Also available in Persian — نسخه فارسی EN فا
🟠 Important ❓ Unknown

Iran Collaborates with Ransomware Criminals to Attack the U.S., Israel, Azerbaijan, and the UAE

Jul 12, 2026 July 12, 2026 4 min read 📰 Radio Farda
📋 Key Takeaway

U.S. intelligence agencies report that Iran is collaborating with ransomware groups to conduct cyberattacks against various countries, including the U.S. and Israel. This collaboration includes stealing sensitive data and attempting to influence U.S. elections. The findings highlight the ongoing cyber threat posed by Iran and its strategic use of hacking for political objectives.

🔍 Quick Context Guide
💡 Bottom Line: Iran's collaboration with ransomware groups signifies a growing threat to multiple nations.

👥 Key Players

Ali Khamenei (علی خامنه‌ای) QUOTED
Supreme Leader of Iran
"the Supreme Leader of the Islamic Republic of Iran... urged the fourteenth government to continue the actions of Ebrahim Raisi's administration regarding artificial intelligence."
Masoud Pezeshkian QUOTED
Government official
"in his first meeting with the government of Masoud Pezeshkian."
U.S. Cybersecurity Agency ACTOR
U.S. government agency
"the U.S. Cybersecurity Agency announced on Wednesday."
FBI ACTOR
U.S. law enforcement agency
"The FBI's assessment indicates that a 'significant percentage' of these Iranian cyber hacking operations."
Pentagon's Cyber Crime Center ACTOR
U.S. military agency
"the Pentagon's Cyber Crime Center announced on Wednesday."

⚡ Actions

U.S. intelligence agencies ANNOUNCE organizations in the U.S., Israel, Azerbaijan, UAE
"U.S. intelligence agencies have warned that the Islamic Republic of Iran is collaborating with cybercriminal ransomware groups."
Confidence: 90%
Iranian hackers TARGET government entities, educational, healthcare, and defense sectors
"Iran has recently targeted not only government entities but also the educational, healthcare, and defense sectors."
Confidence: 90%
Iranian hackers COLLABORATE prominent ransomware groups
"Hackers associated with Iran either use ransomware themselves or collaborate with prominent ransomware groups."
Confidence: 90%

📰 What Happened

Iran collaborates with ransomware groups to attack the U.S., Israel, Azerbaijan, and UAE.

  • U.S. intelligence agencies announce organizations in the U.S., Israel, Azerbaijan, UAE
  • Iranian hackers target government entities, educational, healthcare, and defense sectors
  • Iranian hackers collaborate prominent ransomware groups

💡 Why It Matters

🇮🇷 For Iran: Because it enhances Iran's cyber capabilities and influence.
🌍 Regional: Because it escalates tensions with Israel and neighboring countries.
🌐 International: Because it poses a threat to U.S. and allied cybersecurity.

📚 Background

Iran's collaboration with ransomware groups signifies a growing threat to multiple nations.

📝 Key Evidence

"Iran has recently targeted not only government entities but also the educational, healthcare, and defense sectors."
→ Iran's cyber operations against multiple sectors.
📡 Source: INDEPENDENT
📊 Confidence: 80%
Radio Farda is known for its critical stance on the Iranian government.

U.S. intelligence agencies have warned that the Islamic Republic of Iran is collaborating with cybercriminal ransomware groups to launch cyberattacks against organizations in the U.S., Israel, Azerbaijan, and the United Arab Emirates. The FBI, the Pentagon's Cyber Crime Center, and the U.S. Cybersecurity Agency announced on Wednesday, September 7, that Iran has recently targeted not only government entities but also the educational, healthcare, and defense sectors of these countries. The FBI's assessment indicates that a 'significant percentage' of these Iranian cyber hacking operations have been aimed at accessing the networks of these entities through ransomware. In addition to installing ransomware, hackers associated with the Islamic Republic have pursued a broad campaign to steal 'sensitive technical data' from Israeli and Azerbaijani institutions. The three U.S. intelligence agencies prepared their report based on data provided by various institutions affected by these malicious activities. Meta reported attempts by Iranian-affiliated hackers to infiltrate the WhatsApp accounts of U.S. officials. The findings of these three agencies indicate that hackers associated with Iran either use ransomware themselves or collaborate with prominent ransomware groups for espionage and data theft operations. U.S. entities have concluded that hackers linked to Iran share in some of the information obtained through such computer traps in exchange for assistance in launching ransomware. In some cases, hackers have collaborated with ransomware groups that 'locked' the networks of victims and sought to extort those caught in the trap. The report from these three U.S. agencies reminds that cyber actors linked to Iran have been behind multiple hacking operations targeting Israeli organizations and companies for the past four years, primarily not for financial extortion but to embarrass Israel and share the stolen data from these Israeli entities online. The report mentions the Iranian technology company 'Danesh Novin Sahand,' which serves as a 'cover for the cyber activities' of the Islamic Republic and has reportedly exploited vulnerabilities in cybersecurity products like Check Point or Palo Alto VPN equipment. The Iranian government's 'Storm 2035' initiative aims to interfere in U.S. elections. Iranian-backed hackers created a user account named 'John McCain,' the late prominent U.S. senator, after entering the victim's network and before expanding their infiltration and data theft operations. Hackers disable antivirus programs or security software on the victim's computer to operate unnoticed within the targeted network, pursue their objectives, steal information, and monitor the activities of their prey. U.S. cyber experts believe that hackers typically conceal their affiliation with the Islamic Republic and deliberately leave the origins of their actions ambiguous. The three U.S. intelligence agencies wrote in their recommendations that merely addressing vulnerabilities in the software used on victims' computers is not sufficient for adequate protection; organizations must take additional measures to safeguard themselves from these traps and report any ransomware attacks or cyber incidents. U.S. agencies have pointed out four specific vulnerabilities in the software used on computers that need to be addressed. The report from the three agencies comes amid renewed attention from U.S. intelligence organizations to Iran's cyber activities aimed at influencing the upcoming presidential election in the U.S. According to CNN, Iran's actions are part of a multi-year campaign by the Islamic Republic targeting both Donald Trump and Joe Biden and their close associates. Microsoft also reported on Wednesday that hackers linked to the Revolutionary Guard have installed malware on computers in the satellite, oil, gas, and communications sectors in the U.S. and the UAE. The Islamic Republic of Iran, seeking to enhance its intelligence capabilities, is increasingly utilizing cyber hacking and recently artificial intelligence. This week, the Supreme Leader of the Islamic Republic of Iran, in his first meeting with the government of Masoud Pezeshkian, urged the fourteenth government to continue the actions of Ebrahim Raisi's administration regarding artificial intelligence so that, according to him, Iran does not 'fall behind' in this field and that this technology does not 'soon fall under the supervision of a global artificial intelligence agency, like nuclear energy.'

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →