An Iran-linked hacktivist group identified as Nasir Security, also known as Nasir Resistance, has allegedly leaked data stolen during a months-long breach of Dubai International Airport. Reports say the exposed material includes passport images belonging to Americans, Arabs, and Emiratis, along with photos of luggage contents and airport security scanner images. No confirmed evidence has emerged that airport operational systems or intelligence data were exposed, but the leaked personal records could be used for identity theft, fraud, and targeting of travelers.
The intrusion was reported amid a broader escalation in regional cyber activity following U.S.-Israel strikes against Iran, with researchers linking the campaign to a wider pattern of Iranian cyber operations. Separate reporting also noted activity by the Iranian state-backed group Seedworm, which has reportedly compromised multiple organizations, including a U.S. bank and another airport, underscoring concerns that transportation infrastructure and traveler data are becoming focal points in the expanding cyber conflict.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
On or before April 1, 2026, Nasir Security began publishing data it claimed was stolen from Dubai International Airport, including passport photos of Americans, Arabs, and Emiratis, luggage content images, and airport security scanner photos. Researchers warned the exposed personal data could facilitate identity theft and fraud.
Cybernews reported that the suspected Iran-linked hacktivist group Nasir Security, also known as Nasir Resistance, compromised Dubai International Airport over a period of months. The intrusion allegedly resulted in theft of passenger-related imagery and documents rather than sensitive operational or intelligence systems data.
Late-February U.S.-Israel joint missile strikes against Iran were cited as a trigger for an escalating cyber conflict in which subsequent hacktivist activity occurred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.