Skip to content
Cybersecurity

Israel-Iran Cyber War: What Internet Intelligence Shows

/ 12 min read / Malik Tanveer Dhool

The Israel–Iran cyber war runs alongside the 2026 conflict — wiper attacks, exposed industrial controllers, and hacktivist DDoS waves. Here is what internet intelligence reveals about the digital front, and how researchers track it.

← Back to Blog
Share X in

WarBrief Live | October 6, 2026 | Cyber Intelligence

Since coordinated U.S. and Israeli strikes hit Iran on February 28, 2026, the two countries’ long-running shadow conflict has run on two tracks: missiles in the air and malware on the wire. Cyber operations now support military campaigns, target power and water systems, and spill over onto hospitals, law firms, and small businesses. This guide to Censys Israel Iran cyber warfare research explains what the public evidence shows about that digital front, and how defenders use internet intelligence — continuous scans of the public internet — to watch it develop.

Neither side publishes a complete account of its cyber operations. What we can verify comes from government advisories, vendors, researchers, and officials on the record. This article separates confirmed facts from claims, and shows how open internet scanning lets the rest of us observe the conflict’s infrastructure.

Key Takeaways

  • The cyber war runs in parallel with the kinetic one: the February 28, 2026 opening strikes were paired with a near-total internet blackout across Iran that lasted more than 60 hours, according to network monitors.
  • Iran-aligned groups escalated sharply after the strikes — hacktivist DDoS claims jumped 103% in March 2026, and the Handala persona, linked by researchers to Iran’s intelligence ministry, claimed destructive attacks including a wiper strike on medical-device maker Stryker.
  • Critical infrastructure is firmly in the crosshairs: U.S. agencies warned in April 2026 of Iran-linked actors exploiting exposed industrial controllers, and water systems in at least 12 U.S. states were hit by that summer.
  • Internet intelligence helps defenders see attacks coming: researchers use continuous internet-wide scanning — the kind Censys pioneered — to find exposed devices and map adversary infrastructure before incidents occur.

What does the Israel–Iran cyber war look like in 2026?

The cyber dimension of the 2026 conflict is not a separate war; it is woven into the fighting. Before and during military operations, both sides have used cyber tools for espionage, disruption of command systems, and information operations aimed at civilian populations. After strikes, aligned hacker groups have launched retaliatory campaigns against government, commercial, and infrastructure targets.

The scale is now measurable. Israel’s National Cyber Directorate told Germany’s Die Welt that hostile cyber incidents rose from roughly 1,600 in June 2025 to about 4,800 in June 2026, a threefold increase, according to Reuters’ reporting of the interview on June 29, 2026. The targets ranged from critical infrastructure and central organizations to small and mid-sized companies — including law practices and accounting firms whose systems were in some cases wiped.

“Unlike in the kinetic realm, there is no ceasefire in cyberspace.” — Yossi Karadi, Director General of Israel’s National Cyber Directorate, in an interview with Die Welt, reported by Reuters on June 29, 2026.

Microsoft’s Digital Defense Report, published October 1, 2026, put Israel’s exposure in global context. Based on telemetry from July 2025 through June 2026, Israel accounted for 7.6% of all observed global cyber threat activity — second only to the United States at 25.5%, as summarized by Ctech. The report identified Iran as the primary state-backed source of attacks on Israel, and found Israel was the target of 39% of all Iranian-linked activity. These figures describe observed activity volume; attribution in cyberspace is always an assessment, not a certainty.

How did cyber operations shape the opening of the February 2026 war?

When U.S. forces launched Operation Epic Fury and Israel launched Operation Roaring Lion on February 28, 2026, cyber and electronic-warfare capabilities were integrated into the opening phase, according to compiled reporting on the conflict. The reported goal was to disrupt Iranian command-and-control, communications, and sensor networks ahead of and during the airstrikes.

The most visible digital effect was a near-total internet blackout across Iran. NetBlocks reported connectivity falling to 1–4% of normal for over 60 hours. The outage was attributed to a combination of physical strikes on data centers and large-scale cyber disruption — which some Israeli sources described as the largest cyberattack in history. That description is a source claim, not an independently verified ranking.

Information operations ran alongside the disruption. Reports describe Israeli operations that compromised a popular Iranian prayer app and state broadcasting channels, pushing messaging directly to Iranian civilians. On the Iranian side, the blackout itself limited the state’s ability to coordinate sophisticated responses in the first days of the conflict, and analysts assess that much of the early retaliatory cyber activity was pushed out to external proxy groups rather than directed from inside Iran. Tracking Adversary Infrastructure With Censys Data

AI-generated illustration

When did the cyber conflict escalate? A dated timeline

  • January 14–15, 2026: Check Point researchers observed Iran-linked actors intensifying scans of Hikvision and Dahua IP cameras across Israel, the UAE, Qatar, Bahrain, and Kuwait — activity the researchers attributed to Iranian threat actors and assessed as reconnaissance to support military intelligence and battle-damage assessment. (Source: Check Point Cyber Security Report 2026, via Security Affairs.)
  • February 28, 2026: Coordinated U.S. and Israeli strikes on Iran began. Cyber and electronic-warfare operations were integrated into the opening phase, and Iran’s internet connectivity collapsed to 1–4% of normal for more than 60 hours, according to NetBlocks and other monitors. (Sources: CENTCOM statements; NetBlocks reporting.)
  • March 2026: Hacktivist DDoS claims surged. Radware recorded a 103.1% jump to 1,308 claimed attacks in March, with roughly 60 groups — Iran-aligned, anti-Western, and pro-Russian — joining campaigns against Israel, the United States, and Gulf states. (Source: Radware, via Ctech, September 9, 2026.)
  • March 11–12, 2026: The Handala persona claimed a destructive wiper attack on Stryker, a U.S. medical-device manufacturer, claiming to have wiped devices across 79 countries — figures that are Handala’s own claims and remain unverified. MITRE’s ATT&CK database lists Handala as a persona of VOID MANTICORE, assessed to operate on behalf of Iran’s Ministry of Intelligence and Security. (Sources: MITRE ATT&CK G1055; security researchers’ reporting.)
  • March 27, 2026: Handala claimed to have hacked the personal email of FBI Director Kash Patel and published more than 300 emails — again, a group claim, not independently confirmed. (Source: Picus Security threat-group timeline.)
  • April 7, 2026: The FBI, CISA, and NSA issued advisory AA26-097A warning that Iran-linked advanced persistent threat actors were exploiting internet-exposed Rockwell Automation programmable logic controllers across critical infrastructure sectors, with activity linked to the CyberAv3ngers group associated with Iran’s Revolutionary Guard. (Source: U.S. agencies’ advisory, via Security Affairs.)
  • June 29, 2026: Israel’s cyber chief Yossi Karadi told Die Welt that hostile incidents had tripled year over year to about 4,800 in June 2026, and that attacks on critical infrastructure had so far been fended off. (Source: Reuters.)
  • July 22, 2026: CISA expanded advisory AA26-097A. By early August, water and wastewater systems in at least 12 U.S. states had been hit in the Iran-linked campaign — including a July 27 pump-station failure in Clayton County, Georgia, that triggered a precautionary boil-water advisory. (Source: Startup Fortune, October 3, 2026, citing WSB-TV and The Record.)
  • September 9, 2026: Radware reported that Israel absorbed 784 hacktivist-claimed DDoS attacks in the first half of 2026 — nearly one in six such attacks worldwide, and more than twice Ukraine’s 390. (Source: Radware, via Ctech.)
  • October 1, 2026: Microsoft’s Digital Defense Report found Israel was the world’s second-most targeted country for cyber threat activity over the prior year, with Iran the main state-backed source of attacks against it. (Source: Microsoft, via Ctech.)
  • October 5, 2026: Iran’s National Center for Cyberspace chief Mohammad-Amin Aqamiri claimed Iran had foiled cyberattacks that began “in the very first hours” of the February 28 assault, and said Iran had disabled Starlink terminals during the January riots — Iranian official claims carried by state media, not independently verified. (Source: Press TV, Iranian state media.)

