Iran conflict spikes gulf cyberattacks as phishing rises 130%
A months-long cyber war between the US and Iran has taken a devastating toll on regional economies, but a lesser-known consequence is the surge in malware and phishing attacks targeting Gulf states. According to a new report from Bitdefender, malicious activity in the region has jumped a staggering 130% since the conflict escalated.

Gulf region in crosshairs as cyber delinquents seize opportunity
Analyst Alina Bizga, in an exclusive interview with Business Insider, explained that geopolitical turmoil provides hackers with a prime opportunity to launch their campaigns. 'Events of rapid change are a chance for cyber criminals to make their real-time operations more effective,' she noted. 'They don't necessarily tie to the events directly, but exploit moments when usual processes are under pressure.'
Bitdefender's research found that the attacks, which initially rose 130% after the conflict began, have since intensified to levels four times higher than the pre-conflict norm. The campaigns use various corporate scenarios to maximize their chances of success, often mimicking legitimate business communications.
A recent high-profile example is a crippling attack on US-based Stryker, attributed to the Iranian group Handala. But these cyber criminals don't just rely on links to click from suspicious websites. They also employ tactics like fake invoices, contracts, bank notifications, and delivery confirmations via emails. This 'Trojan horse' approach, as Bitdefender describes it, leaves no trace but uses system tools to remain undetected.
While the report stops short of naming a specific actor, the sophistication of the tactics has sparked debate over whether organized groups or even states are exploiting the chaos as cover. Bizga countered that, while the tools may be advanced, they're 'widely available and commonly used in cybercrime ecosystems.' Additionally, she noted that the presence of such tools doesn't necessarily indicate state involvement.
The Gulf region, with its high concentration of energy, finance, and international trade, naturally generates a large volume of corporate communications. As Bizga pointed out, 'this region is a high-value environment.' The phishing attacks, therefore, are not limited to the Gulf alone but are observed globally, with a notable increase in activity directed at Gulf states.
Bizga emphasized that the phishing is merely the initial step, with the ultimate goal of establishing a foothold - whether through compromised credentials, infected systems, or unauthorized access to business tools. Once in place, attackers maximize and monetize the impact.
To avoid falling prey to these attacks, Bizga advised several key precautions, including vigilance around unexpected files, avoiding compressed archives, and verifying urgent messages and financial requests. Staying up to date with security software and working with reputable providers are also crucial.
