ConflictClarifier

2026伊朗-海湾危机追踪
CC
Events Archive
strikeMar 18, 2026

Every Fortune 500 CEO's nightmare: the Iran War and the Pandora's Box of AI cyber warfare | Fortune

Summary

When U.S. and Israeli forces launched a sweeping air and sea campaign against Iran’s military infrastructure in late Feb. 2026, the missiles weren’t the only weapons that flew. Within hours, more than 60 Iranian-aligned cyber groups mobilized, according to Palo Alto Networks’ Unit 42, armed with AI-assisted reconnaissance tools and a mandate to strike back where it hurts most: America’s corporate nervous system. Within hours, cybersecurity agencies in the UK and Canada both warned about heightened threat levels, followed by similar warnings from Europol and the Department of Homeland Security. For Fortune 500 CEOs, the message couldn’t be clearer—or more unsettling. The Iran war has blown open a Pandora’s box of AI-powered cyber warfare, and no firewall, no matter how expensive, was built for what’s coming next. A new attack template Iran’s cyber playbook has already claimed its first major corporate victim. Iranian-aligned hackers disrupted operations at U.S. medical technology giant Stryker, as first reported by the Wall Street Journal and confirmed by the company—a sobering signal that the private sector is squarely in the crosshairs. According to threat intelligence firm Flashpoint, the Iranian-aligned hackers executed a sophisticated “no-malware” attack on Stryker—not through traditional malicious code, but by weaponizing Microsoft Intune, a legitimate cloud-based endpoint management service, to remotely wipe devices across the company’s network. The attack has sent a chill through every corporate IT department in America: the tools used to manage your own infrastructure can now be turned against you. The more chilling template, analysts warn, isn’t the conventional data breach—it’s a coordinated campaign designed to destroy institutional trust from the inside out. Iran’s state-backed hacking groups, including Void Manticore aka Handala, have already deployed ransomware-style attacks, distributed denial-of-service operations, and “wiper” attacks engineered to permanently erase data from corporate servers. These aren’t smash-and-grab operations. They are psychological warfare at enterprise scale. According to Flashpoint, the Handala Hack Team claimed responsibility for breaching a Mossad “secret treasury,” allegedly leaking 50,000 confidential emails. In a chilling escalation, the group also claimed to have identified the precise geographic coordinates of a target through cyber reconnaissance—and that a kinetic missile strike followed. Cyber and physical warfare, in other words, are no longer separate domains. “Aggressive and creative resistance is baked into the ethos of the Iranian security apparatus,” Brian Carbaugh, co-founder and CEO of AI-based security firm Andesite and a former director of the CIA’s elite Special Activities Center, previously told Fortune. “For business leaders and those protecting businesses and making decisions at a very high level, they need to be prepared for this to continue on for some time and for the conflict to take a number of different courses of direction and swerve around the road.” AI as the great equalizer—and the great threat multiplier What separates this conflict from previous cyber flashpoints is the role of artificial intelligence (AI) on both sides of the battlefield. U.S. and Israeli forces have used AI platforms from Palantir and the Pentagon’s Maven Smart System to execute more than 15,000 strikes since the war began—over 1,000 per day—with remarkable precision, according to security columnist Shimon Sherman of the Jewish News Syndicate. AI has compressed the military “kill chain” from days to minutes, he added. (Iran, for it’s part, has used its firepower to target data centers in the UAE). But cybersecurity firm CloudSek argued in a blog post that the same compression is now available to Iran’s proxies—and to any hacker group with a laptop and access to an AI reconnaissance pipeline. AI tools have sharply lowered the barrier to identifying and exploiting exposed industrial control systems, default credentials, and internet-facing corporate infrastructure across America. Threat groups with no prior industrial control systems background are now, effectively, sophisticated actors overnight. Flashpoint said the 313 Team, an Iranian-aligned Cyber Islamic Resistance group, claimed a complete shutdown of the official British Army website—a clear signal that state-adjacent institutions and critical government infrastructure are primary targets. The defender is already behind What makes the current threat environment uniquely dangerous for corporate America is the simultaneous convergence of physical and cyber disruption. On March 17 alone, a drone strike on the Fujairah oil hub in the UAE halted refining operations; a Kuwaiti-flagged LNG tanker was damaged by drone debris near the Strait of Hormuz; and the U.S. Embassy in Baghdad suffered its heaviest attack since the war began. These are not abstract geopolitical events—they are direct shocks to the energy supply chains that power global commerce. “The conflict has entered a stage where the economic and operational impacts are becoming much more visible,” said Josh Lefkowitz, CEO of Flashpoint, in a statement issued Wednesday. “We’re seeing disruption at major transportation hubs, pressure on global shipping routes, and cyber activity targeting private companies already creating ripple effects across supply chains, travel, and day-to-day commercial operations. For organizations connected to the region, the risk environment now includes simultaneous physical disruption and cyber activity.” The timing couldn’t be worse for corporate America. The Cybersecurity and Infrastructure Security Agency (CISA)—the federal government’s primary cyber defense body—is hobbled by furloughs, a leadership reshuffle, and the lingering effects of a partial government shutdown. The cavalry, in other words, is understaffed and reorganizing. Meanwhile, Iran’s own command structure has been decimated by allied strikes—including the elimination of Ali Larijani and Gholamreza Soleimani, commander of the Basij paramilitary unit—which, paradoxically, makes the threat more dangerous, not less. “The Iranian leadership vacuum is likely going to lead to more unpredictable, decentralized proxy attacks,” Kathryn Raines, a former NSA expert who is now a threat intel team lead at Flashpoint, told Fortune‘s Amanda Gerut. Decentralized means harder to anticipate, harder to attribute, and harder to stop. President Trump has also accused Iran of weaponizing AI for disinformation, allegedly collaborating with media outlets to shape narratives around the conflict. Corporate reputations—not just networks—are now targets. The boardroom imperative Every Fortune 500 CEO sitting in a board meeting this week faces the same stark reality: the Iran war has permanently altered the cyber threat landscape. AI hasn’t just made attacks faster—it has made them cheaper, stealthier, and accessible to a sprawling ecosystem of state proxies and opportunistic hacktivists who share the same AI-assisted toolkit. The Pandora’s box is open. The question isn’t whether the next major attack on a U.S. corporation is coming—it’s whether the C-suite will be ready when it does. Additional reporting contributed by Amanda Gerut.

