CloudSEK reports surge in Iranian-aligned cyberactivity targeting US critical infrastructure

CloudSEK reports surge in Iranian-aligned cyberactivity targeting US critical infrastructure

Research reveals rapid mobilisation of hacktivist groups and growing use of AI tools to identify vulnerable industrial control systems following February 28 US-Israel strikes on Iran.

CloudSEK has documented an immediate and significant surge in Iranian-aligned cyberactivity targeting US critical infrastructure following the February 28 US-Israel strikes on Iran, with AI now acting as a direct force multiplier for threat actors.

According to CloudSEK researchers, the escalation highlights how geopolitical conflicts are increasingly mirrored in cyberspace, with hacktivist communities rapidly mobilising to exploit exposed industrial systems and digital infrastructure.

CloudSEK’s key findings include:

• Over 60 Iranian-aligned hacktivist groups activated on Telegram within hours of the February 28 strikes, representing the largest single-event mobilisation of this ecosystem ever recorded.

• An Electronic Operations Room was formed on Telegram to co-ordinate attacks, operating on ideological initiative rather than central state direction, which makes activity harder to predict and constrain.

• More than 40,000 US industrial control systems are currently reachable on the public Internet, many with default or no credentials, representing an immediately exploitable attack surface.

• CloudSEK researchers demonstrated that an actor with no prior ICS knowledge can move from intent to a working list of accessible US industrial targets in under five minutes using AI tools and passive reconnaissance. No scanning, no exploitation and no specialist knowledge required.

• The same AI platforms now embedded in US defence operations are accessible to threat actors for offensive reconnaissance, creating a dual-use dynamic that significantly widens the threat landscape.

Both reports are primary sourced, technically detailed and directly tied to the current conflict escalation. These can be read here and here.

Browse our latest issue

Intelligent CISO

View Magazine Archive