Iran Cyberattacks on Israel Surged in 2026: Israeli Cyber Chief Warns of Escalation

Iran Cyberattacks on Israel Surged in 2026: Israeli Cyber Chief Warns of Escalation

Four months after Operation Epic Fury, Israel’s cyber chief stood at a conference and said what most people already suspected: the digital attacks have not slowed down. They have gotten worse.

Israel’s cyber chief confirmed at a conference on Sunday, June 29, 2026, that Iran’s cyberattacks against Israel have surged dramatically throughout 2026, a statement delivered four months after Operation Epic Fury. This US-Israeli military campaign killed Iran’s Supreme Leader Ali Khamenei and dismantled most of Iran’s conventional military infrastructure. The attacks are coming from Iranian state-linked threat actors, Iranian hacktivist proxies, and opportunistic groups from across the region. Critical infrastructure, government networks, defense firms, and financial systems are the primary targets. And the digital war shows no sign of following the fragile ceasefire on the ground.

The missiles stopped. The packets did not.

What the Israeli Cyber Chief Actually Said

The Reuters report does not publish a full transcript of the statement. What it confirms is the core finding: cyberattacks from Iran against Israeli targets have surged in 2026.

That word surged is doing real work here. It is not “increased.” It is not “continued.” Surged signals a qualitative shift in volume or intensity that the Israeli cybersecurity leadership considers significant enough to state publicly at a conference.

The statement came at a moment when most public attention had moved to the diplomatic dimension of the Iran conflict ceasefire negotiations, international mediation, and reconstruction. The cyber chief’s remarks are a reminder that the conflict’s digital dimension did not pause for diplomacy.

Israel was already the most targeted country by geopolitically motivated hackers in 2025, absorbing 12.2% of all global attacks according to ZENDATA Cybersecurity. In the 24 hours following the February 28 strikes, Israel jumped from 6% to 21% of global incidents, a 3.5 times increase in a single day. The June 29 statement suggests that the elevated targeting level has not returned to baseline.

The Context: What Happened on February 28

To understand the cyber surge, the February 28 timeline is essential.

On February 28, 2026, the United States and Israel launched coordinated airstrikes codenamed Operation Roaring Lion and Operation Epic Fury, targeting Iranian military command, nuclear facilities, missile infrastructure, and senior leadership. Supreme Leader Ali Khamenei was reported killed on March 1. The Defense Minister, the IRGC commander, and the army chief of staff were also reported killed within hours.

The cyber domain was integrated into the opening phase of those strikes. US Chairman of the Joint Chiefs Gen. Dan Caine confirmed publicly that “coordinated space and cyber operations effectively disrupted communications and sensor networks” in Iran before the main kinetic strikes, with the explicit goal of leaving the adversary “disrupted, disoriented and confused.”

Iran’s domestic internet collapsed to 1 to 4% of normal levels within hours, a combination of physical strikes on data centers and what some Israeli sources described as the largest coordinated cyberattack in history. Iranian state television satellite feeds were replaced with speeches by Trump and Netanyahu. A prayer app with over 30 million installations was hijacked to send surrender messages to military personnel.

That is the opening move. The cyber surge Israel’s chief described on June 29 is a months-long response.

Who Is Attacking The Actors Behind the Surge:

Iran lacks symmetric conventional response options against the United States and Israel, which is why the regime has historically relied on cyber operations and a dispersed ecosystem of proxy forces.

The attacking ecosystem is not a single organization. It is layered.

State-sponsored actors: Primarily units linked to the Islamic Revolutionary Guard Corps, represent the most technically capable tier. MuddyWater, active on US and Israeli networks since at least early February, was confirmed operating with two new backdoors: Dindoor, which runs via JavaScript runtime, and Fakeset, a Python-based tool. Seedworm was operating parallel campaigns across the Middle East, Turkey, and Africa. TA453 was conducting credential phishing against US think tanks as recently as March 8, even as Iran’s own internet was severely degraded.

Iranian hacktivist proxies: Form a second, noisier tier. Handala Hack linked to Iran’s Ministry of Intelligence claimed breaches of Israeli energy firms, Jordanian fuel systems, and healthcare targets. The Cyber Islamic Resistance, which functions as an umbrella collective coordinating smaller crews, launched synchronized DDoS campaigns, website defacements, and data-wiping attacks. FAD Team, aligned with the IRGC’s Fatimiyoun unit, has focused specifically on industrial control system attacks targeting SCADA and PLC control systems in Israel and elsewhere, and allegedly gained unauthorized access to OT devices at an Israeli security firm.

Opportunistic actors, from outside Iran, have joined the campaign. Pro-Russian hacktivist group NoName057(16) declared solidarity with Iran and launched DDoS attacks against Israeli defense and municipal organizations, including defense contractor Elbit Systems. By March 2, more than 60 groups had publicly claimed actions against Israeli or allied targets. Over 100 pro-Iranian hacktivist groups mobilized on Telegram within 15 days of the February 28 strikes.

The scale of the ecosystem is the tactical insight most coverage misses. Israel is not defending against one adversary. It is defending against a coordinated, layered, and continuously evolving network of actors who are neither fully state-controlled nor fully independent.

What Is Being Targeted

The targeting pattern follows what Iran has learned over the years of offensive cyber operations and what became dramatically more urgent after February 28.

Critical infrastructure: Is the priority. The Stryker attack, a breach of a major US medical technology company attributed to Iran-aligned hackers, wiped thousands of computers and paralyzed the company’s global operations. Jordan’s National Cybersecurity Center confirmed it blocked an Iranian cyberattack targeting the national wheat silo management system. Claims of breaches to Israeli water management systems, power transmission infrastructure, and industrial control systems have circulated, though independent verification of the most dramatic claims remains incomplete.

Financial systems are a consistent target. Israeli bank websites were knocked offline via DDoS attacks attributed to Dark Storm Team. Predatory Sparrow wiped Bank Sepah’s data and burned $90 million in stolen cryptocurrency from Nobitex in a single operation.

Government and defense networks draw the most sophisticated state-level attention. Intel 471 identified national government, aerospace and defense, and technology as the three most impacted industries in the week following the February 28 strikes.

Information operations run in parallel with the technical attacks. Iranian state media was hijacked to display anti-regime messages. Palestinian television channels were interrupted to display pro-Israel content. A Citizen Lab report documented an AI-enabled disinformation campaign designed to instigate Iranian internal unrest.

Why the Ceasefire Did Not Stop the Cyber War

This is the detail that the Israeli cyber chief’s statement makes explicit and that most diplomatic coverage ignores.

When conventional military options are degraded or constrained, cyber operations become more important as an instrument of state power, not less. Iran’s conventional military infrastructure was systematically dismantled in February. Its cyber capability was not. The IRGC units that run offensive cyber operations operate differently from the missile forces that were struck. They are dispersed, deniable, and functional regardless of what happens to physical military infrastructure.

The fragile ceasefire that exists on the ground creates a political constraint on kinetic retaliation. It creates no equivalent constraint on cyber operations. A state-linked hacker group attacking Israeli financial systems provides no treaty-violating casus belli. The attack happens. Responsibility is deniable. The ceasefire technically holds.

Cyber warfare has become the conflict’s permanent layer, the dimension that continues regardless of what diplomatic frameworks exist above it. The Israeli cyber chief confirming a surge in June 2026 is not a surprise. It is a confirmation of the structural logic of modern hybrid conflict.

The Stryker Attack: The Case That Changed Everything

Of all the cyberattacks documented in 2026, the Stryker breach deserves specific attention because of what it revealed about Iran’s operational evolution.

Iran did not use custom malware in the Stryker attack. The breach was conducted using legitimate IT tools, abusing trusted software rather than deploying detectable malicious code. Security researchers confirmed this. No malware signature was found. The disruption was real: thousands of computers were wiped out, and global operations were paralyzed.

Stryker is a US medical technology company. The attack was not on a military target, a government network, or a defense contractor. It was in a company that makes surgical equipment. The targeting choice signals something about where Iran believes the leverage is and about how willing it is to cross what Western governments have historically treated as implicit red lines around civilian critical infrastructure.

Frequently Asked Questions

What did Israel’s cyber chief say on June 29, 2026?

Israel’s cyber chief confirmed at a conference that Iran’s cyberattacks on Israel have surged in 2026, a statement delivered four months after Operation Epic Fury. This US-Israeli military campaign killed Iran’s Supreme Leader and dismantled most of Iran’s conventional military infrastructure. The specific figures cited have not been published by Reuters.

Why did Iranian cyberattacks surge after Operation Epic Fury?

When conventional military capacity is destroyed or constrained, cyber operations become a primary remaining instrument of asymmetric retaliation. Iran’s IRGC cyber units operate differently from missile forces; they are dispersed, deniable, and functional regardless of physical military infrastructure. A ceasefire constrains kinetic action but creates no equivalent constraint on cyber operations.

What Iranian threat actors are attacking Israel in 2026?

The attacking ecosystem includes IRGC-linked state actors such as MuddyWater, Seedworm, and TA453; Iranian hacktivist proxies including Handala Hack, Cyber Islamic Resistance, and FAD Team; and opportunistic actors such as pro-Russian group NoName057(16). Over 100 pro-Iranian hacktivist groups mobilized on Telegram within 15 days of the February 28 strikes.

What is the Stryker cyberattack?

The Stryker attack was a breach of the US medical technology company Stryker attributed to Iran-aligned hackers. It wiped thousands of computers and paralyzed the company’s global operations without using custom malware. Iran abused legitimate IT tools instead, leaving no detectable malware signature. The attack is significant because it targeted civilian critical infrastructure rather than military or government networks.

What types of targets are Iranian hackers hitting?

Primary targets include Israeli critical infrastructure (water systems, power grid, industrial control systems), financial systems (bank websites, cryptocurrency exchanges), government and defense networks, and US companies with connections to Israel. Information operations, disinformation campaigns, hacked media broadcasts, and compromised apps run simultaneously with technical attacks.

Is there a cyber ceasefire between Iran and Israel?

No. The fragile ceasefire that exists on the ground creates political constraints on kinetic action but no equivalent constraint on cyber operations. The Israeli cyber chief’s June 29 statement confirming a surge in attacks is an implicit acknowledgment that the conflict’s digital dimension continues regardless of diplomatic frameworks.

Share this article