Actors involved

USIsraelIranProxy

Sources

  • Nick LichtenbergBy Nick Lichtenberg

    When U.S. and Israeli forces launched a sweeping air and sea campaign against Iran’s military infrastructure in late Feb. 2026, the missiles weren’t the only weapons that flew. Within hours, more than 60 Iranian-aligned cyber groups mobilized, according to Palo Alto Networks’ Uni

See this event through different lenses

Compare how Western, Iranian, Israeli, Global South, and Pro-Peace perspectives frame this event.

Compare Perspectives

Community Notes

Community Notes

Loading notes...

Related events

strikeUnverifiedUSIsraelIranEUChina
1 source

Japan’s Defense Ministry said Friday that Iran used its geographical advantage to “inflict unbearable costs at a relatively low military expense,” effectively closing the Strait of Hormuz by indicating that it had laid naval mines, Kyodo News reported.

The ministry said Japan would strengthen its defense capabilities based on lessons from the US-Iran war, including by using defense equipment also operated by allies and like-minded partners to help ensure rapid supplies from other countries. It also stressed the need to maintain sufficient missile stockpiles and be prepared to quickly increase defense equipment production in an emergency, according to its first report analyzing the Iran war since February.

The US-Israeli war against Iran began on Feb. 28, with attacks targeting military, nuclear and infrastructure sites across the country. Iran responded with missile and drone strikes against Israel and US military facilities across the region. READ: EU joins US-led campaign to isolate Iran financially: Treasury chief Bessent Washington and Tehran signed a memorandum of understanding on June 18 concerning freedom of navigation through the Strait of Hormuz, but its implementation has stalled amid disagreements over security arrangements in the strait.

The Japanese report also said the country should take its own geographical characteristics into account when developing combat strategies, including the fact that it is surrounded by sea. The report noted the US use of AI to accelerate decision-making and operations, citing attacks on around 1,000 targets within 24 hours, while also highlighting the risk of AI making incorrect judgments.

“It is important to establish a process that maximizes the benefits of AI while ensuring appropriate human involvement,” the ministry said. The report comes ahead of a planned revision of Japan’s key security documents by the end of this year.

strikeUnverifiedUSIranProxy
1 source

A major offensive by Yemen's Houthis to seize control of the gateway to the Red Sea has left more than 120 people dead, sources told AFP Friday, the country's deadliest clashes in years. Fighting erupted on Thursday, after the Iran-backed Houthis launched a ground assault along with rocket and drone attacks near coastal areas, vying for control of the narrow Bab al-Mandab strait at the Red Sea's southern entrance.

