//

Iran to Step Up Cyberattacks but Experts Warn of Exaggerated Impact

Iran is currently more focused on defending itself from Israeli cyber offensives and prioritises the US and Israel over the UK as targets.

1 min read
[Representational Photo: Getty Images]

Iran is expected to intensify its disruptive cyberattack efforts, but cybersecurity experts caution that Tehran often exaggerates or fabricates the true impact of its operations, according to a detailed analysis reported by Times UK.

The warnings come amid claims by Jonathan Reynolds, the UK’s Secretary of State for Business and Trade, who recently stated that “not a week goes by” without an Iranian cyberattack targeting the UK’s critical national infrastructure. However, cybersecurity specialists and intelligence officials challenge this narrative, saying it is not grounded in reality.

Experts emphasize that Iran’s cyber capabilities lag significantly behind those of Russia, China, and even North Korea. The National Cyber Security Centre (NCSC), part of GCHQ, noted in its latest report that while Iranian threat actors remain “aggressive in cyberspace,” their techniques tend to be less sophisticated. These primarily involve spear-phishing campaigns — a method relying on social engineering to trick individuals into giving up passwords or access credentials.

The NCSC has identified Iran’s Islamic Revolutionary Guard Corps (IRGC) as a key user of spear-phishing to target people with ties or interest in Iranian and Middle Eastern affairs, including government officials, journalists, activists, and think-tank experts.

Times UK reported on an Iranian journalist who was targeted via Telegram by a group masquerading as a women’s refugee organisation attempting to steal his email password. Cybersecurity firm Unit 42 recently uncovered Iranian hackers impersonating a model agency as part of similar espionage tactics.

Jamie MacColl, senior research fellow at the Royal United Services Institute, told Times UK that while Iranian cyberattacks are not as technically advanced as those from other hostile states, their large-scale spear-phishing campaigns can still cause harm. Most Iranian cyber activity in the UK is focused on espionage rather than attempts to disrupt critical infrastructure — though such attacks remain a possible future aim.

MacColl also highlighted a particularly worrying aspect of Iran’s cyber operations: the use of stolen information to target and threaten Iranian dissidents living in the UK and Europe.

Despite these concerns, experts say the immediate cyber threat to the UK from Iran is unlikely to escalate. Iran is currently more focused on defending itself from Israeli cyber offensives and prioritises the US and Israel over the UK as targets.

John Hultquist from Google’s Threat Intelligence Group told Times UK that Iran’s cyberattacks often have mixed success and that Tehran frequently exaggerates their effects to boost psychological impact. He urged caution against overstating Iran’s cyber capabilities, warning that this could unintentionally help Iranian actors by amplifying their influence.

While Iran’s disruptive cyber campaigns may be limited, Hultquist stressed that individual organisations could still face serious consequences and should prepare by adopting strong cybersecurity measures similar to those used against ransomware attacks.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog