ConflictClarifier

متتبع أزمة إيران-الخليج 2026
CC
Events Archive
strikeApr 30, 2026

The 3 Cyber Threats Changing Security Careers

Summary

When it comes to the cyber threats that keep CISOs and cybersecurity professionals awake at night, business email compromise scams, threats against critical infrastructure and the increasing use of artificial intelligence tools by cybercriminals rank in the top tier. While concerns about AI tools used for malicious purposes have made numerous recent headlines, business email compromise (BEC) scams continue to rack up billions in losses for enterprises large and small. At the same time, threats against U.S. critical infrastructure have remained problematic for years, but the recent war with Iran has led U.S. government agencies to issue fresh alerts in the past two months as international tensions have increased. AI, BEC and critical infrastructure vulnerabilities are among the most prominent cyber threats detailed in the FBI’s 2025 Internet Crime Report, published by the bureau’s Internet Crime Complaint Center (IC3) in early April. Overall, agents received well over 1 million complaints from U.S. victims in the last year, with losses from various schemes, scams and threats totaling $20.9 billion – a 26 percent year-over-year increase. And while the FBI can tout some successes, such as the impact the IC3 Recovery Asset Team has had in recovering stolen funds from consumers and businesses, the report details how cyber threats affect everyday people, businesses of all sizes, government agencies and especially the cyber professionals tasked with protecting networks and IT infrastructure. “It has never been more important to be diligent with your cybersecurity, social media footprint, and electronic interactions. Cyber threats and cyber-enabled crime will continue to evolve as the world embraces emerging technologies such as artificial intelligence,” according to the FBI report’s foreword. While these three are not the only threats that organizations face, cybersecurity experts note that each is making the jobs of CISOs and their security teams more difficult, especially as AI helps enhance scams like phishing emails used in BEC ploys. At the same time, critical infrastructure, including industrial networks that use older operational technology (OT) and industrial control systems (ICS), remains vulnerable, especially to nation-state groups. While AI threats, BEC and critical infrastructure vulnerabilities have evolved over the last year, the FBI points to where defenses are falling short and what cybersecurity professionals need to understand about how these and other threats are changing their jobs. AI-Enabled Threats The FBI IC3 report states what has become obvious over the last year – as AI technologies have become cheaper and more available, cybercriminals and threat actors have adopted these tools themselves. In 2025, agents received more than 22,000 complaints reporting AI-related cyber incidents, with adjusted losses exceeding $893 million. Cybercriminals are using these tools in the same way office workers use AI, including writing better, more convincing emails and helping with coding and administrative support to increase the speed of attacks. The increased efficiency means the number of threats organizations face can become overwhelming, said Vincenzo Iozzo, CEO and co-founder at security firm SlashID. “Threat actors have integrated AI across multiple dimensions of their operations. In terms of speed, AI is being used to decrease breakout time, the interval between initial compromise and lateral movement,” Iozzo told Dice. “On the scale axis, AI has dramatically amplified social engineering campaigns. Phishing emails that once required manual customization can now be generated at volume with convincing, context-aware language and a much better conversion rate.” As other versions of AI are also released, such as agentic AI tools that let agents make decisions for themselves, defenders and cyber professionals will face more sophisticated threats. “Agentic AI is being used by threat actors as an autonomous partner that can independently plan multi-step operations, manage the drudge work of infrastructure provisioning, and dynamically adapt its tactics in real time when it encounters defensive blocks,” Ram Varadarajan, CEO at security firm Acalvio, told Dice. “Agentic AI is being used for machine-speed swarm attacks. Legacy defenses are built for human attackers, and are now unable to fight back in either speed or scale against the agentic attacker.” For these reasons, organizations are turning to AI to improve the speed and efficiency of their cybersecurity processes. Iozzo noted that these tools can help with threat prioritization and alert fatigue. AI can enable security teams to process and triage alerts with significantly richer contextual information than previous rule-based or threshold-based tools provided. This extends across the full defensive stack, including security operations center (SOC) alert processing and correlation, custom detection engineering, vulnerability scanning and prioritized remediation, and threat intelligence enrichment. “Rather than treating every alert as equally urgent, AI allows teams to focus human attention on the threats that matter most, informed by behavioral baselines and environmental context,” Iozzo added. Varadarajan added that future cybersecurity is likely to turn away from bot-to-human and into bot-to-bot defense. “AI can be used to strengthen defenses by orchestrating game-theoretic deception -- deploying adaptive honeypots and ‘radiant’ honeytokens that exploit a model's pattern-matching logic to misdirect and neutralize the attacker without human intervention,”. BEC Rakes In Billions BEC schemes have been around for a decade, but they increasingly enable cybercriminals to steal billions each year. In 2025, the FBI recorded nearly 25,000 complaints, and the losses totaled more than $3 billion, surpassing losses from data breaches and ransomware. Traditionally, BEC schemes start with cybercriminals stealing a top executive's credentials through phishing, social media scams, or deepfakes. Then they impersonate that executive, sending urgent messages to lower-level employees to transfer or wire money to bank accounts. In other cases, the attackers spoof a company's business partner. As with other frauds and scams, AI has helped improve phishing emails that target vulnerable organizations and their leadership. “The ability for attackers to use generative AI to produce deepfake audio, imagery, and video is a rising concern, as attackers are increasingly using deepfakes to start sophisticated social engineering attacks,” Nicole Carignan, senior vice president for security and AI strategy and field CISO at Darktrace, told Dice. “While the use of AI for deepfake generation is real, the risk of image and media manipulation is not new. The challenge now is that AI can be used to reduce the skill barrier to entry and speed up production to a higher quality.” In many ways, security training within organizations has not kept pace with the level of BEC incidents, especially as the threats have become more sophisticated. Mika Aalto, co-founder and CEO at Hoxhunt, believes that cybersecurity professionals have to help organizations change and manage human, or employee, behavior rather than providing workers with information about scams that might target them. “Social engineering remains the easiest way into organizations. Security teams need to invest as much in preparing people as they do in technology. The most effective defense is training employees on the exact types of attacks they are likely to face, turning real-world phishing attempts into learning moments that build lasting cyber resilience,” Aalto told Dice. “Organizations need to move beyond traditional third-party risk management and adopt human risk management — hardening the human layer with the skills and reporting mechanisms that turn employees into threat sensors and feed human threat intelligence directly into detection and response.” Critical Infrastructure Remains Vulnerable The U.S. Department of Homeland Security recognizes 16 sectors as critical infrastructure, including the health care sector, transportation, financial services, water and wastewater treatment facilities. The FBI’s numbers show that the majority of complaints in 2025 related to these sectors included ransomware attacks and data breaches. In the health care sector, for example, agents reported 460 ransomware incidents and another 182 related to data breaches. A major concern remains who can access legacy systems, including OT and ICS technologies, within these sectors. Organizations need to consider how to securely manage privileged access to their critical environments. This includes ensuring employees, vendors, and third parties have the access and permissions needed to do their jobs without additional risk exposure, said James Maude, Field CTO at BeyondTrust. “The C-Suite, CISOs, and CSOs need to look beyond siloed views of obviously privileged identities in individual systems and take a holistic view of the combinations of privileges, entitlements and roles that could be exploited by an attacker to elevate privilege, move laterally and inflict damage,” Maude told Dice. “The identity security debt accumulated by many organizations represents a far greater risk than any other area, as it only takes the attacker to log in using the right identity and all is lost because of the paths to privilege that abound in their environment.”

Actors involved

Iran

Sources

  • Dice StaffBy Dice Staff

    When it comes to the cyber threats that keep CISOs and cybersecurity professionals awake at night, business email compromise scams, threats against critical infrastructure and the increasing use of artificial intelligence tools by cybercriminals rank in the top tier. While concer

See this event through different lenses

Compare how Western, Iranian, Israeli, Global South, and Pro-Peace perspectives frame this event.

Compare Perspectives

Community Notes

Community Notes

Loading notes...

Related events

strikeUnverifiedUSIsraelIran
1 source

US and Iran trade strikes as tensions escalate amid renewed conflict - US Central Command has struck three Iranian oil tankers, including one near the Kharg Island export hub, after Iran's Islamic Revolutionary Guard Corps fired ballistic missiles at two US Navy vessels.

- Admiral Brad Cooper declared that the US would exact a higher economic cost for attacks on its ships, confirming that no American personnel were harmed during the strike. - Iran's Revolutionary Guard retaliated by threatening further attacks on US military ships, claiming to have targeted three US-linked vessels and three tankers navigating unauthorised routes in the Strait of Hormuz.

- The Iranian Red Crescent has requested an International Criminal Court investigation into a suspected US strike on an Iranian wedding that left at least five people dead, accusing Washington of war crimes. - The recent exchanges represent a dangerous deepening of the wider conflict between the US, Israel, and Iran, which has flared repeatedly since initial strikes in February.

Location: Iran
strikeUnverifiedUSIsraelIran
1 source

Iran said its forces attacked a US naval drone trying to enter the Strait of Hormuz, hours after targeting ships in retaliation for American strikes on three oil tankers. The latest round of clashes, which began with US raids last week, comes amid a deadlock in their six-month war.

Iran has maintained its stranglehold on the strategic Strait of Hormuz while Washington continues a counter-blockade of Iranian ports. Washington is also seeking to choke Iran's economy, rolling out sanctions on entities with financial links to the Islamic republic in a bid to force it into submission.

The Islamic Revolutionary Guard Corps, the ideological arm of Iran's military, said today that it "attacked an American military unmanned surface vessel" attempting to enter the strait, according to a statement carried by state television. Hours earlier, the IRGC said its naval forces "targeted three oil tankers on the unauthorised route of the Strait of Hormuz and three vessels affiliated with the child-killing America in other areas".

It warned ships not to attempt to transit by unapproved routes. Yesterday, US Central Command (CENTCOM), which oversees American military operations in the region, said it struck tankers linked to the Iranian Guards, accusing the most powerful arm of the Iranian military of unsuccessfully firing at American warships.

"Following Iran's failed attacks, CENTCOM permanently disabled the IRGC crude oil carriers M/T Downy off the coast of Kharg Island and M/T Stark 1 near Jask," it said. "American forces also completely destroyed the unladen crude oil carrier M/T Kylo ...

in the Gulf of Oman, striking the vessel in multiple critical locations to render it inoperable after the crew was directed to abandon ship," he said. Video posted by CENTCOM showed large fireballs and billowing flames after projectiles slammed into the ships.

The three vessels were "part of a multibillion-dollar shadow network that funds the IRGC and its regional proxies", it said. 'Higher economic cost' The IRGC meanwhile claimed the two American warships they targeted had been "forced to retreat" after "suffering damage", but CENTCOM said those ships successfully evaded Iranian attacks.

CENTCOM commander Admiral Brad Cooper said after the operation: "If you shoot at two of our ships, we will impose an even higher economic cost - taking out three of yours." The Iranian foreign ministry hit out at Washington over the strikes on oil tankers, calling them "illegal and aggressive actions".

A correspondent for Iranian state TV in Jask in the southern province of Hormozgan said one of the tankers was empty and the second was carrying oil. The crews were transported to shore on lifeboats, they said. Another state TV correspondent on Kharg Island said the attack there caused no casualties.

Iran's Khatam-al Anbiya central military command warned that if the US continued its attacks, then Tehran's retaliation against US warships would be "more severe than before, and there is a possibility of their expansion". The administration of US President Donald Trump has tried to downplay the significance of the six-month conflict, which has proven increasingly unpopular at home as midterm elections near.

US Vice President JD Vance went so far as to say that he "wouldn't call it a war". Mr Trump reiterated that view on Friday, calling the war "small potatoes" for Washington. Iran's Security Chief Mohsen Rezaei warned this week that the Islamic republic had adopted a "new strategy" against Washington that "will shatter your foundations".

The US has been trying to step up pressure on Tehran in a bid to wrestle control of the Hormuz strait, through which one-fifth of world oil supplies previously flowed. A fragile ceasefire between the two sides collapsed in July after attacks on commercial ships in the strategic waterway.

Mr Trump has in recent weeks repeatedly threatened to claim sovereignty over the strait, even posting a map showing it as "new US territory". Mr Vance has insisted the US will not reopen talks with Iran until it ends attacks on commercial shipping in Hormuz.

strikeUnverifiedUSIsraelIranUN
1 source

CAIRO (AP) — Iran said Sunday it struck an unmanned U.S. vessel trying to enter the Strait of Hormuz, the latest salvo in a new flare-up of fighting between the two countries. The U.S. did not immediately confirm the purported attack, which came a day after the U.

S. military said forces struck three Iranian oil tankers in response to a missile attack on Navy warships. The war began with U.S. and Israeli attacks on Iran on Feb. 28. But since a ceasefire agreement was announced in June, on-and-off fighting has persisted with both sides trying to inflict military and economic pain as negotiations have collapsed.

Strikes come about a week after fighting resumed The U.S. and Iran resumed attacks last week, following a month of relative calm, with the Strait of Hormuz and Iranian communities along it again being targeted. At least five people were killed earlier in the week during a U.

S. bombardment of southern Iran. The Trump administration appears to have adopted a dual-prong approach to the conflict, responding militarily to attacks on the strait while going after foreign financial institutions that handle Iran’s money.

But Tehran's hard-line new senior leaders have signaled the willingness to dig in after weathering decades of sanctions. Iran has found ways over the years to circumvent sanctions, and now the U.S. blockade, and get its oil to buyers to help ease growing economic pressures.

That relies in part on a shadow fleet transporting its oil. Meanwhile, Iran's nuclear program, the issue that contributed to the outbreak of the war, was meant to be addressed in negotiations that fell apart soon after the U.S. and Iran signed a memorandum of understanding in mid-June.

Diplomats say the U.S., Britain, France and Germany seek to refer Iran to the U.N. Security Council for failure to comply with its nuclear nonproliferation obligations. Instead, Tehran's new leverage focuses on the Strait of Hormuz that is crucial to global oil and natural gas shipments and was seen as an international waterway before the war began.

___ Magdy reported from Cairo and Frankel reported from Jerusalem.

strikeUnverifiedUSIran
1 source

Iran attacks naval drone near Hormuz after US strikes 3 oil tankers The latest round of clashes, which began with US raids last week, comes amid a deadlock in the six-month war Iran said on Sunday that its forces attacked a US naval drone trying to enter the Strait of Hormuz, hours after targeting ships in retaliation for American strikes on three oil tankers.

The latest round of clashes, which began with US raids last week, comes amid a deadlock in their six-month war. Iran has maintained its stranglehold on the strategic Strait of Hormuz while Washington continues a counter-blockade of Iranian ports. Washington is also seeking to choke Iran’s economy, rolling out sanctions on entities with financial links to the Islamic Republic in a bid to force it into submission.

The Islamic Revolutionary Guard Corps, the ideological arm of Iran’s military, said on Sunday it “attacked an American military unmanned surface vessel” attempting to enter the strait, according to a statement carried by state television. Hours earlier, the IRGC said its naval forces “targeted three oil tankers on the unauthorised route of the Strait of Hormuz and three vessels affiliated with the child-killing America in other areas”.

Location: Iran