Also available in Persian — نسخه فارسی EN فا
🔴 Breaking ❓ Unknown

What are Iran's 'Government Hackers' Doing?

May 13, 2026 May 13, 2026 9 min read 📰 Radio Farda
📋 Key Takeaway

The U.S. has indicted seven Iranian hackers allegedly linked to the Islamic Revolutionary Guard Corps for cyberattacks, including DDoS attacks on American banks and infiltration of a dam control system. This development highlights the ongoing cyber warfare dynamics between Iran and the U.S., raising concerns about the implications for cybersecurity and international relations.

🔍 Quick Context Guide
💡 Bottom Line: The indictment marks a significant step in holding Iranian hackers accountable.

👥 Key Players

Ahmad Fathi ACCUSED
Hacker
"The seven Iranian hackers are accused of disrupting 46 targets."
Hamid Firoozi ACCUSED
Hacker
"A hacker named Hamid Firoozi managed to infiltrate this system using a Google feature."
Colin Anderson QUOTED
Cybersecurity Researcher
"I find it interesting that this issue has now reached the legal arena."
Islamic Revolutionary Guard Corps (سپاه پاسداران انقلاب اسلامی) LINKED_TO
Military Organization
"The hackers are said to be affiliated with the Islamic Revolutionary Guard Corps."
U.S. Government ACTOR
Government of the United States
"Charges were filed against seven Iranian hackers."
Iranian Foreign Ministry (وزارت امور خارجه ایران) ACTOR
Government Body
"The Iranian Foreign Ministry spokesperson stated that the U.S. is not in a position to accuse citizens."

⚡ Actions

U.S. Government INDICT Ahmad Fathi, Hamid Firoozi, Amin Shakouhi, Sadegh Ahmadzadegan, Omid Ghafari Nia, Sina Kaysar, Nader Saeedi
"The seven Iranian hackers are accused of disrupting 46 targets during a period of approximately two years."
Confidence: 90%
Iranian Foreign Ministry ANNOUNCE U.S. Government
"The U.S. is not in a position to accuse citizens of other countries without providing documented evidence."
Confidence: 90%
U.S. Government SEND Interpol
"A notice has also been sent to Interpol."
Confidence: 80%

📰 What Happened

U.S. indicted seven Iranian hackers linked to IRGC for cyberattacks on American financial institutions.

  • U.S. Government indict Ahmad Fathi, Hamid Firoozi, Amin Shakouhi, Sadegh Ahmadzadegan, Omid Ghafari Nia, Sina Kaysar, Nader Saeedi
  • Iranian Foreign Ministry announce U.S. Government
  • U.S. Government send Interpol

💡 Why It Matters

🇮🇷 For Iran: Because it highlights the Iranian government's involvement in cyber operations.
🌍 Regional: Because it escalates tensions between Iran and the U.S.
🌐 International: Because it raises concerns about cybersecurity and foreign interference.

📚 Background

The indictment marks a significant step in holding Iranian hackers accountable.

📝 Key Evidence

"Charges were filed against seven Iranian hackers."
→ Indictment of hackers linked to IRGC.
"The hackers are said to be affiliated with the Islamic Revolutionary Guard Corps."
→ Connection between hackers and Iranian military.
📡 Source: INDEPENDENT
📊 Confidence: 80%
Radio Farda is known for its critical stance towards the Iranian government.

Last week in the United States, charges were filed against seven Iranian hackers. The hackers, whom the U.S. claims were collaborating with two companies in Iran, namely 'IT Sec' and 'Marsad', are said to be affiliated with the Islamic Revolutionary Guard Corps. In response to this indictment, the Iranian Foreign Ministry spokesperson stated that the U.S. is not in a position to accuse citizens of other countries without providing documented evidence. The majority of the indictment focuses on hacking attacks known in the internet world as 'DDoS'. In such attacks, hackers significantly increase traffic to a website, effectively taking it offline. The seven Iranian hackers are accused of disrupting 46 targets during a period of approximately two years, primarily between Tuesdays and Thursdays, with most targets being American banks or companies related to finance, stocks, and the stock market. Additionally, another accusation against the Iranian hackers involves infiltrating the control system and obtaining information from the Bowman's dam located 35 kilometers from New York City, which occurred about three years ago. The seven Iranians charged by the U.S. are: Ahmad Fathi, Hamid Firoozi, Amin Shakouhi, Sadegh Ahmadzadegan, Omid Ghafari Nia, Sina Kaysar, and Nader Saeedi. In the latest developments, the American newspaper Wall Street Journal reported that one of these hackers managed to infiltrate this system using a Google feature and did not perform anything extraordinary. We have spoken with Colin Anderson, an American researcher in cybersecurity, regarding the capabilities of Iranian hackers. Mr. Anderson has been researching the activities of government-linked hackers in Iran for several years in Washington. Mr. Anderson, what is your assessment of the significance of the U.S. officials' announcement? The indictment against hackers that the U.S. judicial system and federal police have no access to? In my opinion, this action is, firstly, a step away from the trend where these individuals are always immune. Because if you look at the history of Iranian cyber actions and their hacking, this country has had one of the strongest groups for attacking websites in the past decade. Since late 2009, these actions have become heavily politicized, and attacks on commercial websites were politically motivated, causing significant economic damage. After that, in 2012 and 2013, we witnessed retaliatory actions from these Iranian hackers. I call them retaliatory because during this time, Iran was engaged in a kind of cyber war with the U.S. and Israel. During this period, we see irregular attacks, and the attacks from the opposing side have led to more attacks. I find it interesting that this issue has now reached the legal arena and it has been stated that the perpetrators of the attacks are no longer immune. Alongside the indictment against seven individuals, a notice has also been sent to Interpol, which means that if these individuals leave Iran and are in a country that has an extradition agreement with the U.S., they will be handed over to that country. You surely remember that one of the individuals included in the recent prisoner exchange between Iran and the U.S. was a person named Nima Golestaneh, who was handed over to the U.S. in Turkey due to accusations of hacking an American company. Therefore, I think the issue is to say that we know you and your actions will have consequences. In this regard, Mr. Anderson, before this conversation, I conducted a preliminary search on Persian websites and came across the names of individuals, and perhaps about three years ago, some Iranian sources had exposed their activities. Why is the U.S. judicial system making this public now, after several years since their actions? I believe we are in a time when the issue of threats to U.S. infrastructure by foreign hackers has become much more politicized. There are many discussions about how to deal with Chinese hackers or North Korean hackers. Especially after the revelation of Iranian hackers infiltrating a dam in New York, this has become one of the main topics in the context of Iran-U.S. policies. Therefore, I think the disclosure of these individuals' identities is somewhat intertwined with the broader policies regarding Iran. You mentioned the hacking of the Bowman dam control system. The Wall Street Journal in its recent report states that a hacker named Hamid Firoozi managed to infiltrate this system using a Google feature and did not perform anything extraordinary. What is your opinion on this? When we look at Iran's technical capabilities in attacking foreign services and disrupting them, most of these attacks do not have specific complexity. 'Google Dorking' essentially means using Google to find websites with vulnerabilities that can be exploited. This is not technically complex at all, and I would even say it is a kind of laziness. However, the serious damage is different from technical complexity. This means using the search engine to find websites that have weaknesses that can be exploited. This is not a technically complex task, and even I would say it is a kind of laziness. But the attacks on the banking sector were different and caused significant losses. The perpetrators of these attacks found several computers with which they attacked the traffic of these companies to the point where these websites went offline. This may seem complex, but it is not. These individuals exploited obvious weaknesses in websites and used tools that are common. Once they accessed the websites, they took control of them, which is also not a very complex task, and directed their traffic to banks and financial institutions. A low-cost attack that is not complex. You say these attacks were not that complex, but you have been monitoring the activities of Iranian hackers connected to power for several years. What is the overall technical capability of this group of Iranian hackers, and can they cause serious damage? Serious damage is different from technical complexity. If we look at the case of attacks on financial institutions, that case caused serious damage. Millions of dollars were lost due to the inaccessibility of these websites. In 2012, when the website of Saudi Aramco was attacked, and the computers in the sales department went down, hundreds of millions of dollars were lost due to the halt of this section's activities. You can cause significant damage without having high technical capability, especially when your victim is unprepared to counter it. In the case of this Saudi company, for example, hackers were able to access the entire system by hacking one person's computer. The same thing happened with an American millionaire named Sheldon Adelson, who had spoken about a nuclear attack on Qom in Iran. His companies' websites were attacked in this way, where one of the network administrators who had the ability to make changes to several websites was hacked, and from that point, the way to infiltrate the other websites and steal information from them was opened. Complex technical attacks are a different world. For example, one must identify the vulnerabilities of a software and exploit those vulnerabilities to infiltrate a system and target more advanced objectives such as government centers. And Iranians have not performed well in this area and have not attacked systems that are more prepared. For example, unlike government hackers in China and Russia, who have attacked places like the U.S. State Department, Iranians have not been active. Is it clear what the reason for this is? I mean, it is possible that they have the capability but have not used it? I think it is not possible that they have the knowledge and have not used it. I believe Iran has one of the best technical universities in the world. The academic quality of those who graduate from these universities is unparalleled. I think many of these individuals leave the country. And from this perspective, brain drain does not help this process. Also, the environment has not necessitated them to carry out such attacks. If Iranian hackers can attack the Aramco system using a relative capability, for example, they do not need to use more technical complexities. Therefore, it has been sufficient for them. Of course, achieving advanced technologies in the field of cyber warfare is not easy, costly, and time-consuming and requires management. And it is still unclear to me whether, for example, the Iranian government wants to make a heavy investment in the domestic cybersecurity industry to compete with international industries. When you talk about the Iranian government, I wanted to address this issue specifically, as we have multiple power structures in Iran. Do you have any conclusions about which of these power structures is more active in cybersecurity and hacking? Based on some public sources, the FBI indictment, and some other actions, it seems that most of the Iranian activities in the field of cyber warfare are carried out under the orders of the security intelligence section of the Islamic Revolutionary Guard Corps. What we see in the activities of Iranian hackers is that they do not only target foreign objectives but also domestic targets become prey to these attacks. For example, we have had multiple reports about individuals who, after being arrested, realized that the security apparatus had access to all their online information. I think you pointed out a more important issue. What Iranian hackers are specifically skilled at is a phenomenon called 'social engineering'. They use trust-building to target individuals' personal weaknesses to gain access to people's emails. And those who are accused of attempting to hack Western defense websites are the same ones who try to access the personal information of the Iranian government's opponents. There is a direct connection between these two, and there is abundant technical evidence to prove this. What these hackers usually do is identity theft or impersonating the opposite gender. Individuals in these situations lower their defensive guard more easily, and their systems become easier targets. And Iranian attackers perform well in this area and have a special expertise in this regard.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →