Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Iran hackers resume threats to hit critical infrastructure with ‘unforgettable lessons’

(Image by norqin from Pixabay)

By Bridget Johnson

After an April cessation in kinetic hostilities was announced in the United States’ conflict with Iran, a key state-connected Iranian hacking group similarly dialed back its mounting public threats against critical infrastructure and declared that it had “currently postponed overt confrontation” with the United States per “highest leadership” orders.

Now, as the ceasefire has collapsed and strikes have resumed, Handala has circled back to ominous critical infrastructure threats that reflect those made earlier in the war yet aren’t as detailed.

On Thursday, the group posted on its Telegram channel an image of various critical infrastructure sectors — pumps at a gas station, an aisle at a supermarket, an electricity substation and a water treatment facility — accompanied by the text “YOU WILL REALIZE.”

The threat got vaguer on Saturday as Handala posted an image of a hooded figure with a laptop computer standing amid mainframes. “Sometimes, all it takes is a tiny ripple to change the waters of the Land of Stars… Handala knows better than anyone how to stir the ocean! Many unforgettable lessons,” the group said.

Just before the April ceasefire, in response to President Donald Trump threatening to strike Iran’s power grid, Handala claimed that they were poised to inflict water, electricity and oil sector attacks on the United States and its allies of a caliber to “send your lives back to the Middle Ages.”

“Rest assured: when the time comes, the darkest of nights will have only just begun for America and all its supporters,” the group vowed when announcing that they agreed to an April pause.

Stating in May that they detected “preparations for the renewed outbreak of military conflict in the coming days,” Handala said it would respond to increased U.S. and Israeli actions with “devastating” widespread attacks targeting energy and IT infrastructure.

The nature of renewed hostilities and the recent vague threats from the hackers suggest that this may be their focus yet again as kinetic strikes increasingly hit critical civilian systems. Iran said a Saturday strike on one of its water desalination plants disrupted the water supply to several villages, while Kuwait urged its residents on Saturday to keep power use to a minimum in the sweltering heat after the second Iranian strike on its power and water desalination facilities.

Handala claimed credit for a massive wiper attack on a U.S. medical technology company at the start of the Iran war and, later, the breach of the FBI director’s personal email. In May, Handala claimed that strikes on Fujairah oil facilities in the United Arab Emirates were a “coordinated hybrid cyber and missile attack” with the Islamic Revolutionary Guard Corps and “a fully coordinated operation” that began with their breach of port systems and was followed by kinetic attacks “minutes later.”

Handala also said last month that it assisted the IRGC with pinpointing U.S. targets in response to strikes conducted in retaliation for the downing of a U.S. military helicopter by an Iranian Shahed drone off the coast of Oman.

In June, the group claimed that they breached California water systems in retaliation for alleged U.S. strikes that damaged civilian water infrastructure in southern Iran. They posted images of what appeared to be system logs related to the Bay Area city of San Mateo, Calif., followed by more purported logs and a Cal Water bill bearing the name and address of a customer in Chico, which is north of Sacramento. After an investigation in conjunction with Mandiant, California Water Service said that “the threat actor activity was limited to unauthorized access to a small number of specific user accounts within two third-party service provider platforms.”

“Mandiant did not identify evidence of threat actor activity in Cal Water’s internal information technology or operational technology environments,” Cal Water said. “The investigation determined that the threat actor accessed one active customer’s online Cal Water account using stolen user credentials. The customer account did not provide access to the billing system, and no payment information was compromised.”

At the time of the ceasefire, Handala announced that even though it was dialing back overt action against the U.S. at the time it was continuing cyber operations against Israeli infrastructure “at full force.” 

In a July 4 statement corresponding with the state funeral of Ayatollah Ali Khamenei, Handala claimed that “more than 100 highly critical access points that the Zionist regime had established within the infrastructure of several countries in the region have been identified and neutralized over the past three years, and corresponding guidelines have also been issued.”

“Under the leadership of the new leader of the Ummah, Seyyed Mojtaba Khamenei, Handala will continue its devastating strikes until the eradication of the world’s oppressors and the struggle against disbelief, polytheism, and hypocrisy, and it will continue its path until vengeance and retribution have been taken for the blood of the martyred leader and the oppressed people of Palestine, Iraq, and Yemen,” Handala added.

A pro-Iran hacking group that didn’t relent from DDoS attacks on U.S. interests during the ceasefire — claiming to have hit Bluesky, eBay, Spotify, Microsoft, X and more companies — claimed today to be behind an Airbnb site outage.

The Islamic Cyber ​​Resistance in Iraq – 313 Team claimed late last month to have conducted “a sophisticated cyberattack targeting the U.S. National Weather Service” that “caused intermittent outages and slowed down the website’s operations” and said they were behind the outage of an incident response platform that alerts residents and response teams during disasters, attacks, public health emergencies and more.

On July 12, 313 Team claimed on their Telegram channel that they were behind a Navy Federal Credit Union app outage. The previous day, the hackers claimed to have disrupted the ABC News website.

This past Monday, the group said they targeted the n8n workflow automation platform and “completely disabled the login interface.”

Since then, 313 Team claimed to have targeted Nafath, the national digital identity platform in Saudi Arabia, and then turned its attention to the Saudi Ministry of Human Resources and Social Development’s Qiwa workforce management platform in what they said was a multi-day attack. “We want to reaffirm our unwavering support for the Republic of Yemen and the Ansar Allah movement in breaking the unjust blockade imposed by the illegitimate Saudi regime on the dear Yemeni people,” the group said Friday.

This afternoon, 313 Team said it targeted the Airbnb website, which reflected an “access denied” message as of this article’s publication. The group said on its Telegram channel that it intended to disable the site for an hour.

Click to listen highlighted text!