The number of cyber incidents attributed by Israel to Iran has risen sharply during the latest phase of the regional conflict.
Yossi Karadi, Director General of the Israel National Cyber Directorate, told German newspaper Die Welt that approximately 4,800 reports of cyber incidents and hostile online activity were received during operations in June 2026. During Israel’s military operation against Iran in June 2025, the corresponding number was approximately 1,600.
The figures represent a threefold increase. They should not, however, be interpreted as 4,800 successful breaches. They cover incident reports and hostile activity handled by Israel’s national cyber response infrastructure, including attempted attacks, suspicious activity and confirmed incidents.
The more strategically important finding is where the pressure is being directed.
According to Karadi, the campaign has targeted critical infrastructure, major organisations, small and medium-sized companies and individual members of the public. Israel says it has so far prevented successful attacks against its critical infrastructure, but some less-protected companies reportedly had databases deleted or computer systems completely wiped. Law firms, accounting practices and other smaller professional-service organisations were among the targets identified.
Military agreements do not stop cyber operations
Karadi summarised the situation with a warning: there is no ceasefire in cyberspace. He said that on the day a ceasefire was signed following the June 2025 conflict, cyberattacks against Israel doubled. Unlike conventional forces, hacking groups do not need to withdraw troops, reposition equipment or cross a physical border. Their infrastructure may already be active, their access to compromised systems may remain in place, and their operators can continue working from anywhere.
Cyber campaigns may also continue serving strategic objectives after military operations have slowed. They can collect intelligence, damage confidence in public institutions, impose economic costs, produce propaganda material and maintain pressure without creating the same immediate escalation risk as a missile or air strike.
Microsoft has previously characterised Iranian cyber operations against Israel as a means of gathering intelligence, disrupting services, retaliating below the threshold of open war and demonstrating ideological resistance to domestic and regional audiences.
A ceasefire may therefore change the political context without removing the motive, access or capability required for continued digital operations.
Iran’s cyber ecosystem is becoming more coordinated
The latest escalation is not only a matter of higher attack volume.
Karadi described an increasingly coordinated ecosystem. Its core reportedly includes cyber units associated with Iran’s security apparatus and Islamic Revolutionary Guard Corps. Additional layers include ideologically motivated civilians, paid operators, activist groups and foreign cybercriminal organisations.
He said Iranian groups that previously operated more independently began sharing information and attack knowledge after the 2025 conflict. Tehran has also allegedly attempted to recruit foreign groups, including ransomware operators, to support campaigns that may initially appear financially motivated.
This mixture of state units, proxies, activists and criminals creates several advantages for the sponsor:
- access to a wider range of technical capabilities;
- greater operational capacity during periods of escalation;
- uncertainty about who authorised a particular attack;
- plausible deniability when an operation causes excessive damage;
- the ability to combine espionage, disruption and propaganda.
Independent threat research also indicates that Iranian-linked groups are improving their methods. Palo Alto Networks’ Unit 42 reported in March that Boggy Serpens, also known as MuddyWater and attributed to Iran’s Ministry of Intelligence and Security, had moved towards more persistent, carefully tailored campaigns.
The group has targeted government, diplomatic, energy, maritime, aviation, financial and technology organisations across the Middle East and other regions. Its recent operations have used hijacked legitimate accounts, multi-stage social engineering and AI-assisted software development to improve the credibility and adaptability of attacks.
The implication for businesses is that geopolitical cyber campaigns should not be expected to arrive with an obvious government label. An attack may look like ordinary phishing, ransomware, supplier fraud or account compromise until its broader purpose becomes visible.
Why attackers move from infrastructure to smaller businesses
Critical infrastructure is the most politically significant target, but it is often also the most heavily defended. Energy networks, telecommunications providers, banks and government systems usually receive national-security attention, regulatory oversight and continuous threat intelligence. Attacking them successfully may require time, specialist capability and access that cannot be created quickly.
Smaller businesses offer a more accessible route to visible results. A law firm may hold confidential correspondence involving government bodies, defence contractors or politically exposed clients. An accounting practice may possess financial records, payment information and credentials for customer systems. An IT service provider may offer access to dozens or hundreds of downstream organisations. Even where the compromised company is not strategically important by itself, its clients, data and relationships may be.
Karadi said attackers shifted towards easier targets when they could not achieve results against critical infrastructure. In some cases, the objective was not extortion but destruction: databases were deleted and systems were wiped.
This distinction matters. A conventional cybercrime group normally wants the victim to recover after paying. A destructive actor may have no interest in negotiation, preserving business operations or providing a working decryption key.
The purpose may simply be to impose cost, generate fear and produce evidence of damage that can be amplified online.
The cyber conflict is not one-sided
Iran has also experienced significant cyber disruption during the conflict. On 23 June, Iran’s state-owned banking technology provider said cyberattacks had disrupted card services at Bank Melli, Bank Saderat and Bank Tejarat. ATM services, point-of-sale terminals and mobile applications were affected, and card operations were temporarily suspended to prevent further unauthorised access.
A separate incident on 14 June reportedly disrupted services at four major banks after an attack on a shared communications system. Iran did not publicly identify the attacker, although its authorities have previously blamed hostile foreign actors, including Israel, for similar incidents. Israel did not comment on those allegations.
