After Khamenei: Iranian Cyber Escalation in the Gulf and the Shock Waves on Europe and Italy
The sequence is now established. On February 28, 2026 the United States and Israel conducted a joint operation against Iranian territory culminating in the killing of Supreme Leader Ali Khamenei, announced by Iranian state media on March 1. On April 6, IRGC intelligence chief Majid Khademi was also killed in a further joint US-Israeli strike. In between, Tehran responded with missiles and drones against Israel, US bases and regional allies, attempted to close the Strait of Hormuz, and suffered an adversarial cyber operation that pushed Iran into an internet blackout lasting over 60 hours, with connectivity dropping to 1% of normal levels.
The ceasefire that followed has been described by every observer as fragile. For AEGIDA, the relevant data point is not political but operational: in the six weeks between March 1 and April 13, 2026, the intensity, complexity and target base of cyber operations attributed to Tehran and its proxies have increased measurably — and the geographic trajectory does not stop at the Gulf.
The Gulf: From Disruption to Complex Intrusion
The sharpest data point comes from the UAE Cybersecurity Authority, which on April 10 quantified 600,000 attacks recorded on federal territory in the latest measurement cycle — triple the prior period. More significant than volume is the mix: the attacker portfolio now includes ransomware, data breach with extortion, targeted document leaks, destructive wipers and defacements. This is no longer the old generation of symbolic DDoS or propaganda-driven defacements: it is an articulated offensive posture with defined KPIs and persistent intrusion capability.
The qualitative leap concerns the attack surface. Campaigns historically focused on public portals and government sites have extended to three high-value target classes: banking institutions, civil aviation control systems, and police digital platforms. The observed pattern in each class is breach with data exfiltration and threat of publication — a monetization that hybridizes state logic (political signal) and criminal logic (economic leverage), making it difficult to separate pure state-sponsored groups from aligned but financially autonomous hacktivist collectives.
Key figure: 600,000 cyberattacks recorded by the UAE in the latest cycle — triple the prior period. Portfolio: ransomware, breach with extortion, targeted leaks, destructive wipers, defacements. Expanding targets: banks, civil aviation, law enforcement.
United States: The PLC Campaign Against Water, Energy and Government
On April 7 CISA, FBI and partners issued the joint advisory AA26-097A documenting a sustained campaign by Iran-affiliated actors against internet-exposed Programmable Logic Controllers in US water, wastewater, energy and government services sectors. Identified targets include Rockwell Automation/Allen-Bradley PLCs, with manipulation of project files and alteration of data shown on HMI and SCADA systems. Some victims have experienced operational disruption and economic loss. CyberAv3ngers, linked to the IRGC, is among the principal attributed actors.
The strategic reading, echoed in a CSIS analysis published April 11, is that the Iranian approach to the cyber domain is no longer episodic or symbolic: it has become a sustained strategic posture treating cyberspace as an extension of state power, with critical infrastructure as the backbone of coercive politics. This is a paradigm shift: before February-March, Iranian operations were largely opportunistic and noisy; today they are planned, silent where needed, and oriented to preserving mid-term access.
Why Europe — and Italy — Are in Range
The case for Europe being in range is not speculative: it is the direct read of the historical track record of Iranian groups. APT34 (OilRig), APT35 (Charming Kitten) and MuddyWater have operated repeatedly against European targets in the 2019-2020 and 2024 tension cycles, with documented campaigns against energy, defense, telco, academia and government in Italy, Germany, France, the UK and the Netherlands. The Italian footprint is documented particularly in energy (gas operators, electric utilities, refining) and defense industry (military platform suppliers and their subcontracting chain).
After Khamenei, retaliation rhetoric targets the US and Israel publicly, but operational practice will hit those perceived as allies too: states hosting US bases, those supplying weapons to Israel, those participating in NATO missions in the Eastern Mediterranean. Italy is in all three categories. Aviano Air Base, Italian naval presence in the Red Sea within Operation Aspides, logistical support for US rotations in the Middle East — each of these is enough, in the Iranian targeting grid, to justify the inclusion of Italian entities in spear-phishing, credential stuffing and deep intrusion campaigns.
The state dimension is compounded by aligned hacktivism. Groups like Handala (already featured in the Stryker-Intune case AEGIDA documented on April 9), Cyber Toufan, and a constellation of Telegram collectives regularly claim operations against European companies accused of links with Israel. The selection criterion is often crude — a mention in a public list, a contract reported by a newspaper, a sponsorship — but the reputational and operational impact is real.
The Post-Ceasefire Model: Why Truce Does Not Reduce Risk
The public promise by Iran-aligned collectives to continue operations despite the ceasefire is not rhetoric: it reflects a structural dynamic. First, many of these groups are not hierarchically subordinated to the Iranian political command, but operate in a gray zone of tolerance and partial funding that survives independently of diplomatic talks. Second, the ceasefire reduces pressure on Iran's domestic infrastructure — the internet blackout has ended — and frees operational resources that in open war were absorbed by defense. Third, the kinetic pause shifts the conflict's center of gravity to the cyber domain, which is by definition below the threshold of conventional war and therefore politically useful as a tool of continuous pressure.
For defenders, this means the post-ceasefire window is not a breathing window but one of maximum relative intensity: the noisy operations of March give way to silent operations of April-May, with enumeration, credential harvesting and persistent positioning for future escalations. Detection becomes harder precisely as perceived risk drops.
Post-Khamenei geographic picture: (1) Gulf — complex intrusion on banks, aviation, law enforcement; (2) US — PLC campaign on water, energy, government (CISA AA26-097A); (3) Europe/Italy — high risk of spear-phishing and intrusion on energy, defense, central PA and NATO allies. The ceasefire shifts activity from noise to silence; it does not reduce it.
Operational Indicators to Monitor Now
- Password spraying against Microsoft 365 and Google Workspace tenants of Italian entities in energy, defense, PA, healthcare and telco, with sources on European and Asian residential IPs (pattern already observed in the April 7 campaign).
- Exploitation attempts against Rockwell Automation, Schneider, Siemens PLCs exposed on the Internet — including mid-sized Italian water operators and utilities, historically under-defended vs. majors.
- Spear-phishing on defense supply chain employees with geopolitical-themed lures (fake NATO briefings, conference invitations, "classified" documents on Israel-Iran).
- Handala-like campaigns leveraging supply chain vectors (MDM, endpoint management, patching tools) — the Stryker-Intune case is the template.
- Defacement and leaks against Italian SMEs with known or alleged contracts with Israel — reputational and legal damage often exceeds technical damage.
- Anomalous traffic toward .ir TLDs, but especially toward command and control infrastructure hosted on low-cost European providers (Bulgaria, Romania, Netherlands) frequently used by Iranian clusters.
Recommendations for Italian Enterprises and Public Administration
- 1.Immediate review of exposed surface: every internet-reachable service must have an owner, a documented patch cadence, and an anomaly alert. Prioritize VPNs, firewalls, MDM platforms, OT/SCADA systems and mail portals.
- 2.Aggressive rollout of phishing-resistant MFA (FIDO2/passkey) on accounts with access to critical systems. Iranian password spraying has proven effective wherever MFA was based only on SMS OTP or apps without cryptographic binding.
- 3.Rigorous OT/IT segmentation for water, energy, transport and healthcare operators — with bastion hosts, authenticated jump servers, and monitoring of flows toward PLCs and HMIs. No PLC should be directly reachable from the Internet.
- 4.Proactive threat hunting focused on documented Iranian TTPs: use of legitimate tools (PsExec, WMI, PowerShell), persistence via scheduled tasks and services, C2 over HTTPS with Let's Encrypt certificates on European VPS.
- 5.Incident response drills with specific scenarios: breach with exfiltration + public leak, destructive wiper on domain servers, compromise of an MDM or patching provider.
- 6.Review of contracts with defense and energy suppliers to include contractual notification obligations compatible with NIS2 and with real operational timelines (24-72 hours, not weeks).
- 7.Monitoring of public mentions of the company in contexts linked to Israel or military supplies — being cited in a hacktivist list is often the first weak signal before an attack.
- 8.Coordination with ACN and CSIRT Italia: sharing IoCs and anomalous telemetry is today a defense multiplier, not a reputational cost.
Conclusion: Iran's Doctrine Has Changed, Italy's Defense Must Update
Khamenei's death has accelerated a transformation already in motion: Iranian cyber has left its adolescent phase — noisy, demonstrative, politically useful only as a signal — and entered a mature phase, where preserving access, mixed monetization (state and criminal), and target selection along a sophisticated geopolitical grid become the norm. For Italy, this means ceasing to think of Iran as a second-tier actor compared to Russia and China: in terms of volume, speed and aggressiveness against European targets, Tehran is today in the same league as Moscow.
The ceasefire does not reduce risk: it shifts it from the domain of noise to that of silence. And silence, in cybersecurity, is always the more dangerous condition. The next six to eight weeks will be decisive in revealing which Italian organizations were prepared for the new paradigm and which will wake up too late.
Primary sources: Wikipedia — 2026 Iran war and Assassination of Ali Khamenei; CISA Advisory AA26-097A (April 7, 2026) — Iranian-Affiliated Cyber Actors Exploit PLCs; CSIS — Iran shift from episodic to sustained cyberattacks (April 11, 2026); The National — Iranian cyber attacks move from disruptive to complex threats in Gulf (April 10, 2026); CNN Politics — Iran-linked hackers disrupt multiple US industrial sites (April 7, 2026); Nextgov/FCW — Pro-Iran hackers targeting US ICS (April 2026); Trellix Research — The Iranian Cyber Capability 2026.