Also available in Persian — نسخه فارسی EN فا
❓ Unknown

Espionage by 'Probably Iranian' Hackers on LinkedIn

Jan 31, 2026 January 31, 2026 2 min read 📰 Radio Farda
📋 Key Takeaway

A group of hackers, likely from Iran, has been using fake LinkedIn profiles to spy on international targets, including in the U.S. They have successfully interacted with over 200 real users. This highlights ongoing cyber threats from Iran, particularly in sensitive sectors.

🔍 Quick Context Guide
💡 Bottom Line: Iranian hackers are leveraging social media for espionage, posing significant risks to international security.

👥 Key Players

TJ 2889 MENTIONED
Hacker group
"Identified as a likely Iranian cyber espionage group, highlighting Iran's capabilities in cyber warfare."
Dell's security unit MENTIONED
Cybersecurity researchers
"Provided the report that identifies the hacking activities and the methods used."

📰 What Happened

A group of hackers, likely from Iran, has been using fake LinkedIn profiles to spy on international targets, including in the U.S. They have successfully interacted with over 200 real users.

  • The hackers used two groups of fake profiles to gain legitimacy and interact with real users.
  • Targets included individuals in telecommunications, defense, and government sectors across various countries.

💡 Why It Matters

🇮🇷 For Iran: Demonstrates Iran's ongoing investment in cyber capabilities as a tool for espionage and influence.
🌍 Regional: Increases tensions in the Middle East, particularly with Gulf states that are often targets of Iranian cyber operations.
🌐 International: Highlights the persistent cyber threat posed by Iran to U.S. interests and allies, raising concerns about national security.

📚 Background

Iran has been identified as a major player in cyber warfare, often targeting countries it perceives as adversaries. Cyber espionage is a key component of its strategy.

Cybersecurity Geopolitical tensions in the Middle East
📡 Source: INTERNATIONAL
📊 Confidence: 70%
The report comes from Dell's security unit, a reputable source in cybersecurity, providing a reliable analysis of the situation.

A group of 'probably Iranian' hackers has utilized a complex network of user profiles on the LinkedIn social media platform to spy on targets worldwide, including in the United States. A report published by Dell's security unit and reflected in CNN states that the hackers' fake profiles are divided into two groups: the first group presented themselves as collaborators with various governments and international companies, while the second group lent legitimacy to the first group through various means. This report, published on Wednesday, October 7, identifies the group behind these profiles as 'TJ 2889' and indicates that there is strong circumstantial evidence suggesting this group operated from Iran. The computer domains used by these hackers match those of previous cyber attacks attributed to Iran, and their targets included countries in the Middle East, Arab nations, North Africa, and the United States. Dell researchers noted that these cyber spies often posed as associates of major international companies such as Northrop Grumman, General Motors, Teledyne Technologies, Airbus, and Doosan. It appears that these hackers have been successful, as over 200 real LinkedIn users interacted with 25 fake users. Most targets were located in Saudi Arabia, Qatar, the United Arab Emirates, and Pakistan, with 12 targets in the United States. Many of the targets operated in telecommunications, defense, and government sectors. Iran, alongside China, Russia, and North Korea, is defined as one of the biggest threats to the United States in the cyber domain.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →