Iran-linked hackers take aim at US and other targets, raising risk of cyberattacks during war

Advertisement

Advertise with us

WASHINGTON (AP) — Pro-Iranian hackers are targeting sites in the Middle East and starting to stretch into the United States during the war, raising the risk of American defense contractors, power stations and water plants being swept into a wave of digital chaos that could expand if Tehran's allies join the fray.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

WASHINGTON (AP) — Pro-Iranian hackers are targeting sites in the Middle East and starting to stretch into the United States during the war, raising the risk of American defense contractors, power stations and water plants being swept into a wave of digital chaos that could expand if Tehran’s allies join the fray.

Hackers supporting Iran claimed responsibility for a significant cyberattack Wednesday against U.S. medical device company Stryker. Since the war began Feb. 28, they also have tried to penetrate cameras in Middle Eastern countries to improve Iran’s missile targeting. They have targeted data centers in the region, as well as industrial facilities in Israel, a school in Saudi Arabia and an airport in Kuwait.

Iran has invested heavily in its offensive cyber capabilities while cultivating ties to hacking groups. In recent years, groups working for Tehran have infiltrated the email system of President Donald Trump’s campaign, targeted U.S. water plants and tried to breach the networks used by the military and defense contractors.

FILE - The CEO of FireEye Kevin Mandia gives a tour of the cybersecurity company's unused office space in Reston, Va., March 9, 2021. (AP Photo/Nathan Ellgren, file)
FILE - The CEO of FireEye Kevin Mandia gives a tour of the cybersecurity company's unused office space in Reston, Va., March 9, 2021. (AP Photo/Nathan Ellgren, file)

The goal is to wear down the American war effort, drive up the costs of energy, strain cyber resources and cause as much pain as possible for American companies that depend on the defense industry.

“Something is going to happen because the gloves are off,” said Kevin Mandia, founder of the cybersecurity companies Mandiant and Armadin.

Who is being targeted

Pro-Iranian, pro-Palestinian hackers claimed credit for disrupting systems at Stryker, a Michigan-based medical technology company. A group known as Handala said the attack was in retaliation for suspected U.S. strikes that killed Iranian schoolchildren.

Like other ideologically motivated hackers, profit is not Handala’s goal, according to Ismael Valenzuela, vice president of threat intelligence at the cybersecurity company Arctic Wolf.

“What distinguishes this group is its clear focus on data destruction rather than financial extortion,” he said in an email.

Polish authorities are investigating a recent cyberattack — on a nuclear research facility — that may have ties to Iran, though they acknowledge that another group could be behind the attack and using the Iran war to mask its identity.

Going forward, U.S. defense contractors, government vendors and businesses that work with Israel are likely targets, as is critical infrastructure such as hospitals, ports, water plants, power stations and railways.

Pro-Iranian hackers openly discuss their plans in Telegram and other online message boards.

“The datacenters need to be taken out,” wrote one user, as uncovered by researchers at U.S.-based SITE Intelligence Group. “They host the brains of USAs military communication and targeting systems.”

Cyber operations also gather intelligence — for example, Iran’s effort to hack into cameras in neighboring countries to aid its missile targeting. Infiltrating U.S. networks, meanwhile, would offer view into military planning or supply chains.

Going after easy targets

The strikes on Iran’s military as well as internet outages may have limited Iran’s cyberattacks in the short term. But experts say Iranian hackers and their allies will aim for quick victories by targeting the weakest links in American cybersecurity.

Often, local water plants or health care facilities lack the funds and know-how to install the latest software patches or take other security steps. That has made them a favorite target, both because of the relative ease of penetrating them and because of the panic these disruptions can cause.

This can include denial-of-service attacks, in which hackers try to jam a network so legitimate users cannot use it, and website defacements, which can prevent a company from communicating with customers. Hack-and-leak operations, where hackers threaten to release sensitive stolen material, are another possibility.

The attacks are not that sophisticated, according to Shaun Williams, a former FBI and CIA officer who is now a senior director at the cybersecurity firm SentinelOne. But if a business or government agency has failed to keep up with its cybersecurity, it could pay a steep price, he said.

“Patch your systems. Ensure your firewalls and security solutions are up to date,” Williams said. “Remove your stale accounts. All the cyber hygiene that you should be doing, it’s more critical now than ever. Prepare for disruption.”

When it comes to cyber, Iran is considered a chaos agent

Russia and China present the greatest cyber threats to the U.S., while North Korea is a growing concern. But what Iran has lacked in resources it has made up for in ingenuity, experts say.

In recent years, Tehran’s digital warriors have impersonated American activists online to covertly encourage protests against Israel on college campuses. They have set up fake news websites and social media accounts primed to spread false and exaggerated claims before big U.S. elections.

In 2024, Iranian hackers infiltrated the email system of the Trump campaign and later tried to disseminate files that the hackers said they stole. Hackers linked to Iran also tried to hack into the WhatsApp accounts of both Trump and his then-Democratic opponent, President Joe Biden.

The activity prompted the Department of Homeland Security to issue a public warning last year about Iranian cyber threats.

“Iran and especially the proxies don’t care how big or smart you are. This is about making an impact, about creating chaos,” said James Turgal, a cybersecurity expert who spent 22 years as an FBI agent and is now a vice president at Optiv, a Denver-based information security firm.

Next moves from Russia and China

Experts are watching closely to see if Russia, China or hacking groups allied with either country provide hacking assistance to Iran, mounting attacks intended to undermine American operations in Iran and make it harder for the U.S. to sustain its fight.

While China has so far taken a cautious approach, there is evidence that pro-Iranian hackers in Russia are already at work. Researchers at the cybersecurity firm CrowdStrike detected a surge of activity from Russian hackers in support of Tehran since the war began.

One group known as Z-Pentest claimed responsibility for disrupting several U.S. networks, including some involved in closed-circuit video cameras.

The timing of the attack suggests the hackers were targeting U.S. interests because of the war in Iran, according to Adam Meyers, head of counter adversary operations at CrowdStrike.

“Western organizations should continue to remain on high-alert,” Meyers said.

Report Error Submit a Tip

More Stories

Goldeyes face rival RedHawks in first round of playoffs

Mike McIntyre 5 minute read Preview

Goldeyes face rival RedHawks in first round of playoffs

Mike McIntyre 5 minute read Yesterday at 6:44 PM CDT

Now the real fun begins.

The Winnipeg Goldeyes have completed the marathon that is the American Association regular season, hitting the finish line Monday afternoon in Kansas City with a 5-1 loss. That leaves the Fish with a 54-46 record, good for second place in the West Division and tied for fourth-best in the 12-team league.

That’s a tidy turnaround from a year ago, when the Fish flopped with a 41-58 record to finish at the bottom of their division and 11th-overall.

Up next? The sprint that is the playoffs, with eight teams looking to reel in the 2026 championship by winning eight high-stakes games over the next three weeks.

Read
Yesterday at 6:44 PM CDT

Woman died while getting wisdom teeth out; case raises questions about transparency of dental association

Nicole Buffie 5 minute read Preview

Woman died while getting wisdom teeth out; case raises questions about transparency of dental association

Nicole Buffie 5 minute read Friday, Sep. 4, 2026

The parents of a 23-year-old southwestern Manitoba woman who died after receiving a local anesthetic during a wisdom tooth extraction say they are in the dark about the investigation into their daughter’s death.

Dulaney and Victoria Blatz say the Manitoba Dental Association has been unwilling to give them information about the probe into their daughter’s death, saying the self-governing regulatory body must be more transparent with the public.

“We have pushed through various channels trying to get information, but it’s nothing but stalling and sidelining,” Victoria said Friday. “This has crashed our world to pieces and we just want answers.”

Virginia Blatz went to Boundary Trails Dental Centre in Morden on Nov. 27, 2024, to have her wisdom teeth removed, but never returned home.

Read
Friday, Sep. 4, 2026

Parts of River Heights hammered by storm

Melissa Martin 5 minute read Preview

Parts of River Heights hammered by storm

Melissa Martin 5 minute read Yesterday at 5:54 PM CDT

A powerful storm cut a swath of destruction through River Heights on Sunday, leaving much of the area without power.

Nobody was hurt in the storm.

By the time it subsided, parts of the quiet neighbourhood, especially Borebank and Lindsay streets between Grant and Taylor, had been ravaged: power lines downed, Manitoba Hydro poles toppled, trees splintered and crashed down on vehicles and homes.

In one case, a vehicle was flipped into a yard and sat under a partially downed tree. Shingles were stripped from roofs. Some residents described looking out during the storm and seeing power lines ablaze and the blue glow of electricity arcing over their backyards.

Read
Yesterday at 5:54 PM CDT

Puzzles Palace

1 minute read Monday, Jul. 27, 2026

To solve our puzzles, please subscribe with this special offer: |

Man injured in downtown shooting

1 minute read Sunday, Sep. 6, 2026

A man in his 20s is in critical condition after he was shot in downtown Winnipeg early Sunday morning.

The Winnipeg Police Service's major crimes unit is investigating and no arrests have been made.

Police responded to the area of Portage Avenue and Balmoral Street, near the University of Winnipeg campus, at about 4:20 a.m. Sept. 6 for the report of a male suffering a gunshot wound. Police provided first aid to the victim, who was taken to hospital.

For newcomer pizza purveyors, it’s all about crafting solid foundations

David Sanderson 7 minute read Preview

For newcomer pizza purveyors, it’s all about crafting solid foundations

David Sanderson 7 minute read Saturday, Sep. 5, 2026

A recent poll conducted by an Internet-based market-research firm determined that close to 20 per cent of people eschew their leftover pizza crust.

Some argued that the residual crust lacks flavour. Others submitted that it’s too hard or crunchy to enjoy sans toppings. Given that information, what are we to make of Crusty Craft Pizza, a five-month-old takeout spot whose owners are so confident in their European-style pizza crust that they’ve chosen to highlight it in their business moniker?

Whenever somebody informs them they don’t like pizza crust, their response is, well, they haven’t tried theirs, says Oleksii Samokvhal, who together with his wife, Iryna Mehedyn, opened Crusty Craft Pizza in early April, at 1311 Day St. in Transcona.

“It’s thin in the middle, with raised edges we hand-form ourselves,” says Mehedyn, a native of Ukraine who, like her Kyiv-born husband, relocated to Winnipeg to escape the conflict in their home country.

Read
Saturday, Sep. 5, 2026