriotic hacker groups, the IRGC has its own dedicated cyber-electronic command, and several Advanced Persistent Threats (APT34, APT39 and APT42) have long been linked to the country”.[50] Despite this, however, the BBC journalist Joe Tidy noted in the early stages of the conflict that “Over hours of press conferences, speeches and dozens of social media posts, mentions of cyber operations are vanishingly rare”[51].
Nevertheless, as with any modern conflict, cyber operations have certainly played a role in the US-Israel-Iran war also. Examples of hacking and other offensive cyber operations aligned with the conflict have been well documented, and it is not our goal to enumerate them here. A categorized summary will be instructive, however:
One noteworthy cyber incident associated with the war was the destructive cyberattack on US-based medical device and services provider Stryker[57], which reportedly took out its order processing, shipping and manufacturing for nearly a month and ate into its first-quarter results[58]. On March 11, 2026, Stryker disclosed a cybersecurity incident that caused a “global disruption” to its Microsoft environment and impaired access to business systems supporting operations and corporate functions. Reporting and threat-intelligence analyses describe the incident as a destructive “wipe” operation, where infrastructure was reportedly reset or wiped at scale via administrative control-plane abuse (apparently Microsoft Intune and Microsoft Entra ID). The incident disrupted order processing, manufacturing, and shipping, with downstream supply-chain consequences reported by public health authorities like the English NHS, and procedure delays reported in some health systems.
Public reporting is that an Iran-aligned hacktivist group called Handala claimed responsibility for the attack, and the DOJ has alleged that the Handala-branded infrastructure involved was controlled by Iran’s MOIS. The US Department of Justice also announced seizure of four domains in the context of this incident and explicitly described them as used by Iran’s Ministry of Intelligence and Security (MOIS) - including Handala-branded domains - to claim hacks, post stolen data, and run psychological operations.
Handala’s public claims about the Stryker incident commonly include wiping or factory-resetting large numbers of systems, destroying 12 petabytes of data, and exfiltrating large data volumes (often “50 TB”). The group’s public messaging ties the Stryker attack to geopolitical retaliation. Reuters reported Handala framing the attack as a response to strikes in Iran and “ongoing cyber assaults,” while DOJ states the persona claimed retaliation for “ongoing cyber assaults against the infrastructure of the ‘Axis of Resistance’.” Reports connect the claim to a strike on a school in Minab, Iran.[59] According to Reuters, “Staff and contractors said in social media posts that the logo of an Iran-linked hacking group has appeared on the company's login pages”, though Reuters was reportedly not able to verify the posts.
Unit 42 has described a surge of Iran-linked activity since late February 2026, including hacktivists, and reports anticipating a mix of disruption and hack-and-leak operations as part of a broader conflict ecosystem.
Handala Hack Team is one of the principal online personas associated with a large Iranian state-nexus cluster comprised of multiple fronts and tracked as Banished Kitten. Banished Kitten has been observed since 2008 and is associated with the MOIS[60]. The group is broadly tracked and widely reported on, so a brief summary of our own[61] prior reporting on the group will suffice here.
Handala has become one of the most visible cyber actors aligned with Iranian strategic interests and is a classic exemplar of “Establishment Era” hacktivism. Although it presents itself as an independent hacktivist collective, it is widely assessed to function as a front linked to Iran’s Ministry of Intelligence and Security (MOIS), with possible ties to the IRGC. Rather than operating purely as a technical intrusion group, Handala blends cyber activity with propaganda and influence operations, positioning itself as both an operational and psychological tool within Iran’s broader strategy.
In practice, Handala conducts familiar hacktivist activities such as data leaks and doxxing, alongside several confirmed disruptive attacks and numerous other claims that are probably exaggerated. The group frequently exaggerates its capabilities and the scale of its operations. While some of the data it releases is genuine, it is often limited, repackaged, or drawn from publicly available sources. In several instances, its claims have been shown to be misleading or outright false. This gap between perception and reality is not incidental - it is central to how the group operates.
Handala’s real strength lies in its ability to shape narratives. Through platforms such as its “Handala Alert” website and doxxing initiatives like “RedWanted,” the group amplifies its claims, targets individuals, and attempts to build credibility by referencing external reporting. These efforts are designed less to demonstrate technical sophistication than to create psychological impact, intimidate opponents, and reinforce pro-Iranian messaging. In this sense, Handala functions as much as an information warfare actor as it does a cyber one.
This approach reflects the broader structure of Iran-linked cyber activity, which relies on a mix of state-sponsored actors, proxy fronts, and loosely organized hacktivist groups. Across this ecosystem, operations tend to emphasize visibility over impact, using tactics such as DDoS attacks, defacements, and influence campaigns to generate attention and political effect. While Iran possesses more advanced cyber capabilities, public reporting is dominated by noisy hacktivist fronts, while higher-end espionage and disruptive capabilities are often harder to observe or attribute.
In the context of the ongoing conflict involving the United States, Israel, and Iran, Handala has maintained a steady stream of claimed attacks and information operations, while increasingly adopting more aggressive rhetoric, including explicit threats of cyber-enabled kinetic activity and even calls for physical violence against senior leaders. Yet the broader cyber environment thus far has remained relatively contained. The overall environment remained moderate, with most activity consisting of low-impact disruption and narrative amplification, notwithstanding a limited number of consequential destructive incidents. At the same time, Iranian-linked actors beyond the hacktivist layer have demonstrated credible intent to target critical infrastructure.
Since the war began in February 2026, the significant incidents linked to Handala/Banished Kitten include:
Handala/Banished Kitten has thus combined several genuine and consequential intrusions with doxxing, exaggerated breach claims, rhetoric and recruitment for physical attacks. The recent US water incidents are relevant to the wider Iranian cyber ecosystem, especially the IRGC-linked CyberAv3ngers/Hydro Kitten cluster, but cannot currently be considered confirmed Handala activity.
Handala serves as a visible instrument of pressure and perception, projecting influence and signaling capability even when the underlying technical impact is modest. The Stryker incident was by no mean modest, but it should still be viewed through the lens of Handala’s prior modus-operandi and Iran’s prevalent strategic orientation: Iran’s state-aligned hacktivist proxies are a cognitive weapon – concerned with imposing psychological costs on their adversaries by sowing fear, uncertainty and doubt. Technical impact should be understood as a means to an end here, not an end in itself. Seen through this lens, almost any victim and any impact provide a tactical opportunity, and the choice of Stryker as a target likely has more to do with its symbolic alignment with the West than anything specifically it may contribute to the conflict.
The head of the UK’s online security agency recently asserted that the country could face “hacktivist attacks at scale” if it becomes embroiled in a conflict and that the impact could be similar to recent high-profile ransomware incidents, according to the Guardian[71]. Given the recent escalation of hacktivist activity, this bleak prognosis is well founded.
We define hacktivism as a form of computer hacking that is done to further the goals of political or social activism. While activism describes a normal, non-disruptive use of the Internet in order to support a specific cause (online petitions, fundraising, coordinating activities), hacktivism includes operations that use hacking techniques with the intent to disrupt but not to cause serious harm (e.g., data theft, website defacements, redirects, denial-of-service attacks).
The history of hacktivism can be categorized into three distinct eras: the Digital Utopia Era, the Anti-Establishment Era, and the Establishment Era. These eras are primarily defined by the evolvin]g ethos of hacktivist groups and the corresponding strategies they adopt. While the emergence of a new era does not imply the complete disappearance of characteristics from earlier periods, the influence of prior ethos and strategies typically diminishes as those of the contemporary era take precedence.
As we described in our 2025 Security Navigator report[72], Hacktivism has evolved through three broad eras. The first, the “Digital Utopia Era” from the mid-1980s, was rooted in ideals such as free access to information, privacy rights, and exposing software vulnerabilities to protect users, with groups like the Cult of the Dead Cow (cDc), Chaos Computer Club (CCC), and Bayrische HackerPost (BHP) using the Internet to disrupt systems and educate the public. In the mid-2000s, the “Anti-Establishment Era” emerged, led by groups such as Anonymous, WikiLeaks, and LulzSec, which abandoned hopes of a digital utopia and instead became reactionary, disruptive, and cynical toward governments and corporations, responding to censorship, social injustice, and geopolitical conflicts, sometimes simply “for the lulz.” The current “Establishment Era” marked a reversal again, with hacktivist groups increasingly aligning with governments, religious institutions, and nation-states, supporting one side or another in geopolitical conflicts. This became especially visible during Russia’s 2014 intervention in Ukraine, with state-aligned cyber-attacks on both sides, and later through groups like the Syrian Electronic Army and Anonymous conducting operations aligned with broader political and strategic causes. The attributes of this complex and evolving new era of “hacktivism” are also clearly visible in the ongoing conflict between Iran, Israel and the US and its allies. Over time, the evolution of hacktivism has made it increasingly distinct from its origins and from the original meaning of the term.
It was in 2022 that hacktivist groups began to escalate their tactics, apparently motivated by geopolitical conflicts. Known perpetrators of such attacks have consistently attributed their actions to allegiance with one side or another in these conflicts. The first notable step in escalatory hacktivism was a desire to target and disrupt operational technology (OT). Since 2022, hacktivist groups have increasingly claimed attacks against operational technology. Although most claims remain exaggerated or unverified, some incidents have produced credible cyber-physical effects, while the sophistication or behavior of certain groups suggests possible state coordination or sponsorship[73].
One group pioneering the escalation of hacktivist tactics was Predatory Sparrow, a purportedly pro-Israel group, who in June 2022 conducted cyber-physical attacks against the operational technology of three Iranian steel manufacturers to cause destructive, kinetic impacts. The group cited unspecified aggression by the Islamic Republic as the reason for the attack. There were no casualties, which Predatory Sparrow highlighted as deliberate[74]. Fortunately, the attack targeted isolated manufacturing facilities where disruption would not have had significant broader consequences for civilian populations.
In 2023, CyberAv3ngers, a hacktivist group reportedly aligned with Iran and linked to the IRGC, intensified their tactics by targeting operational technology used in critical national infrastructure. The group revealed anti-Israel sentiment, stating that it considered any equipment manufactured there to be a legitimate target. These attacks were moderately disruptive, focusing on defacing control screens with anti-Israel messaging, but left one facility to operate manually and another unable to supply water to its 180 customers for two days[75].
More recently, in 2024, a pro-Ukrainian hacktivist group named OneFist claimed on X (formerly Twitter) that it had been conducting a campaign against Russian power plants. The group shared images and videos of HMI interfaces displaying live process data, implying manipulation to disrupt power generation at targeted facilities[76].
Pro-Russian hacktivist groups have also increasingly moved beyond website disruption and attempted to interfere directly with operational technology. The Cyber Army of Russia Reborn, known as CARR, manipulated industrial control systems at water, wastewater, hydroelectric and energy facilities in the United States and Europe. In January 2024, the group caused water-storage tanks in Abernathy and Muleshoe, Texas, to overflow, resulting in the loss of tens of thousands of gallons, and separately gained control of alarms and pumps at a US energy company. Later campaigns by CARR, NoName057(16), Z-Pentest and Sector16 targeted exposed HMI and SCADA systems, sometimes changing passwords, operating parameters and alarms and forcing operators to restore manual control. US authorities assess that CARR was founded, funded and directed by Russia’s GRU, while the degree of direct Russian support for the other groups varies. They are thus an example of a state-aligned hacktivist ecosystem whose actions have sometimes caused real operational and physical effects[77].
Finally, since March 2026, US agencies have reported Iranian-affiliated APT actors targeting internet-connected PLCs across water and wastewater systems, energy companies, government facilities and local municipalities. The actors extracted and modified PLC project files, manipulated information displayed on HMI and SCADA systems and, in some cases, disabled alarm and shutdown logic, causing operational disruption and financial loss. The federal advisory does not publicly name the operators responsible for this current campaign or classify them simply as hacktivists but does note similarities with earlier CyberAv3ngers activity. On 26 and 27 July, an attack targeted operational technology at more than 30 Minnesota community water systems and elsewhere, temporarily shutting down controls at the well and treatment plant in Braham and disrupting communications elsewhere. Minnesota and the FBI have not publicly attributed those specific attacks, but private researchers have assessed that their timing and methods were consistent with CyberAv3ngers. The wider US campaign is therefore currently attributed to Iranian-affiliated actors[78].
These attacks demonstrate a clear trajectory of escalation and intensification, often aligning with state-backed narratives in conflict settings. As we argue in this paper, the goal of such attacks is to shock and distress, so such escalation is to be expected – and further anticipated. Once the target society starts becoming conditioned to familiar forms of assault (like DDoS attacks for example), hacktivist groups will feel compelled to reclaim public attention with larger, more visible, or more dangerous attacks.
In the world of enterprise cybersecurity, we are often conditioned to view our mission through the lens of technical metrics: attacks recorded, the number of patches deployed, the speed of incident response, or the integrity of our network perimeters. However, this narrow focus on infrastructure sometimes overlooks the actual strategic objective of modern state-sponsored cyber activity. Cyberspace isn’t just a technical system; it’s a socio-technical and cognitive construct. Within this framing, the primary target of attacks is often really the perception and legitimacy of our beliefs and institutions.
Understanding how nations like Iran may be expected to deploy cyber means during times of peace and conflict requires us to understand how they conceptually understand cyberspace, and how they conceptually approach conflict.
Iran’s experience in the 1980 to 1988 war with Iraq produced a set of durable strategic lessons that arguably continue to shape its behavior today. Faced with conventional inferiority and international isolation, Iranian decision-makers have historically adapted by emphasizing endurance, mass mobilization, and asymmetric forms of conflict. Analyses of wartime operations show a reliance on irregular forces and low-intensity methods to offset material disadvantages, particularly during the 1983-87 period but also still today.[79] This experience appears to have informed a core belief that sustained, below-threshold conflict can generate meaningful strategic outcomes over time.
A second lesson has emerged from the vulnerability of Iran’s cities and infrastructure to missile attacks. Through experiences like the “Tanker War” and Iraqi missile campaigns, Iranian leaders seem to have observed that strategic coercion could occur without decisive battlefield victories[80]. This contributed to the prioritization of missiles and other cost-imposing tools within Iran’s deterrence framework. Over time, this logic has expanded into a broader conflict model that integrates rockets, unmanned systems, cyber activities, and proxy actions as calibrated response options. For Iran, such tools enable pressure on adversaries while managing escalation risks.