Cyber-enabled operations also accompanied the US-Israeli strikes in March. Iranian news websites were altered, and the BadeSaba religious-calendar application, which reportedly had more than five million downloads, displayed messages urging members of the armed forces to surrender their weapons.
Reuters could not establish responsibility for those operations, and some wider claims concerning attacks against Iranian government and military services could not be independently verified.
These examples demonstrate the difficulty of assessing cyber activity during a conflict. Technical evidence may remain classified, governments may disclose only selected information, and activist groups may exaggerate their impact for propaganda purposes.
Responsible reporting must therefore distinguish between:
- an attack claimed by a group;
- an incident attributed by a government;
- an independently confirmed disruption;
- a technically verified attribution to a specific state actor.
Cyber operations have become part of strategic communication
The objective of a cyberattack is not always limited to the affected system. A relatively small breach can be converted into a much larger influence operation through leaked documents, manipulated screenshots, fabricated claims and social-media amplification. Attackers may exaggerate the scale of their access or combine authentic stolen information with false material.
Karadi described propaganda campaigns as another layer of Iran’s cyber strategy. These include AI-generated videos and other content intended to influence public opinion alongside direct attacks on systems.
This creates a dual crisis for the affected organisation. The technical team must investigate what happened, while leadership must determine what information is genuine, what has been altered and how to communicate without unintentionally validating the attacker’s narrative.
An organisation that restores its systems but loses control of the public explanation may still suffer significant reputational and commercial damage.
A wider trend, not an isolated wartime spike
Israel’s reported increase began before the latest June escalation. The Israel National Cyber Directorate said it handled more than 26,000 cyber incidents during 2025, representing a 55% increase over 2024. The most frequently targeted sectors were finance, government and digital-service providers.
The June 2026 figures indicate how quickly that underlying threat level can rise when geopolitical tension creates new incentives for state groups, proxies and politically motivated actors.
The risk is also not geographically confined to Israel and Iran. Unit 42 has observed Iranian-linked campaigns affecting organisations across Europe, the Middle East, Central Asia and South America. Targets have included maritime companies, energy businesses, diplomatic organisations, telecommunications providers and IT vendors.
A European company does not need to operate in a conflict zone to become exposed. It may be targeted because it:
- supplies an Israeli, Iranian, American or defence-related customer;
- operates ports, energy, aviation or telecommunications infrastructure;
- employs politically or militarily relevant individuals;
- provides legal, financial, cloud or IT services to a target;
- has publicly taken a position on the conflict;
- possesses comparatively weak security but valuable relationships.
Cyber exposure follows business connections, not national borders.
What boards and executives should do
The immediate lesson is not that every company should expect a sophisticated state attack. It is that conventional cybercrime assumptions may be inadequate during periods of geopolitical escalation.
1. Maintain the elevated posture after the headlines fade. Security measures should not automatically return to normal when a ceasefire is announced or military operations slow down. Threat levels should be based on observed activity, government advisories, intelligence from suppliers and evidence within the organisation’s own environment, not solely on political announcements.
2. Prepare for destruction, not only ransomware. Incident-response plans frequently assume that attackers will encrypt data and demand payment. Organisations must also be ready for an adversary whose objective is to delete information and disrupt operations permanently. This requires offline or immutable backups, isolated administrative access and regularly tested restoration procedures. Management should know how long it would take to rebuild essential services without cooperation from the attacker.
3. Treat professional-service firms as high-risk dependencies. Law firms, accountants, consultants, managed-service providers and cloud administrators may hold credentials and information belonging to many clients. Supplier assessments should consider not only whether a provider stores personal data, but also whether compromising it could expose confidential strategy, privileged communications, payment processes or administrative access.
4. Map geopolitical exposure. Executives should identify which customers, countries, sectors and public positions could attract state-linked or ideological targeting. The exercise should cover subsidiaries, joint ventures, suppliers, senior personnel and outsourced providers, not only the location of the company’s headquarters.
5. Integrate communications into cyber exercises. A destructive incident may be accompanied by leaks, fabricated claims or online propaganda.
Exercises should therefore involve management, legal counsel, communications teams and business leaders as well as cybersecurity personnel. The organisation must be able to explain what it knows, what remains unverified and how customers should respond.
6. Measure recovery capability. Boards should ask more than how many attacks were blocked. Useful indicators include:
- how quickly a compromised account can be contained;
- how many critical suppliers have privileged access;
- when essential backups were last restored successfully;
- how long core business services can operate manually;
- whether executive and crisis communications remain available if normal systems fail.
Cyber resilience is now part of geopolitical resilience
The latest figures from Israel illustrate an important change in the nature of conflict. National cyber authorities may successfully protect major infrastructure while attackers redirect their efforts towards companies with fewer resources. For those businesses, being outside the defence, energy or government sectors offers no guarantee of safety.
A ceasefire can halt aircraft, missiles or artillery. It does not automatically remove compromised credentials, close attacker infrastructure, end proxy relationships or eliminate the political value of disruption.
For decision-makers, the conclusion is straightforward: geopolitical risk can arrive through an email account, a professional adviser, a software supplier or an inadequately protected backup system.
Cyber preparedness must therefore continue after military activity pauses, because the digital part of the conflict may be only beginning.
