Wars don’t stay on the battlefield anymore. Since military operations between Israel, the United States, and Iran kicked off on February 28, 2026, the internet has become a second front and the numbers tell a stark story.
A leading content delivery network provider tracked a 245% rise in malicious traffic within weeks of the conflict starting. That’s not a gradual climb. That’s a spike. And for IT and security teams managing infrastructure across virtually every sector, it’s a signal that demands attention right now.
The Numbers Behind the Surge
The breakdown is telling. Automated reconnaissance traffic rose 65%. Botnet-discovery activity jumped 70%. Infrastructure scanning climbed 52%. Credential-harvesting attempts were up 35%, and denial-of-service reconnaissance grew 38%.
Each of those numbers represents a different attack vector. Together, they paint a picture of coordinated, multi-layered pressure being applied across the global internet simultaneously.
Put simply: threat actors aren’t just attacking. They’re mapping. They’re probing. They’re preparing. And they’re doing it at a scale and speed that suggests this isn’t opportunistic – it’s organized.
For security teams, the instinct is often to focus on active incidents. But what these numbers reflect is largely pre-attack activity. The reconnaissance phase. The stage where adversaries quietly identify which doors are unlocked before they decide which ones to walk through.
That context matters – because it means there’s still a window. The organizations that act during this phase have a better chance of closing vulnerabilities before they become breach pathways.
Who’s Behind It – And Why the Answer Is Complicated
You might expect Iran to top the source list. It doesn’t.
Russia accounts for 35% of the malicious traffic. China accounts for 28%. Iran-attributed IPs represent only a small slice of the total – and there’s a straightforward reason for that.
Since the conflict began, Iran has shut down roughly 99.5% of its domestic internet infrastructure. Security analysts largely view this as a deliberate move to control information flow, not a consequence of infrastructure damage. Israel’s early cyber operations reportedly collapsed Iran’s internet connectivity to between 1% and 4% of normal levels by targeting routing and DNS systems.
But Iran going dark doesn’t mean Iran going quiet. Proxy networks, compromised IoT devices, and foreign botnets give threat actors plenty of ways to keep operating without exposing their true origin. Attackers routinely route malicious traffic through inadequately secured infrastructure in third-party countries – making geographic attribution a partial picture at best.
Iran’s core backbone connectivity is reportedly still intact, meaning the capability to scale up exists whenever the decision is made to use it. Analysts describe Iran’s cyber posture as degraded but operational – supported by pre-positioned access in foreign networks and a web of proxy actors and front companies that continue to function regardless of domestic internet conditions.
The practical implication for defenders: don’t anchor your threat model to Iranian IP ranges. The infrastructure behind these attacks is deliberately distributed and deliberately obscured.
70+ Hacktivist Groups, One Coordination Hub
Here’s where the story gets structurally important for security teams.
Within hours of the February 28 strikes, a coordination hub known as the Electronic Operations Room activated. Its role: synchronize Iran-backed hacktivist operations across more than 70 disparate groups – including international collectives and pro-Russian actors like NoName057(16).
These groups didn’t just react independently. They pivoted together, targeting nations seen as aligned with the U.S. or Israel. Groups including Server Killers, the 313 team, and Keymous+ publicly claimed increased activity in the period that followed.
What analysts are flagging isn’t just the volume of attacks. It’s the coordination. Independent hacktivist groups operating with nation-state-level synchronization is a different kind of threat than the industry has historically planned for.
Traditionally, hacktivism has been characterized by loose, reactive, ideologically driven action – chaotic by nature, limited in sophistication. What’s emerging now looks different. More than 70 groups operating through a shared coordination structure, with synchronized targeting and shared operational tempo, starts to look less like a protest movement and more like an extended operational arm of state strategy.
That distinction has real implications for how defenders assess risk. A loosely coordinated hacktivist campaign is manageable. A synchronized multi-group operation with strategic targeting guidance from a state-level actor is a materially different challenge.
Russia and China: Opportunists in the Noise
While security teams worldwide locked their focus on Iran, something else was quietly happening.
State-sponsored groups – Russia’s Sandworm and China’s Volt Typhoon among them – are assessed to be using the current chaos as cover. Their reported activity: pre-positioning inside Western energy grids and telecommunications infrastructure.
Not to strike immediately. To embed. To wait. To maintain long-term leverage.
Both Russia and China host large proxy infrastructures that foreign threat actors actively use, in part because neither government tends to interfere when Western targets are involved. The conflict didn’t give these actors new ambitions. It gave them a distraction they could work behind.
Security professionals describe it plainly: the conflict created the opportunity, not the intent.
