Back to Insights Threat Intelligence

Cyberattack attempts within the framework of Operation Lion’s Roar

The New Battleground: Civilian Organizations in the Crosshairs as Private Companies and Infrastructure Become Part of Geopolitical Conflict

Since the beginning of the war, we have witnessed a sharp increase in cyberattacks against organizations in the US, Israel, and other countries. A prominent example is the attack against the American medical equipment company, Stryker. The company’s global network was shut down, and computer screens displayed the logo of the “Handala” threat group, which is identified with pro-Iranian activity. According to reports, the attackers attempted to exploit cloud management systems to take control of devices and remotely wipe data. This case illustrates how civilian companies, which are not directly related to the fighting, become strategic targets intended to inflict economic and reputational damage. Simultaneously, attempted attacks have been identified against energy, water, telecommunications companies, and government bodies, with the aim of disrupting vital life systems.

Behind the Scenes: State-Sponsored Threat Groups and Access Theft
Breaches based on weak passwords and sophisticated cyber espionage

Several threat groups linked to Iranian intelligence (including APT33, APT55, and CyberAv3ngers) are actively operating against critical infrastructure. Some of these groups managed to penetrate Industrial Control Systems (ICS) simply by finding an “open door”—the use of manufacturer default passwords that were never changed or common, weak passwords. Another concerning phenomenon is the activity of groups like MuddyWater, which act as “Initial Access Brokers.” They do not carry out the entire attack themselves; instead, they specialize in initial breaches and credential theft, then sell that access to other threat groups. This model makes the threat far more complex and dangerous, as several hostile actors can operate simultaneously on the same breach within your organization.

Armies of Hacktivists: Hundreds of Attacks Under the Umbrella of Telegram
Coordinated activity, use of AI, and psychological warfare

In addition to state-level capabilities, dozens of hacktivist groups (ideological hackers) have established attack coalitions coordinating activity via the Telegram app. These groups claim to have carried out hundreds of attacks against government websites, defense companies, and commercial organizations. Most activity focuses on Distributed Denial of Service (DDoS) attacks, homepage defacements, and leaking stolen information, but attempts at deeper penetration into corporate networks have also been identified. Attackers are currently utilizing AI tools to refine phishing messages and Broaden influence campaigns online. The digital campaign has also attracted pro-Iranian groups from Russia and Iraq, expanding the scope of the threat and making attribution more difficult.

Recommendations from IPV Security Professionals
To strengthen your organization’s digital resilience, it is recommended to take the following steps:

  • Password Security: Replace default passwords and adopt strong passwords across all systems.
  • Identity and Access Management (IAM): Remove access for inactive users and accounts of former employees.
  • Software Updates: Perform regular security patching for all servers and systems.
  • Cloud Service Protection: Strengthen VPN systems, email platforms, and cloud services.
  • Monitoring and Control: Increase monitoring for anomalous network login attempts.
  • Isolated Backups: Ensure the existence of functional backups that are physically separated from the main network.
  • Incident Response (IR) Plan: Prepare an organized action plan for when a cyber incident is detected.
  • Risk Assessment: Conduct in-depth audits of the organization’s critical systems.
  • Employee Training: Raise staff awareness regarding phishing attempts and social engineering.

In conclusion, the current conflict proves that the civilian and business home front is on the digital firing line. Attacks target anyone perceived as a “weak link”—from medical equipment companies to national infrastructure. Organizations must assume they are potential targets, strengthen basic defenses, and prepare for operational disruption scenarios as an integral part of risk management and business continuity.

For more information: https://www.euronews.com/next/2026/03/18/how-cyberattacks-are-being-used-as-weapons-in-the-iran-war

To consult with an expert, contact IPV Security!
For professional consultation, you can reach us at info@ipvsecurity.com or by phone at 077-4447130.
For 21 years, IPV Security has specialized in information security, cyber, risk assessments, and information security standards and regulations.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation