Why Iran's Cyber Warfare Strategy Has Become a 'Perfect Weapon' Against the US


This story, titled "Iran's cyber attack strategy is 'perfect weapon' against US" First published on The National and was retrieved from its original source on September 2, 2026.
Our site bears no responsibility for its content. You can review the details of this story at its original source.
Amid new reports that Iran has broadened cyber attacks on the US, technology experts are warning that hacking is perfectly suited to Iran's geopolitical situation. A report from NBC said Iran had increased efforts in recent weeks to compromise computer systems in the US, which had the potential to affect electricity, telecoms and other critical infrastructure.
Morey Haber, chief security adviser at US cybersecurity company BeyondTrust, told The National he was not surprised by Iran's continued attempts to flex its cyber crime capabilities against the US. “Cyber is an asymmetric weapon, perfectly suited to Iran’s geopolitical position and only requires expertise,” he said. Sanctions on Iran make hacking a logical last choice for the country, he added.
“These attacks can have a significant impact on a population without requiring aircraft, missiles or personnel on American soil, while creating ambiguity around attribution and a proportional response,” he explained. Mr Haber added that, surprisingly, Iranian attacks were not particularly sophisticated from a technical standpoint. But the hackers seem to be having significant success by taking advantage of poor cybersecurity hygiene such as antiquated systems, weak password credential processes and devices that are unnecessarily connected to the internet.
Yiyi Miao, chief product officer of cybersecurity firm OPSWAT, also said he wasn't surprised that Iran was bolstering its various hacking attempts. He cautioned that just because recent Iranian hacks against the US haven't caused anything cataclysmic, the US shouldn't be lulled into a false sense of security.
In July, several US states acknowledged hacks on their water systems, which experts say probably originated in Iran. At the time, however, US President Donald Trump said “incompetence” by state officials was to blame. Without mentioning Iran by name, the Critical Infrastructure Security and Resilience Agency issued a warning about potential cyber attacks against critical US digital systems.
“We are seeing increased targeting of programmable logic controllers in the water and wastewater systems sector,” the agency posted on X, urging utility operators to follow instructions from federal authorities to minimise hacking risks.
As state-sponsored efforts often take place discreetly, one group, Handala, has frequently boasted of its activities since US and Israeli strikes against Iran began at the end of February. In March, Handala followed through on a threat to attack the FBI by hacking director Kash Patel's personal email and cloud services. It was later determined that Handala was behind a cyber attack against Michigan-based medical technology company Stryker.
One of Handala's more concerning hacks took place in June, when the group took credit for breaching the systems of California Water Service, publishing 5 gigabytes worth of data from the breach as proof. However, the group highlighted its restraint in messages on Telegram, stating it did not cut off the water supply and that disruption occurred due to a lack of technical knowledge among the cybersecurity experts at the company.
Long before the US strikes on Iran, cyber hostilities between the countries were an open secret. A 2025 digital defence report from Microsoft indicated that Iran most frequently targeted Israel, the US, the UAE and India with attempted cyber attacks. American officials warned last year that Iran was doubling down on efforts to hack US computer systems, with FBI assistant director Brett Leatherman highlighting these concerns in August 2025.
Iran has also accused the US and Israel of trying to hack its computer infrastructure. Weeks after US strikes on Iran began, US cyber director Sean Cairncross described Iran as a “perpetual bad actor” whose efforts to compromise US digital infrastructure had increased.
John Fokker, vice president of threat intelligence strategy at Trellix, said other countries should also take notes, pointing to recent incidents involving critical infrastructure in the UK and Iranian-linked targeting of the energy and oil and gas sectors across the Middle East. “Cyber operations have become an extension of modern geopolitical conflict, providing states with a way to apply pressure, create disruption, and signal intent without necessarily escalating to direct military action,” Mr Fokker added.
Technology
Technology
Technology
Technology