This is the “never let a good crisis go to waste” dynamic playing out in real time. Every major geopolitical disruption draws security operations center resources toward the most visible threat. That visible threat – in this case, Iranian-linked hacktivism and DDoS campaigns – becomes the focal point. And in the margins of that focal point, more patient, more sophisticated actors move quietly into position.
The concern isn’t necessarily an imminent strike from Sandworm or Volt Typhoon. It’s that by the time defensive teams re-focus their attention, the access will already be established. The footholds will already exist inside power grids, water treatment systems, and telecommunications backbones. And removing deeply embedded actors from critical infrastructure is significantly harder than preventing them from getting in.
Noisy Attacks Are Often a Smokescreen
One attack that drew significant attention was a wiper attack on medical-technology company Stryker, attributed to a group called Handala. High-profile. Disruptive. Widely covered across the security industry and mainstream press.
Analysts suggest that’s partly the point.
Loud, visible attacks pull focus. They generate incident response activity, media coverage, executive attention, and regulatory scrutiny. While all of that is happening, quieter actors move deeper into critical infrastructure – living off the land, using legitimate system tools, leaving minimal forensic traces, and establishing persistence that can remain undetected for months.
The Stryker attack made headlines. The pre-positioning happening in parallel, inside less prominent but equally critical systems, largely did not. That asymmetry between what gets attention and what actually represents strategic risk is something security leaders need to actively account for right now.
Visibility bias is a real problem in threat response. The attack you’re reading about in the news is rarely the attack that should be consuming the most defensive resources.
The Real Risk: Reconnaissance That Becomes Action
The 245% figure captures a lot of scanning and probing activity. That’s actually the more important signal.
Botnet discovery up 70%. Automated recon up 65%. These aren’t attacks in the traditional sense. They’re the phase that comes before attacks – target profiling, vulnerability mapping, access validation, and attack surface documentation.
Think of it as the planning stage of a physical operation. Adversaries are currently walking the perimeter, testing the fences, identifying blind spots in camera coverage. The breach hasn’t happened yet. But the groundwork is being laid methodically, at scale, across thousands of targets simultaneously.
Security professionals are drawing a clear line: organizations that treat this period as a warning have time to prepare. Patch exposed services. Review access controls. Stress-test incident response plans. Validate logging and detection coverage across edge devices and network boundaries.
Those that treat the current environment as background noise – another threat cycle that won’t affect them directly – may find themselves significantly underprepared when the reconnaissance phase ends and the action phase begins. History suggests that window closes faster than most organizations expect.
The Boundary Between State and Hacktivist Is Gone
The clearest structural takeaway for IT and security teams is this: the traditional threat model is outdated.
The line between state-sponsored cyber operations and independent hacktivist activity has effectively dissolved. What was once a relatively clean distinction – sophisticated, well-resourced nation-state actors on one side, ideologically motivated but technically limited hacktivists on the other – no longer holds.
More than 70 groups operating in coordinated fashion through a shared hub, with synchronized targeting and strategic guidance, represents a hybrid threat category that existing frameworks weren’t designed to address. It’s not purely state. It’s not purely grassroots. It’s something in between, and it combines the scale of the latter with the strategic direction of the former.
That changes the threat model. It changes the scale of what defenders need to anticipate. And it changes what organizational readiness actually looks like in practice.
What Security Teams Should Be Doing Right Now
The experts are aligned on the direction, even if the specifics vary by organization and sector.
Expand detection coverage beyond known Iranian threat indicators. With the majority of malicious traffic routing through Russian and Chinese IP spaces, narrow geographic attribution will miss most of what’s actually happening. Focus on behavior – unusual scanning patterns, lateral movement, anomalous authentication attempts – rather than origin-based blocking alone.
Treat the reconnaissance spike as an active alert, not a background condition. The current environment is the warning phase. Organizations that use it to identify and close exposure are in a fundamentally different position than those that wait for an incident to force action.
Revisit assumptions about critical infrastructure isolation. Sandworm and Volt Typhoon’s reported pre-positioning activity targets the systems that organizations often consider most protected. Edge devices, operational technology environments, and telecommunications links deserve specific attention right now.
And perhaps most importantly: escalate the conversation internally. Cybersecurity at this moment isn’t just a technical discipline or an IT department concern. For organizations running critical digital infrastructure, analysts across the industry are now describing it in starker terms.
Not a support function. Not a compliance requirement. A survival function.
The conflict started on February 28. The cyber dimension of it is still accelerating. And the organizations best positioned to weather it are the ones treating that reality seriously – today, not after the next headline.