Past conflicts have also produced a powerful ideological framework known as the “Sacred Defense,” which links national survival, regime legitimacy, and collective mobilization. [CM16] Government efforts to document and retell past wars, as reflected in official military histories and doctrinal framing, have reinforced this narrative across generations.[81] The result is a strategic culture that frames external threats as persistent and existential, while legitimizing expansive security measures. The narrative supports the mobilization of aligned militias and affiliated networks, often framed as part of a broader resistance effort that includes both physical and informational domains.
These lessons have converged into a structured approach to power projection centered on asymmetric methods and proxy actors. The post-war period saw the development of a networked model anchored by the IRGC and its external arm, which coordinates and supports partner forces abroad.[82] In the conflict with Iraq, for example, this took the form of a layered ecosystem of militias with varying degrees of alignment but shared strategic utility.[83]
What has emerged is a consistent preference for indirect influence, deniable operations, and persistent pressure rather than conventional confrontation.
Iranian state discourse conceptualizes cyberspace primarily as a socio-political environment that shapes identity, public order, and regime security. Official rhetoric and institutional design consistently frame the domain as a governed space where culture, ideology, and political stability are contested, often using security-oriented metaphors such as “soft war” and references to threats against national identity[84]. This vocabulary reflects a perspective rooted in political and civilizational struggle rather than technical network management, positioning cyberspace as a domain where influence, legitimacy, and social cohesion are continuously negotiated and defended.
The perspective is reinforced by the central role of governance bodies such as the Supreme Council of Cyberspace, which integrates policy, security, and cultural oversight. Analyses from organizations such as ARTICLE 19 and the Carnegie Endowment describe a system that combines regulation, surveillance, and content control with broader political objectives[85]. Cyberspace governance is treated as a comprehensive policy field that includes domestic platform development, information control, and coordination across state institutions. The result is a model where technical infrastructure is managed in parallel with efforts to shape public discourse and societal norms.
Iranian official language also emphasizes cyberspace as a domain of soft power with wide-ranging societal effects. Statements linked to senior leadership describe virtual space as influencing culture, economy, religion, and lifestyle, and stress the need for centralized oversight and coordinated action[86]. This view treats digital environments as extensions of the national social fabric, where governance must ensure alignment with political and moral objectives.
At the doctrinal level, Iran’s international cyber positions further illustrate this understanding. Official statements by Iran assert that cyber operations can violate sovereignty through political, social, or cultural disruption, even in the absence of physical damage[87]. This broad definition of harm explains a policy approach that merges cybersecurity, information control, and societal management into a single framework. It also helps explain Iran’s use of state-linked and affiliated actors to shape narratives and influence audiences beyond its borders[88].
Iran’s approach to offensive cyber operations is rooted in a broader strategic tradition shaped by the Iran-Iraq War and subsequent regional competition and apparently perpetuated by the current war with the US and Israel. As described in analyses such as Vali Nasr’s work on Iranian grand strategy, Tehran’s doctrine emphasizes incremental, adaptive, and networked methods of power projection designed to secure regime stability and strategic depth under pressure. This orientation aligns closely with the characteristics of cyberspace, where deniability, scalability, and persistent low-level engagement enable influence without triggering large-scale retaliation. The result is a model of continuous competition below the threshold of major conflict, integrating cyber operations alongside political, intelligence, and proxy-based tools.[89]
Iran’s conceptualization of cyberspace as a socio-political and cognitive domain directly shapes how offensive operations are designed and employed. Cyber activity is not limited to technical disruption or espionage, rather it is used to influence public perception, shape decision-making environments, and reinforce narratives aligned with Iran’s strategic interests. Intelligence collection provides access to political and security networks, while information operations and messaging campaigns target legitimacy, identity, and public opinion. This integration reflects a view of cyberspace as a space where cognitive effects and social influence are central to achieving strategic outcomes.
A defining feature of Iran’s cyber strategy is its reliance on proxy actors and loosely aligned networks. In parallel with its use of regional militias, Iran has cultivated or enabled cyber proxies and hacktivist collectives that conduct disruptive and influence-oriented operations. As described earlier, state-aligned hacktivist groups thus claim attacks consistent with Iranian strategic narratives, including distributed denial-of-service campaigns against regional targets.[90] These actors operate with varying degrees of coordination, creating ambiguity that complicates attribution while allowing Iran to exert pressure in a controlled and deniable manner.
Iran’s legal and doctrinal framing of cyberspace supports this operational model. Official statements assert broad sovereignty over elements of cyberspace and treat many forms of cyber activity as violations, while reserving the right to respond decisively when threatened[91]. This framework creates a flexible escalation ladder in which Iran can justify a wide range of responses while maintaining operations below the threshold of armed conflict.
Iran’s offensive cyber operations thus reflect its conflict doctrine and its understanding of cyberspace as a cognitive and socio-political environment. Cyber tools are used to impose costs, gather intelligence, and shape narratives. Cognitive impacts, combined with the use of distributed actors, produces a pattern of persistent, multi-vector engagement that is consistent with Iran’s broader approach to asymmetric conflict, and clearly manifested in the behavior of Iran state-aligned hacktivists.
Iran’s concept of cyberspace and conflict sits closer to the strategic traditions seen in China and Russia than to the defensive and institution-building priorities set out in Iraq’s publicly available national cybersecurity strategy. China’s “Three Warfares” combines media influence, psychological operations, and legal tools, while Russia’s broader concept of “Information Confrontation” brings together cyber activity, propaganda, deception, and political influence within a single framework[92]. In both cases, the focus is on shaping perception, influencing decision-making, and maintaining pressure below the level of open war. Iran’s approach follows a similar general logic, where cyberspace is not just a technical domain but part of a broader environment of political and social competition.
China’s model is rooted in formal military doctrine, particularly the People’s Liberation Army’s integration of media, psychological, and legal warfare into its strategic planning[93]. Cyber operations commonly form part of China’s wider approach to information conflict. Russia’s approach is broader and more fluid, using the idea of “information space” to combine cyber operations, propaganda, deception, and political influence into an ongoing contest. Iran overlaps with both by linking sovereignty, public opinion, and influence operations into a unified view of conflict, while also relying on state-linked and aligned actors to manage escalation and extend its reach. This creates a system where cyber activity, narrative control, and indirect pressure work together over time. Iran, like China and Russia, treats cyberspace as part of an ongoing struggle for influence and control.
Russia: The Permanent "Information Confrontation":
It is a mistake to view Russian cyber operations - whether state, hacktivism or criminal - as discrete "attacks". Instead, the Kremlin operates under a doctrine of "Information Confrontation", a holistic concept that blurs the line between technical hacks and psychological operations. Under this ideology, the target isn’t the server, it is the consciousness of a population.
Russian strategy treats technical effects like DDoS attacks or Cyber Extortion - as tools that help sow discord and weaken the target state from within. They operate in a state of permanent struggle that ignores the Western binary of "peacetime" versus "wartime". Whether it is a sophisticated hack-and-leak operation or violence on European streets, the goal is to generate "mayhem", erode resolve, and undermine democratic decision-making.
A chilling reflection of the depth and breadth of Russia’s ambitions regarding cognitive impacts can be found in the records of a 1984 interview conducted with former KGB agent Yuri Alexandrovich Bezmenov, who defected to Canada in 1970[94]. Bezmenov claimed to know details about a Soviet plan to undermine the US - not on the battlefield but in the psyche of the American public. Of course, the man was a spy, so his views need to be taken with a pinch of salt. And yet his claims are hard to ignore. For example, he asserted that 85% of the KGB’s work was involved with something he called “ideological subversion, active measures, or psychological warfare. “Ideological subversion”, he went on to clarify, meant to “change the perception of reality of every American to such an extent that despite of the abundance of information no one is able to come to sensible conclusions in the interest of defending themselves, their families, their community, and their country.” What makes that chilling - as we consider the growing significance of cognitive impacts in global conflict and indeed in cyber operations - is just how well it described today’s observed reality.
China: Sovereignty and Discursive Power:
China’s approach is holistic like Russia’s but focused on sovereignty and framed as a pursuit for "Discursive Power". The PLA’s "Three Warfares" doctrine, which incorporates public opinion, psychological, and legal warfare, Beijing seeks to shape international narratives and constrain an adversary’s choices without a single shot ever being fired.
Offensive cyber activity in the Chinese model functions as an "enabling layer" for this broader cognitive contest. A network intrusion might be carried out for espionage, or to provide the raw materials for a legal or narrative challenge that legitimizes China’s actions or delegitimizes its critics. For Beijing, cyberspace security is inextricably linked to information control and the enforcement of "cyber sovereignty".
Our Cyber Intelligence (CERT team[95] advises us that cyber operations observed around the US-Israel-Iran conflict to date have generally remained measured, with no confirmed large-scale coordinated cyber effects directly impacting critical infrastructure beyond isolated incidents. The impact on organizations outside of the region is also still somewhat limited. However, the pro-Iranian hacktivist threat landscape is intensifying, with a combination of unverified data leak claims, overstated DDoS activity, destructive wiper attacks and possible direct attacks on US infrastructure. Pro-Iranian hacktivist groups are a mix of loosely structured grassroots movements and state-coordinated online fronts associated with Iran’s MOIS and IRGC. In parallel, opportunistic cybercriminals continue to leverage the conflict as a thematic lure to conduct cyber theft and scams, particularly across Middle Eastern organizations.
We should expect Iran’s long-term approach to cyber operations to continue following a pattern that’s familiar from its broader strategy of conflict. It relies on steady, low-level pressure applied through networks of state and non-state actors, rather than direct confrontation - a system built for persistence, where influence, coercion, and signaling happen continuously below the threshold of open conflict. In cyberspace, this model works well because operations can be scaled, denied, and adjusted over time. As we’ll argue later, cyber incidents are also particularly effective at causing anxiety and other psychological impacts in target societies. Iran’s own statements at the United Nations acknowledge that states can use private actors as proxies, which reinforces the idea that this indirect approach is both expected and useful in Iran’s approach to cyber competition[96].
Hacktivist groups are central to this model. They act as flexible, semi-deniable operators who can carry out attacks while pushing narratives that align with Iranian strategic interests. Public reporting shows a mix of actors, from more clearly state-linked groups to looser collectives that adopt shared messaging and targets. Campaigns linked to groups like Handala and CyberAv3ngers illustrate how technical activity and propaganda are combined, with attacks often paired with bold claims and ideological framing[97][98]. This setup creates useful ambiguity - allowing pressure to be applied while making attribution and retaliation difficult.
The March 2026 incident involving Stryker shows how this pattern plays out in practice. The attack disrupted systems and operations across the company, with real disruption and downstream effects on supply chains and healthcare services. A hacktivist persona called Handala claimed responsibility and framed the operation as retaliation tied to events in the conflict. US authorities later linked infrastructure used by the group to Iran’s MOIS, implying a connection between state actors and proxy branding. The technical damage was real, but the surrounding messaging amplified the impact by shaping how the incident was perceived.
That combination of disruption and narrative is key. Hacktivist operations are designed to create doubt and anxiety as much as to cause outages. A temporary service disruption can lead people to question whether systems are secure. A data leak can be framed to suggest corruption or weakness. These effects spread quickly through social media and news coverage, often outpacing verification. In this sense, cyber operations become tools for influencing how people think and react, not just how systems function.
Stryker was clearly a high-value victim for the hacktivist group - presenting a strong base for the narrative that emerged. However, that need not suggest that Stryker was deliberately “selected” as a target. Instead, a powerful strategic advantage enjoyed by hacktivists set on narrative shaping is that almost any victim or impact can be co-opted into a suitable narrative. Thus, it can be that the “message” follows the “means”, and not the other way around. Hacktivists can turn almost any technical compromise into a story that supports the message they want to convey. This reality has serious implications for corporate defenders, since every business that could in any way be linked to the narrative becomes a suitable victim.
The consensus predicts that Iran is likely to keep using hacktivists and proxy actors as a long-term way to engage adversaries in cyberspace. The approach fits its broader strategy of indirect competition and controlled escalation. Cyberspace offers a space where technical actions and psychological effects reinforce each other, allowing Iran to apply pressure, shape narratives, and maintain influence over time without moving into open conflict.
As we’ve written elsewhere, the primary objective of hacktivist activities is therefore to achieve a “cognitive” effect, with the technical impact being a means by which the cognitive effect is achieved. The goal is to influence public understanding and decision-making at scale.
The RAND Corporation describes[99] cognitive hacking within information warfare as the deliberate shaping of how people think, feel, and act by exploiting predictable features of human psychology and modern media environments. Actors design messages that trigger emotion and reinforce existing beliefs, and thus spread quickly through social networks, often using repetition, framing, and coordination to make ideas feel familiar and credible. False or misleading content plays a role, although accurate information can also be used in misleading ways to influence perception. In cyberspace, digital platforms enable rapid scaling of these techniques, allowing small efforts to reach large audiences and create feedback loops that deepen polarization and confusion.
We should see hacktivists as part of a broader information war, but they are cognitive combatants as much as technical ones. Although hacktivism today is harder to separate from state activity, the apparent distinction provides states with a convenient means to extend reach while still avoiding accountability.
So, hacktivism must be framed as a targeted threat to cognitive security – the collective mindset and cohesion of our society – rather than just a minor irritation.
The cognitive playbook aims to manipulate perception, not just cause disruption or destruction. As we’ve previously put it[100]: the purpose is to create FUD - Fear, Uncertainty, and Doubt - escalating anxiety, distrust, and disharmony in the target population. For example, a hacktivist crew might temporarily take down a bank’s website. On the surface, a few hours of service disruption is only a nuisance. But the psychological goal is to sow doubt by triggering questions like “Is my money safe? Should I withdraw cash?”. Similarly, leaking emails from a government agency might not have a direct impact beyond embarrassment, but if those emails can be framed to suggest corruption or incompetence, it undermines public faith in that institution. Hacktivists therefore use technical attacks as a means to a psychological end. They weaponize the narrative. Each cyber incident comes with a storyline: “Country X is weak,” “Your government can’t protect you,” “We fight in the name of [some cause].” And thanks to the echo chamber of social media, these narratives spread faster than we can often contain. One breach claim, whether true or exaggerated, can ricochet globally in minutes, amplified by sympathizers and unwitting bystanders alike.
Of course, Hacktivism is not the only mechanism Iran uses to produce cognitive effects. One clear (if bizarre) example is pro-Iran creators using AI-generated Lego-like figures to mock US and Israeli leaders and frame Iran as resilient and victorious.[101] This fits Iran’s broader cognitive strategy. According to the WSJ, one of the videos released during the current conflict includes a rap soundtrack that says “Sacred defense, we protecting the soil / while you sacrifice soldiers to pay for your spoil” while Lego-style missiles arc across the night sky. The technical novelty of AI is noteworthy, but the essential purpose is to shape perception, create memorable narratives, and spread pro-Iranian messaging quickly across digital platforms. This is the same essential purpose driving hacktivist campaigns, and so identifying and deterring cognitive attacks becomes a key priority for defenders.
One study on the psychological and societal impacts disruptive cyberattacks is a report by Shandler and Gomez titled “The hidden threat of cyber-attacks – undermining public confidence in government[102]”.
Shandler and Gomez argue that the central danger of many cyber-attacks is not “cyber-Armageddon” or spectacular physical destruction. The more common and more politically important risk is that cyber-attacks can weaken public trust in government, institutions and business, increase fear, and damage social cohesion. Their point is that the bigger damage may come from what the public takes the attack to mean: that the state cannot protect basic institutions in an increasingly digital society.
The study tests this idea using survey data gathered soon after the September 2020 ransomware attack on Düsseldorf University Hospital. They surveyed 707 residents in the area and compared people who were aware of the incident with those who were not. The clear finding was that exposure to the attack reduced confidence in government. Even a cyber-attack that did not produce mass physical destruction still had measurable political and psychological consequences.
The authors argue that cyber-attacks exploit features of cyberspace that are closely tied to public confidence. Attribution is often uncertain, technical details are hard for ordinary citizens to verify, and attackers can appear hidden, powerful, and unreachable. The public may not know who carried out the attack, how it happened, whether the authorities are telling the full story, or whether similar attacks can be prevented. This uncertainty makes cyber incidents especially good at producing a sudden loss of trust. The paper stresses that the public tends to see government as ultimately responsible for defending critical infrastructure and public institutions, even though, in practice, cybersecurity depends on government agencies, private firms, software providers, hospital administrators, and individual users. But public judgment is simpler. When a public institution is disrupted, citizens often ask whether the state can protect them. That makes cyber-attacks politically dangerous even when the technical failure happens outside direct government control.
Public confidence may be either the main target of the attack, or an unintended consequence. In cyber-terrorism, sowing fear and making the government look powerless may be the point of the operation. In cyber-crime, cyber-espionage, or cyber-vandalism, the attacker may be seeking money, information, disruption, or notoriety rather than political fear. But the psychological impact can still be similar. A criminal ransomware attack on a hospital can still make citizens feel exposed, helpless, and doubtful that institutions can protect them.
Our research has previously surfaced the concept of the "cohesive pressure system"[103]. While an individual technical disruption - like a ransomware attack on a hospital - might impact a single victim and thus be considered insignificant in the grand scheme of global affairs, the cumulative effect of continuous campaigns of such actions becomes significant.
Shandler & Gomez thus make clear the threat from attacks targeting perception and trust clear: Societal trust and cohesion are the foundation everything else is built on. Economic activity, rule of law, and social stability all rest on a basic shared confidence in institutions and systems and in each other. We can’t have a functioning market if people don’t trust that their bank deposits are safe or that contracts will be honored. We can’t effectively govern if citizens don’t believe official communications or doubt the legitimacy of elections. In fact, it’s now clear that preserving the public’s trust is a national security priority on par with protecting physical infrastructure. Since the time of Bezmenov (mentioned previously), adversaries of all kinds have recognized that undermining trust is a way to weaken nations from within without ever firing a shot. Cyberspace has made that threat even more acute.
In cybersecurity terms, we often say attackers seek the weakest link. But the human psyche is not only the vulnerability, it’s the target. Defending against cognitive threats and protecting societal cohesion has become a strategic imperative that all elements should be concerned with. Public trust is what makes people cooperate, follow rules, and remain calm in crises. Adversaries know if they erode that trust, they can induce paralysis or self-defeating behaviors in their target society, which in turn negatively impacts everyone.
For example, during the COVID-19 pandemic, we saw how disinformation eroded trust in health systems and created social schisms. While that was not purely a cyber issue, it’s illustrative of what can happen when confidence is corroded. Now, imagine similar trust-eroding tactics applied deliberately via cyber means: fake news about a bank collapse causing a digital bank run, or propaganda around an election causing citizens to reject the outcome. This threat impacts all of society, including businesses.
As our earlier reference to Bezmenov makes clear, cognitive warfare predates the internet and cyberspace by a long way. Nor is cognitive warfare restricted to hacktivist techniques. Hacktivism is only one relatively new element within a broader spectrum of cognitive attacks.
The Shandler and Gomez paper examines disruptive and destructive cyber-attacks and focuses on anger, dread, and anxiety as psychological impacts. But cognitive threats extend far beyond cyber disruption. They encompass a wider range of techniques aimed at shaping perception, interpretation, trust, and behavior.
Security is not an objective state; it’s the subjective expression of our freedom to pursue shared visions. Cognitive attacks (including diverse forms of hacktivism) leverage technical compromises to launch an assault on the fabric of trust on which “secure” systems are built. Protecting societal cohesion - the public’s trust and psychological resilience - must therefore become an essential part of our security mission.
We hope we’ve convinced you that it’s important for cyber defenders to understand the mechanics of cognitive impacts and the tactics, techniques and procedures used to achieve them. If we have, we encourage you to read the detailed paper we’ve published on the topics here.
That paper takes the argument beyond Iran and hacktivism to examine the wider idea of cognitive threats in cybersecurity. It begins from the position that the technical disruption caused by a cyberattack is often only part of the hacktivist’s objective. It then broadens the argument further, showing that even attacks motivated by crime or espionage can have serious cognitive effects when people begin to doubt whether governments, businesses, and essential services can protect them.
The paper uses examples ranging from the 2016 US election interference campaign and the compromise of Poland’s national news agency to incidents involving Naval Group and Okta. It then describes the wider cognitive toolkit, including the narratives, tactics, technical delivery methods, and human vulnerabilities that allow these attacks to work. We argue that trust should be treated as a form of critical infrastructure. Cyber defenders must therefore protect more than systems and data, and should also consider reputation, public confidence, shared understanding, and the wider social environment in which their organizations operate.
Finally, the paper translates this argument into a practical model for cognitive defense. Using the NIST functions of Identify, Protect, Detect, Respond, and Recover, we recommend how organizations can anticipate hostile narratives, secure trusted communication channels, detect technical and informational manipulation together, coordinate their response across security, communications, legal, and leadership teams, and restore confidence after an incident. An applied section on disinformation shows how this approach can be incorporated into normal cybersecurity and business-continuity planning.
[6]www.iaea.org/newscenter/statements/iaea-director-generals-introductory-statement-to-the-board-of-governors-2-march-2026
[16]www.lemonde.fr/en/opinion/article/2024/04/19/the-two-pillars-of-iran-s-theocracy-nuclear-power-and-the-revolutionary-guards-have-their-origins-in-the-iran-iraq-war-of-the-1980s_6668894_23.html
[19]www.history.navy.mil/browse-by-topic/wars-conflicts-and-operations/middle-east/praying-mantis.html
[20]www.history.navy.mil/content/history/nhhc/about-us/leadership/director/directors-corner/h-grams/h-gram-020/h-020-1-uss-vincennes-tragedy--.html
[30]www.iiss.org/globalassets/media-library---content--migration/files/research-papers/2024/12/navigating-troubled-waters.pdf
[37]www.theguardian.com/world/2024/apr/01/israeli-airstrike-on-iranian-consulate-in-damascus-kills-irgc-commander
[39]www.iiss.org/publications/strategic-comments/2024/10/israels-position-a-year-after-the-hamas-led-attacks-of-7-october/
[46] The Absent Superpower (2017), Disunited Nations (2020), and The End of the World Is Just the Beginning (2022)
[47]www.iea.org/commentaries/how-global-oil-supplies-have-readjusted-to-help-fill-the-huge-gap-left-by-the-strait-of-hormuz-shock
[48]www.forbes.com/sites/tylerroush/2026/03/31/trump-tells-allies-to-get-your-own-oil-from-strait-of-hormuz-or-buy-from-us/
[50]www.rusi.org/explore-our-research/publications/commentary/fog-proxies-and-uncertainty-cyber-us-israeli-operations-iran
[54]www.reuters.com/business/media-telecom/hackers-hit-iranian-apps-websites-after-us-israeli-strikes-2026-03-01/
[59]www.reuters.com/technology/stryker-shares-fall-after-report-suspected-iran-linked-cyberattack-2026-03-11/
[62]www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations
[77]media.defense.gov/2025/Dec/09/2003840175/-1/-1/0/JOINT_CSA_PRO-RUSSIA_HACKTIVISTS_CONDUCT_ATTACKS_AGAINST_CRITICAL_INFRASTRUCTURE.PDF
[79]ndupress.ndu.edu/Media/News/News-Article-View/Article/2555544/embracing-asymmetry-assessing-iranian-national-security-strategy-19831987
[80]www.iiss.org/globalassets/media-library---content--migration/images/comment/analysis/2017/december/2-mcinnis2125.pdf
[82]www.iiss.org/globalassets/media-library---content--migration/images/comment/analysis/2017/december/2-mcinnis2125.pdf
[89]ndupress.ndu.edu/Media/News/News-Article-View/Article/2555544/embracing-asymmetry-assessing-iranian-national-security-strategy-19831987/
[91]nournews.ir/en/news/53144/General-Staff-of-Iranian-Armed-Forces-Warns-of-Tough-Reaction-to-Any-Cyber-Threat
[94]www.ordo-militaris.net/wp-content/uploads/2025/02/39-years-ago-a-KGB-defector-chillingly-predicted-modern-America.pdf
7 August 2026

10 February 2026 | Blog