TL;DR: Iranian-backed cyber activity has escalated sharply since February 2026, with renewed DDoS, destructive wiper, hack-and-leak, OT targeting and ransomware collaboration, according to SafeBreach and cited CISA advisories. The pattern shows how geopolitical conflict can rapidly expand attack volume, targeting breadth and destructive intent across critical sectors.
At a glance
What this is: This is an independent analysis of how Iranian-backed cyber operations have expanded since February 2026, with the key finding that DDoS, wipers, hack-and-leak activity and OT targeting are all intensifying together.
Why it matters: It matters to IAM practitioners because the same campaign mix now combines destructive operations with credential abuse, exposed OT access, and compromised cloud resources, widening the identity and access governance surface across enterprise and critical infrastructure programmes.
By the numbers:
- A 700% spike in cyberattacks against Israel was recorded during the 2025 conflict.
- As of June 22, 2025, 120 hacktivist groups were reportedly active.
👉 Read SafeBreach's analysis of the heightened Iranian cyber threat and new attack scenarios
Context
Iranian cyber activity is not a single threat type. It is a blended operational pattern that can combine disruptive DDoS, destructive malware, information operations, OT probing and credential-driven follow-on access. For security teams, the governance problem is that these campaigns move across domains faster than most control owners can coordinate.
The identity angle is not optional in this threat set. The article explicitly ties Iranian activity to default credential abuse, brute-force access, compromised cloud resources and exposed OT interfaces, which means IAM, PAM and NHI governance all sit inside the defensive perimeter. That makes this a cross-domain issue, not just a threat-intel update.
Key questions
Q: What breaks when default passwords remain on OT systems?
A: Default passwords turn critical infrastructure devices into easy entry points, especially when those systems are internet-exposed or poorly monitored. Once an attacker authenticates with unchanged credentials, they may not need exploitation at all. The result is often direct movement toward higher-value operational assets, with containment becoming much harder after the first login.
Q: Why does clean core matter for identity and access governance?
A: Clean core matters because it changes where controls can live. When the SAP digital core is kept minimal, identity governance must operate through supported integrations and policy layers instead of bespoke code. That improves upgrade resilience, but only if IAM and GRC teams redesign controls for portability rather than assuming legacy extensions will carry forward.
Q: What should security teams get wrong about DDoS-focused threat reporting?
A: The mistake is treating DDoS as only an availability problem. In this article, DDoS sits alongside data theft, wipers, hack-and-leak operations and OT targeting, which makes it part of a broader coercion strategy. Teams should judge the whole campaign pattern, not the loudest tactic.
Q: Who is accountable when compromised cloud resources are used in follow-on attacks?
A: Accountability should sit with the control owners who govern cloud identity, secret lifecycle and privileged access, plus the incident response lead for campaign coordination. Frameworks such as NIST CSF and NIST SP 800-53 both expect ownership, monitoring and response mapping across these control domains.
Technical breakdown
How Iranian threat operations combine disruption and destruction
Iranian-aligned campaigns often layer DDoS, hack-and-leak, wiper activity and ransomware-style pressure to overwhelm defenders and shape public perception at the same time. That mix matters because the objective is not always persistence or stealth. In many cases the attacker seeks short-cycle disruption, reputational damage or strategic signalling. When these behaviours are coordinated across state-linked and proxy actors, defenders need to treat them as a campaign family rather than isolated incidents.
Practical implication: build detection and response plans that assume concurrent disruption, data theft and destructive activity rather than one incident at a time.
Why OT and internet-facing devices remain attractive entry points
The article highlights PLCs, HMIs, internet-connected cameras and exposed OT services as recurring targets. These systems often fail because they were deployed for availability, not identity rigor, and many still rely on default passwords, weak authentication or limited network segmentation. Once an attacker reaches the device management plane, even limited access can become process disruption, reconnaissance or battle-damage assessment. The risk is less about a single exploit and more about exposed control surfaces with poor lifecycle governance.
Practical implication: inventory external-facing OT assets, remove default credentials, and segment device management interfaces from general-purpose networks.
Why credential abuse and cloud resource misuse expand the blast radius
The article also notes brute-force credential access, compromised cloud resources and ransomware collaboration. That combination shows how identity weaknesses can extend a regional campaign into enterprise environments far from the original target set. A stolen credential, exposed key or over-permissioned cloud role can provide follow-on access for staging, exfiltration or lateral movement. In practice, this is where NHI governance matters most, because service accounts, API keys and cloud roles become operational enablers for externally driven campaigns.
Practical implication: treat cloud roles, service accounts and secrets as campaign ingress points, not just administrative conveniences.
Threat narrative
Attacker objective: The objective is to disrupt operations, damage trust, and create strategic pressure on targeted sectors while broadening the operational cost to defenders.
- Entry occurs through exposed OT interfaces, weak passwords, phishing or compromised cloud resources that give Iranian-aligned actors an initial foothold.
- Escalation follows when the attacker abuses device access, web shells or stolen credentials to move from reconnaissance into disruptive control or destructive deployment.
- Impact is delivered through DDoS, data theft and leaks, wiper activity, ransomware collaboration or OT process disruption that affects operations and reputation.
NHI Mgmt Group analysis
Geopolitical escalation exposes an identity governance blind spot: when state-linked actors broaden from DDoS into credential abuse, cloud misuse and OT targeting, the weak point is often not perimeter defence but who and what can authenticate in the first place. Service accounts, cloud roles and device logins become campaign infrastructure when they are not tightly governed. Practitioners should read this as a warning that identity controls are now part of geopolitical resilience.
Standing access is a multiplier in conflict-driven campaigns: the article’s combination of brute-force access, compromised cloud resources and OT exposure shows how persistent credentials create reusable attack paths. That is the same control failure pattern seen in many machine identity incidents, where access remains available long after the operational need has passed. Practitioners should assume that any persistent secret or role can be repurposed during a fast-moving threat wave.
Device management planes need the same governance discipline as human admin access: PLCs, HMIs and cameras are not just assets, they are authentication surfaces that can become operational choke points. When default passwords, exposed interfaces or weak segmentation are present, adversaries do not need sophisticated exploitation to create impact. Practitioners should treat OT identity and access controls as an operational resilience issue, not a niche engineering concern.
Campaign convergence is the real warning sign: the notable shift is not just more attacks, but the way destructive malware, hack-and-leak operations and ransomware collaboration are converging around the same geopolitical trigger. That convergence complicates incident classification and response ownership. Practitioners should align security, fraud, OT and resilience teams around shared playbooks before the next escalation cycle.
Cloud and NHI governance now sit inside threat-intelligence response: the presence of compromised cloud resources in the article shows that identity telemetry is part of the defensive picture, not a separate governance topic. This is where the field is heading: threat actors increasingly live off authenticating systems rather than only exploiting software flaws. Practitioners should connect threat intel to entitlement review, secret hygiene and role monitoring.
What this signals
Campaign-level resilience now depends on identity telemetry as much as network telemetry: when adversaries combine DDoS, cloud misuse and destructive operations, defenders need a unified view of authentication, privilege and exposure. That means cloud IAM, OT access governance and incident response cannot stay in separate reporting chains. Practitioners should expect threat-intel-driven playbooks to include entitlement review and secret monitoring alongside traditional network defence.
The governance gap is not visibility alone, but response sequencing: teams often detect the loud part of a campaign first and the identity compromise later. That lag matters because compromised roles and service accounts can outlive the initial attack window. Practitioners should build response paths that start with authenticated access paths, then fan out to affected assets, rather than the other way around.
For practitioners
- Harden exposed OT authentication surfaces Remove default credentials from internet-facing cameras, PLCs and HMI devices, then validate that administrative interfaces are isolated from general user networks.
- Reassess cloud roles and secret exposure paths Review service accounts, API keys and cloud roles that could be reused for follow-on access, and revoke any standing access that is not operationally necessary.
- Build campaign-level detection for destructive activity Correlate DDoS, web defacement, data exfiltration and wiper indicators in a single response view so teams can recognise a blended operation early.
- Align OT, IAM and incident response ownership Assign clear ownership for device authentication, cloud identity monitoring and destructive-malware response before a geopolitical event creates overlapping decision chains.
Key takeaways
- Iranian-backed campaigns are now blending disruption, destruction and identity abuse into a single operating pattern.
- The clearest defensive gap is persistent access, because compromised cloud resources and exposed OT logins can be reused across multiple attack stages.
- Practitioners should connect threat intelligence to IAM, PAM, NHI and OT access governance before the next escalation cycle arrives.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 , Initial Access; TA0006 , Credential Access; TA0040 , Impact | The article centres on initial access, credential abuse and destructive impact. |
| NIST CSF 2.0 | PR.AC-4 | Persistent and weak access controls are part of the attack surface described here. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management is central to credential abuse and device access risk. |
| CIS Controls v8 | CIS-5 , Account Management | Account governance directly addresses the standing-access and weak-password issues in the article. |
| NIST Zero Trust (SP 800-207) | Zero Trust is relevant where exposed OT and cloud access require continuous verification. |
Treat every external authentication path as untrusted and verify access continuously before granting reach.
Key terms
- Hack-and-leak operation: A hack-and-leak operation combines unauthorised access to information systems with selective public disclosure of stolen data to create reputational, political or operational pressure. The technique is often paired with messaging campaigns, making the disclosure itself part of the attack objective.
- Operational Technology: Operational Technology is the hardware and software that monitors or controls physical processes such as manufacturing lines, utilities, and transportation systems. Unlike standard IT, OT prioritises uptime and safety, so identity controls must be precise enough to reduce risk without interrupting essential operations.
- Standing Access: Standing access is persistent privilege that remains available without fresh approval or contextual checks. In NHI environments, standing access usually appears as long-lived tokens, reusable service accounts, or broad roles attached to automation. It is convenient operationally, but it expands risk when conditions change or secrets leak.
- Exposed management plane: An exposed management plane is an administrative interface or control surface reachable from untrusted networks. If it is weakly authenticated or poorly segmented, attackers can move from simple discovery into device control, configuration tampering or process disruption without needing a complex exploit chain.
What's in the full article
SafeBreach's full article covers the operational detail this post intentionally leaves for the source:
- The new attack scenario catalog, including the Known Threat Series and Threat Group content added after the June 2025 post.
- The named advisory and threat-group mappings that SafeBreach uses to simulate Iranian-linked TTPs across sectors.
- The podcast series and episode-by-episode topics that expand on cyber command structure, industrial espionage and AI-assisted social engineering.
- The platform-oriented scenario descriptions for OT devices, wiper deployment and credential-access testing.
Deepen your knowledge
NHI Mgmt Group’s NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management and identity lifecycle fundamentals. It helps practitioners connect those controls to the wider security programme they are accountable for.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org