Hacktivist activity has increased as tensions involving the United States, Iran, and Israel intensify, according to Sophos threat research. The reported campaigns indicate a rise in politically motivated cyber operations tied to the regional conflict, with threat actors using disruptive and influence-focused tactics to target organizations and amplify geopolitical messaging.
The activity reflects a broader pattern in which international crises quickly spill into cyberspace, raising the risk of website defacements, distributed denial-of-service attacks, and other opportunistic intrusions against public- and private-sector targets. Sophos said the escalation underscores the need for organizations with exposure to the region or to politically sensitive sectors to monitor for hacktivist threats and strengthen defensive readiness.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Secureworks published research assessing that the threat activity tracked as Abraham's Ax was likely connected to the Moses Staff group. This introduced a specific attribution development separate from broader reporting on rising hacktivist activity tied to regional tensions.
DarkOwl published analysis concluding that Harakat Ashab al-Yamin al-Islamia, which surfaced in early 2026 claiming attacks in Europe, is better understood as a front identity or media node within a broader Iranian-aligned Telegram ecosystem rather than a clearly distinct organization. The report cited fragmented channels, reposting overlap, and shared propaganda artifacts as indicators of coordinated amplification across affiliated networks.
Sophos published research stating that hacktivist activity had increased as conflict involving the United States, Iran, and Israel intensified. The reference does not provide specific underlying incident dates, so the publication date is used as the event date.
On February 28, cyber operations reportedly accompanied coordinated U.S.-Israeli airstrikes on Iran. Reported effects included compromise of the BadeSaba religious calendar app, defacements of Iranian news sites, attacks on government and military services, and major disruption to Iranian communications during a near-total internet blackout.
Cyble reported that hacktivist groups launched distributed denial-of-service attacks against U.S. targets following bombings involving Iran. This reflects a specific campaign development tied to regional geopolitical escalation, distinct from later attribution and trend reporting.
X suspended the account of the pro-Palestinian hacking group Handala as U.S. officials publicly criticized Iran over cyberattacks. The action marked an earlier platform and policy response tied to the broader cyber activity later associated with regional tensions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
darkowl.com
Open sourcecybersecuritydive.com
Open sourceintel471.com
Open sourcefalconfeeds.io
Open sourcetheregister.com
Open sourcecyble.com
Open sourcetherecord.media
Open sourcesecureworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.