How researchers use Censys data to track Israel–Iran cyber warfare

Much of what the public knows about this conflict’s digital front comes not from governments but from researchers watching the open internet. Platforms like Censys continuously scan the public IPv4 address space, recording which devices are reachable and which services and certificates they present. That defensively collected scan data lets analysts find exposed industrial controllers, track adversary infrastructure, and measure how the attack surface changes during a crisis.

During the 2026 conflict, that visibility mattered. When U.S. agencies warned on April 7 that Iran-linked actors were targeting exposed Rockwell Automation controllers, Censys researchers identified 5,219 internet-exposed hosts responding as Rockwell/Allen-Bradley devices, with 74.6% located in the United States. By late July, as the water-sector campaign spread, Censys and other scanning services counted more than 4,100 exposed Rockwell hosts, over 4,100 Siemens SIMATIC hosts, and roughly 2,000 Schneider Electric devices reachable from the public internet — a map of the exact equipment the attackers were reported to be targeting. Scan data of this kind turns a vague warning into a concrete to-do list: these devices, these ports, disconnect them. Cyber Warfare Research: Using Internet Scan Data (2026)

Censys research has also illuminated the Iranian side of the picture. In earlier work, Censys researchers mapped hidden infrastructure used by Fox Kitten, an Iranian threat group, by pivoting on certificate patterns, hosting fingerprints, and shared autonomous systems — surfacing tens of thousands of additional potentially malicious hosts. Censys also tracked exposure of Unitronics, Red Lion, and Tridium industrial devices month by month through the first half of 2025.

It is important to be precise about what this is: defensive observation. Scanning the public internet, correlating certificates, and publishing exposure counts is research — it does not involve participating in any operation, attacking any system, or assisting either side. Internet scanning in conflict zones is a measurement tool, and its value in the Israel–Iran cyber war has been to give defenders facts before incidents: what is exposed, where, and which adversary infrastructure is being staged. CensysInspect Explained: Internet Intelligence Guide How Internet Intelligence Helps Investigate Cyber Attacks

AI-generated illustration

Why does critical infrastructure keep appearing in the crosshairs?

Industrial systems are attractive targets for a simple reason: many are reachable from the internet with weak or no authentication. The April 2026 U.S. advisory described attackers who did not need custom malware at all — they found programmable logic controllers exposed online, changed passwords, locked out the legitimate operators, and in some cases altered the devices’ network settings to disconnect them entirely.

The water sector showed how far that simple playbook can go. The July 2026 campaign against U.S. water and wastewater systems reached at least 12 states, according to state officials and CISA. Reporting in October 2026 described attackers widening the same approach from water systems toward telecom and energy grids. Microsoft’s Digital Defense Report independently noted that the energy, telecommunications, and manufacturing sectors faced significant attention from state-linked campaigns, with objectives spanning espionage, intelligence gathering, support for kinetic military operations, and data destruction.

This is not a new pattern in the region. Iran-linked actors have a documented history of targeting industrial control systems, including the Unitronics devices exploited in earlier campaigns and the CyberAv3ngers activity flagged in the 2026 advisories. What changed in 2026 was tempo and context: with a shooting war underway, exposed infrastructure became a retaliatory target of choice, reachable without breaching hardened networks. For a deeper look at the threat landscape, see our coverage of Iran-focused cyber threat research. Censys, Iran Cyber Attacks and Exposed Infrastructure Censys and Critical Infrastructure: Finding Exposed Systems

The defensive lesson is unglamorous but effective: disconnect industrial controllers from the public internet, route remote access through secure gateways, and monitor exposure continuously. Every device Censys counted in those April and July tallies was a device its owner could have hidden.

Frequently asked questions

What is the Israel–Iran cyber war?
It is the digital dimension of the broader Israel–Iran confrontation: cyber espionage, disruptive attacks on infrastructure, hacktivist DDoS campaigns, and information operations conducted by state-linked actors and aligned groups. It runs in parallel with the kinetic war that began with the February 28, 2026 strikes, and — as Israel’s cyber chief put it — it does not pause when the fighting does.

How does Censys help researchers study cyber warfare?
Censys continuously scans the public internet and records which devices, services, and certificates are visible. Researchers use that data defensively: to find exposed industrial controllers before attackers do, to track how adversary infrastructure is set up and moved, and to measure how the attack surface changes during a crisis. Censys does not participate in operations; it provides observation.

Which groups are linked to Iran’s cyber operations?
Security researchers and MITRE’s ATT&CK framework link the Handala persona to VOID MANTICORE, assessed to operate for Iran’s Ministry of Intelligence and Security. U.S. agencies have linked the CyberAv3ngers group to Iran’s Revolutionary Guard in connection with the 2026 industrial-controller campaign. Iran denies carrying out hacking campaigns against other countries. Dozens of loosely aligned hacktivist groups have also claimed attacks, though their claims are often exaggerated.

Is critical infrastructure actually at risk?
Yes — demonstrably. U.S. agencies warned in April 2026 of Iran-linked actors exploiting exposed industrial controllers, and by that summer water systems in at least 12 U.S. states had been hit. Israel’s cyber chief said critical-infrastructure attacks against Israel had so far been fended off, while smaller organizations suffered wiper attacks. The consistent weak point is internet-exposed operational technology, not exotic zero-day exploits.

Conclusion

The Israel–Iran cyber war of 2026 is best understood as a second front that never closes. It opened in lockstep with the February 28 strikes, surged through the spring as proxy and hacktivist groups joined in, and settled into a persistent campaign against the softest targets available: exposed industrial controllers, small businesses, and public-facing services. The confirmed record describes a conflict heavy on disruption and espionage, where the most damaging effects came not from sophisticated implants but from simple exposure.

That is also why internet intelligence has become central to understanding it. Continuous scanning of the public internet cannot stop an attack, but it can show defenders exactly where they are vulnerable and let researchers watch adversary infrastructure take shape. In a war with no ceasefire in cyberspace, visibility is the closest thing to an early-warning system the public has.

Sources and Further Reading

  • Reuters (via SRN News) — “Iran cyberattacks on Israel surged in 2026, Israeli cyber chief says,” June 29, 2026. srnnews.com
  • Ctech — “Israel was the world’s second-most targeted country for cyberattacks, Microsoft finds,” October 1, 2026. calcalistech.com
  • Ctech — “One in six geopolitical cyberattacks worldwide targeted Israel in first half of 2026” (Radware report), September 9, 2026. calcalistech.com
  • MITRE ATT&CK — VOID MANTICORE (G1055), Handala / MOIS-linked threat group. attack.mitre.org
  • Security Affairs — “Censys finds 5,219 devices exposed to attacks by Iranian APTs, majority in U.S.,” April 2026. securityaffairs.com
  • Security Affairs — “Iran-linked hackers target IP cameras across Israel and Gulf states for military intelligence,” March 2026. securityaffairs.com
  • Startup Fortune — “Iranian hackers widen water system attacks to telecom and energy grids,” October 3, 2026. startupfortune.com
  • Industrial Cyber — “Censys warns systemic exposure of Rockwell PLCs enable Iran-linked targeting of critical infrastructure OT networks,” April 2026. industrialcyber.co
  • Wikipedia — “Cyberwarfare during the 2026 Iran war.” en.wikipedia.org
  • Press TV — “Iran ‘technically prepared’ to counter cybersecurity threats: Cyberspace authority,” October 5, 2026. presstv.co.uk

Written by

Malik Tanveer Dhool

Defense and intelligence analysis for WarBrief.live. Covering conflict, technology, and geopolitical strategy.