ردیاب بحران ایران-خلیج فارس ۲۰۲۶
CC
Events Archive
strikeApr 30, 2026

The 3 Cyber Threats Changing Security Careers

Summary

When it comes to the cyber threats that keep CISOs and cybersecurity professionals awake at night, business email compromise scams, threats against critical infrastructure and the increasing use of artificial intelligence tools by cybercriminals rank in the top tier. While concerns about AI tools used for malicious purposes have made numerous recent headlines, business email compromise (BEC) scams continue to rack up billions in losses for enterprises large and small. At the same time, threats against U.S. critical infrastructure have remained problematic for years, but the recent war with Iran has led U.S. government agencies to issue fresh alerts in the past two months as international tensions have increased. AI, BEC and critical infrastructure vulnerabilities are among the most prominent cyber threats detailed in the FBI’s 2025 Internet Crime Report, published by the bureau’s Internet Crime Complaint Center (IC3) in early April. Overall, agents received well over 1 million complaints from U.S. victims in the last year, with losses from various schemes, scams and threats totaling $20.9 billion – a 26 percent year-over-year increase. And while the FBI can tout some successes, such as the impact the IC3 Recovery Asset Team has had in recovering stolen funds from consumers and businesses, the report details how cyber threats affect everyday people, businesses of all sizes, government agencies and especially the cyber professionals tasked with protecting networks and IT infrastructure. “It has never been more important to be diligent with your cybersecurity, social media footprint, and electronic interactions. Cyber threats and cyber-enabled crime will continue to evolve as the world embraces emerging technologies such as artificial intelligence,” according to the FBI report’s foreword. While these three are not the only threats that organizations face, cybersecurity experts note that each is making the jobs of CISOs and their security teams more difficult, especially as AI helps enhance scams like phishing emails used in BEC ploys. At the same time, critical infrastructure, including industrial networks that use older operational technology (OT) and industrial control systems (ICS), remains vulnerable, especially to nation-state groups. While AI threats, BEC and critical infrastructure vulnerabilities have evolved over the last year, the FBI points to where defenses are falling short and what cybersecurity professionals need to understand about how these and other threats are changing their jobs. AI-Enabled Threats The FBI IC3 report states what has become obvious over the last year – as AI technologies have become cheaper and more available, cybercriminals and threat actors have adopted these tools themselves. In 2025, agents received more than 22,000 complaints reporting AI-related cyber incidents, with adjusted losses exceeding $893 million. Cybercriminals are using these tools in the same way office workers use AI, including writing better, more convincing emails and helping with coding and administrative support to increase the speed of attacks. The increased efficiency means the number of threats organizations face can become overwhelming, said Vincenzo Iozzo, CEO and co-founder at security firm SlashID. “Threat actors have integrated AI across multiple dimensions of their operations. In terms of speed, AI is being used to decrease breakout time, the interval between initial compromise and lateral movement,” Iozzo told Dice. “On the scale axis, AI has dramatically amplified social engineering campaigns. Phishing emails that once required manual customization can now be generated at volume with convincing, context-aware language and a much better conversion rate.” As other versions of AI are also released, such as agentic AI tools that let agents make decisions for themselves, defenders and cyber professionals will face more sophisticated threats. “Agentic AI is being used by threat actors as an autonomous partner that can independently plan multi-step operations, manage the drudge work of infrastructure provisioning, and dynamically adapt its tactics in real time when it encounters defensive blocks,” Ram Varadarajan, CEO at security firm Acalvio, told Dice. “Agentic AI is being used for machine-speed swarm attacks. Legacy defenses are built for human attackers, and are now unable to fight back in either speed or scale against the agentic attacker.” For these reasons, organizations are turning to AI to improve the speed and efficiency of their cybersecurity processes. Iozzo noted that these tools can help with threat prioritization and alert fatigue. AI can enable security teams to process and triage alerts with significantly richer contextual information than previous rule-based or threshold-based tools provided. This extends across the full defensive stack, including security operations center (SOC) alert processing and correlation, custom detection engineering, vulnerability scanning and prioritized remediation, and threat intelligence enrichment. “Rather than treating every alert as equally urgent, AI allows teams to focus human attention on the threats that matter most, informed by behavioral baselines and environmental context,” Iozzo added. Varadarajan added that future cybersecurity is likely to turn away from bot-to-human and into bot-to-bot defense. “AI can be used to strengthen defenses by orchestrating game-theoretic deception -- deploying adaptive honeypots and ‘radiant’ honeytokens that exploit a model's pattern-matching logic to misdirect and neutralize the attacker without human intervention,”. BEC Rakes In Billions BEC schemes have been around for a decade, but they increasingly enable cybercriminals to steal billions each year. In 2025, the FBI recorded nearly 25,000 complaints, and the losses totaled more than $3 billion, surpassing losses from data breaches and ransomware. Traditionally, BEC schemes start with cybercriminals stealing a top executive's credentials through phishing, social media scams, or deepfakes. Then they impersonate that executive, sending urgent messages to lower-level employees to transfer or wire money to bank accounts. In other cases, the attackers spoof a company's business partner. As with other frauds and scams, AI has helped improve phishing emails that target vulnerable organizations and their leadership. “The ability for attackers to use generative AI to produce deepfake audio, imagery, and video is a rising concern, as attackers are increasingly using deepfakes to start sophisticated social engineering attacks,” Nicole Carignan, senior vice president for security and AI strategy and field CISO at Darktrace, told Dice. “While the use of AI for deepfake generation is real, the risk of image and media manipulation is not new. The challenge now is that AI can be used to reduce the skill barrier to entry and speed up production to a higher quality.” In many ways, security training within organizations has not kept pace with the level of BEC incidents, especially as the threats have become more sophisticated. Mika Aalto, co-founder and CEO at Hoxhunt, believes that cybersecurity professionals have to help organizations change and manage human, or employee, behavior rather than providing workers with information about scams that might target them. “Social engineering remains the easiest way into organizations. Security teams need to invest as much in preparing people as they do in technology. The most effective defense is training employees on the exact types of attacks they are likely to face, turning real-world phishing attempts into learning moments that build lasting cyber resilience,” Aalto told Dice. “Organizations need to move beyond traditional third-party risk management and adopt human risk management — hardening the human layer with the skills and reporting mechanisms that turn employees into threat sensors and feed human threat intelligence directly into detection and response.” Critical Infrastructure Remains Vulnerable The U.S. Department of Homeland Security recognizes 16 sectors as critical infrastructure, including the health care sector, transportation, financial services, water and wastewater treatment facilities. The FBI’s numbers show that the majority of complaints in 2025 related to these sectors included ransomware attacks and data breaches. In the health care sector, for example, agents reported 460 ransomware incidents and another 182 related to data breaches. A major concern remains who can access legacy systems, including OT and ICS technologies, within these sectors. Organizations need to consider how to securely manage privileged access to their critical environments. This includes ensuring employees, vendors, and third parties have the access and permissions needed to do their jobs without additional risk exposure, said James Maude, Field CTO at BeyondTrust. “The C-Suite, CISOs, and CSOs need to look beyond siloed views of obviously privileged identities in individual systems and take a holistic view of the combinations of privileges, entitlements and roles that could be exploited by an attacker to elevate privilege, move laterally and inflict damage,” Maude told Dice. “The identity security debt accumulated by many organizations represents a far greater risk than any other area, as it only takes the attacker to log in using the right identity and all is lost because of the paths to privilege that abound in their environment.”

Actors involved

Iran

Sources

  • Dice StaffBy Dice Staff

    When it comes to the cyber threats that keep CISOs and cybersecurity professionals awake at night, business email compromise scams, threats against critical infrastructure and the increasing use of artificial intelligence tools by cybercriminals rank in the top tier. While concer

See this event through different lenses

Compare how Western, Iranian, Israeli, Global South, and Pro-Peace perspectives frame this event.

Compare Perspectives

Community Notes

Community Notes

Loading notes...

Related events

strikeUnverifiedUSIsraelIranProxy
1 source

DUBAI, United Arab Emirates (AP) — Iran attacked a tanker in the Strait of Hormuz early Tuesday, forcing its crew to abandon the ship, while the United States conducted yet another round of airstrikes targeting the Islamic Republic as they struggle over control of the key waterway.

The 10 consecutive nights of U.S. airstrikes haven’t compelled Tehran to loosen its grip on the strait, through which about a fifth of all crude oil and natural gas traded once passed in peacetime. Even as the U.S. and Iran inch closer to all-out war again, Iran’s interior minister traveled to Pakistan, a key mediator in the conflict, for talks.

However, it remains unclear just what new deal could be reached to end the fighting. The interim deal signed last month that was meant to end the fighting has crumbled. Shipping through the Strait of Hormuz has largely stalled. And as fighting intensifies, both sides have targeted civilian infrastructure relied on by millions of people.

“Iran and groups supportive of Iran may target other U.S. interests overseas or at locations associated with the United States and Americans throughout the world,” the U.S. State Department said in a new warning to Americans. The escalation has pushed oil prices higher in recent weeks.

Benchmark Brent crude traded Tuesday above $88 a barrel and regular gasoline in the U.S. climbed to an average of $4 a gallon, keeping pressure on Americans’ wallets ahead of midterm elections this fall. Meanwhile, the U.S. military identified two soldiers who were killed in Jordan in attacks that left a third person missing.

Separately, the military confirmed another death in Iraq on Saturday during the “controlled detonation” of a downed Iranian drone. President Donald Trump took to social media on Monday to warn that “Every time Iran kills an American Soldier they will pay for that killing many times over!

” Trump was planning to attend a ceremony on Tuesday evening at Dover Air Force Base, where at least one service member’s remains were due to arrive. US strikes come as ships attacked The U.S. military’s Central Command said Tuesday it targeted “Iranian military command centers, maritime capabilities, missile and drone launch sites and air defense systems.

” It released more footage of bombings that targeted sites in Iran. “American forces remain postured and prepared to hold Iran accountable for unwarranted aggression toward civilian mariners seeking to freely and openly transit the strait,” the command said.

Iranian state media reported that explosions were heard in Fars, Hormozgan, Ilam, Kerman and Sistan and Baluchistan provinces. However, traffic through the strait has slowed to a crawl during the latest violence. Lloyd's List Intelligence said only three ships transited the strait on Sunday.

The British military’s United Kingdom Maritime Trade Operations center said a tanker came under attack early Tuesday in the strait off Oman, forcing the crew to abandon the vessel. Iran’s paramilitary Revolutionary Guard claimed the attack, as well as two other attacks on ships Monday in the waterway.

The route around Oman has been the one the U.S. military has encouraged ships to travel to avoid Iran’s control. The UKMTO separately reported Tuesday that another previously unknown attack on a ship took place early the previous day. Tehran also hit U.

S.-allied countries throughout the Middle East. Jordan military's said Tuesday that Iran targeted it with five drones and three missiles, all of which were shot down. Bahrain sounded its missile alert sirens Tuesday afternoon as another Iranian barrage targeted the island kingdom, which is home to the U.

S. Navy's 5th Fleet. Nearly 100 US injuries since early July The Pentagon’s chief spokesperson said nearly 100 U.S. service members have been injured since the U.S. restarted strikes on July 7, and 96% of them have returned to duty.

“The vast majority of injuries experienced were minor concussions,” Sean Parnell posted Monday on X in response to a New York Times report that the Pentagon has withheld information about troop injuries from Iranian strikes. He denied that the Pentagon was hiding data about injuries.

However, the Defense Casualty Analysis System, the military’s clearinghouse for reporting deaths and injuries in conflict, has not been updated as of Monday night with the latest attacks. Yemen rebels threaten attacks on other Mideast waterway Yemen’s Houthi rebels announced a maritime embargo against Saudi Arabia on Monday.

The Houthis, who are backed by Iran, said they would block shipping between the Red Sea and the Gulf of Aden by targeting the Bab el-Mandeb, a maritime chokepoint like the Strait of Hormuz, in response to an attack on Sanaa International Airport last week that they blamed on Saudi Arabia.

With the Strait of Hormuz blocked, Saudi Arabia has been relying on a pipeline to the Red Sea to get millions of barrels of oil out to market. The Houthis earlier demonstrated their ability to disrupt shipping there when they targeted ships for months over the Israel-Hamas war in Gaza, with over 100 vessels attacked.

Saudi Arabia’s military said it would keep the waterway open. “All Houthi threats against transiting vessels will be dealt with swiftly and firmly, as such threats are a blatant violation of international law and fall under acts of maritime piracy,” said Maj.

Gen, Turki al-Malki, a Saudi military spokesman. A glimmer of hope for diplomacy Pakistan has intensified diplomatic efforts in recent days to resuscitate the interim deal. Iranian Interior Minister Eskandar Momeni arrived in Islamabad on Monday for two days of talks with Prime Minister Shehbaz Sharif and others.

On Sunday, U.S. Secretary of State Marco Rubio told reporters that the U.S. is still open to negotiating with Iran but that “it has to be real.” “If the door opens to diplomacy — if the guys that want to do something productive for Iran win and take control of that system, or take control of the negotiations — that’ll be a very positive development,” Rubio said.

“That’s not where we are tonight, unfortunately.” Iranian authorities on Sunday said at least 50 people have been killed and 517 wounded in the latest rounds of U.S. strikes. Since the war began on Feb. 28, 17 U.S. service members have been killed.

strikeUnverifiedUSIranRussiaChina
1 source

US Secretary of War Pete Hegseth posted social media images showing damage to a maritime control tower at Iran’s Chabahar port following reported US military strikes, accompanied by the caption “Iran does not control the Strait of Hormuz.” India’s Ministry of External Affairs stated that the Shahid Beheshti terminal operated by India at the port sustained no damage.

The ministry reiterated its position that civilian infrastructure should not be targeted during conflicts.

Location: Iran
strikeUnverifiedUSIranProxy
1 source

The U.S. Central Command reported conducting strikes on Iranian military command centers, missile and drone sites, and air defense systems on Monday evening. Iran attacked a tanker in the Strait of Hormuz early Tuesday, and Houthi forces declared a maritime embargo against Saudi Arabia.

Reports indicate that mediators have proposed a 10-day ceasefire, while Rystad Energy noted risks of higher oil prices.

Location: Iran
strikeUnverifiedIsraelIranProxy
1 source

Yemen's Iran-aligned Houthis announced Monday they would impose a maritime blockade on Saudi Arabia, further throttling a global energy market already greatly restricted by Iran's closure of the Strait of Hormuz. This is why it matters and what it means for the Iran war and the global energy crisis.

It is not clear how the Houthis would carry out a maritime blockade of Saudi Arabia, its northern neighbor along the Red Sea coast, or whether it would include a return to attacks on shipping. Yemen sits on the Bab el-Mandeb strait – the southern gateway to the Red Sea – and closing that would open up a new front in the energy crisis and Iran's overarching conflict with the U.

S. With the Strait of Hormuz already disrupted, the Red Sea has become a critical alternative outlet for Gulf oil and other products. A serious disruption would mean both of the Middle East's major oil export routes are shut simultaneously. Iran's partial blockade of the Strait of Hormuz after Israel and the U.

S. attacked it on Feb. 28 disrupted most oil and other exports from the Gulf, raising prices and delivering a global energy shock. Saudi Arabia responded by diverting more than 70% of its normal daily crude exports to the Red Sea port of Yanbu. Ships from Yanbu bound for Europe go north through the Suez Canal.

Those heading to Asia go south through Bab el-Mandeb. Shipments from Yanbu averaged 4 million barrels per day in recent weeks according to data from Kpler and Signal Ocean, up from around 973,000 bpd a year earlier. Total petroleum volumes transiting Bab el-Mandeb amounted to 7.

4 million bpd in June, or about 7% of global oil output, according to Kpler data, up from 4.2 million bpd last year. That has provided a lifeline for the energy market, helping to keep down global oil prices. Saudi Arabia is considering an expansion of its crude oil pipeline to the Red Sea coast, Reuters reported last week.

When the Houthis launched attacks on Red Sea shipping in November 2023, Gulf oil exports were flowing freely. The Houthis have been in a civil war against the Saudi-backed, internationally recognized government for more than a decade and have attacked Gulf neighbors with missiles and drones.

However, a 2022 truce between the country's warring sides largely held until last week, when Yemen's internationally recognized government said it had struck Sanaa airport to stop an Iranian plane landing. The Houthis said Saudi Arabia was responsible and, in response, fired missiles at Abha airport in the kingdom's mountainous southwest.

A senior Houthi official, politburo member Mohammad al-Farah, then warned in an interview on Iran's Press TV website that if the situation kept escalating, Bab el-Mandeb would be closed. The U.S. says Iran has armed, funded and trained the Houthis with help from Hezbollah.

The Houthis deny being an Iranian proxy and say they develop their own weapons. It is not clear how far the group's stance on Bab el-Mandeb and the Red Sea stems from its own strategic priorities or is being made on Iran's behalf. After Israel's genocidal campaign in Gaza, the Houthis began firing at Israel and on shipping in the Red Sea, saying they were doing so in support of Palestinians.

The attacks severely disrupted global shipping, prompting Maersk, Hapag-Lloyd and other major companies to divert around Africa – a far longer, more expensive route. Red Sea traffic has not recovered since, with traffic through the Suez Canal down 52% in 2025 versus 2023 levels and at its lowest in at least 50 years, Suez Canal Authority data shows.

A U.S.-led mission to restore free navigation in the Red Sea involved repeated strikes on Houthi targets and a campaign that shot down hundreds of drones and missiles. But some Houthi attacks continued until last summer, only ending completely with the Gaza cease-fire in October.

Last month, the Houthis said they would ban ships linked to Israel from the Red Sea after Israel renewed military attacks on Iran. However, that threat was never acted on and shipping groups Maersk and Hapag-Lloyd are resuming some Red Sea routes that they had abandoned during the Houthi attacks last year, Maersk said this month.

While Hezbollah and the Iraqi groups joined the war early with rocket and drone fire after the first U.S. and Israeli strikes on Iran, the Houthis had been comparatively quiet. The group's leader Abdul Malik al-Houthi said on March 5: "Our fingers are on the trigger at any moment should developments warrant it.

" Iranian commanders have repeatedly warned that the Houthis could join the war. The Houthis launched a few missile and drone attacks on Israel in late March and early April. Revolutionary Guards Quds Force commander Esmaeil Qaani said on June 1 they could choke off the Red Sea.

That may now have changed with their announcement of the blockade on Monday against Saudi Arabia in retaliation for what they called the kingdom's siege of its ports and airports, including last week's strike.