Yemen, embroiled in more than a decade of civil conflict, in July became the latest country to be drawn into the Middle East war as the Houthis upended a 2022 truce with the Saudi-backed government. Since then, the Houthis have imposed a maritime blockade of Saudi Arabia and repeatedly attacked its ships in the Red Sea -- a vital alternative route for oil exports after Iran all but halted Gulf shipments by blockading the Strait of Hormuz.

The rebels are now trying to tighten their hold over the Red Sea, one of the world's busiest shipping lanes, which they have disrupted with attacks on passing vessels since the Gaza war broke out in 2023. The Houthi offensive aims to cut off the government-held port city of Mokha, under fire for weeks, and advance towards areas bordering the Bab al-Mandab, military sources told AFP.

The rebels have seized elevated sites overlooking government positions near the Red Sea and the city of Taiz further inland, a military source and a Taiz official told AFP, requesting anonymity. The Houthis could target ships from these elevated positions, they said.

The toll rose to 129 on Friday, according to an AFP tally compiled from several sources, up from an earlier count of 81. A Yemeni military official speaking on condition of anonymity told AFP that 66 of his men had been killed, while medical and military sources close to the Houthis said at least 62 militants had died.

Another medical source said a civilian had also been killed. Although the Houthis do not control areas bordering Bab al-Mandab, they hold the key port city of Hodeida north of Mokha. "They are going for Bab al-Mandab," said Mohammed al-Basha, of the US-based risk advisory Basha Report.

The Houthis want to control the hills overlooking Bab al-Mandab and Mokha before attacking the coast, a Yemeni official in Aden, the government's base since it was ousted from the rebel-held capital, Sanaa, in 2014. The government has sent reinforcements to Taiz from Aden on Saudi orders, he said.

"The Houthis feel that if they capture Bab al-Mandab or Mokha port they will be in a better position of power to negotiate with the government and the Saudis," Basha added. With Iran's closure of Hormuz, the Bab al-Mandab chokepoint has gained increased importance as a transit route for oil from Saudi Arabia, the world's biggest exporter of crude.

The narrow waterway connects the Red Sea -- and, via the Suez Canal, the Mediterranean -- to the Indian Ocean. In July, a fragile truce between the Houthis and the government fell apart after the rebels welcomed an Iranian plane to Sanaa, setting off a spate of attacks.

They later announced a maritime blockade of Saudi Arabia and began hitting its ships and territory.

Location: Tyre
strikeUnverifiedUSIsraelIranUNRussiaChina
1 source

If passed, the resolution would follow up on one adopted on June 12 of last year declaring Iran in breach of its non-proliferation obligations for not fully cooperating with an investigation into uranium traces found at undeclared sites. Israel started bombing Iran's nuclear facilities the next day, soon joined by the U.

S. Iran's uranium-enrichment plants were destroyed or badly damaged. Iran has not let International Atomic Energy Agency inspectors return to the bombed sites since then or verify what remains of its stocks of enriched uranium, some of which was enriched to up to 60% purity, a short step from weapons grade.

FRESH DIPLOMATIC ESCALATION A resolution by the IAEA's 35-nation board reporting Iran to the Security Council would also be the culmination of a standoff over IAEA access to those sites, since the board has passed two resolutions in the past year demanding Iran declare its enriched uranium stocks and grant the IAEA full access to verify them.

"(The board) requests the (IAEA) Director General to transmit this resolution and the previously adopted resolutions ... to all Members of the Agency and to the Security Council and the General Assembly of the United Nations," said the latest resolution draft seen by Reuters.

It also "reiterates its call upon Iran to urgently remedy its non-compliance with its Safeguards Agreement by taking all steps deemed necessary by the Agency and the Board, so that the Director General can provide the necessary assurances regarding the correctness and completeness of Iran's declarations".

The draft has not yet been formally submitted to the board and negotiations over the exact wording are ongoing, diplomats said. Whenever the four powers have submitted a draft resolution on Iran in recent years, it has passed. Concrete action by the Security Council against Iran is unlikely since Tehran's allies Russia and China are permanent, veto-wielding members.

IAEA CONCERNS OVER ENRICHMENT Iran has often retaliated following IAEA board resolutions against it by escalating its nuclear activities or scaling back cooperation with the IAEA, but its options for both are currently extremely limited. It is unclear what other repercussions there might be on Tehran's conflict with the U.

S. As a party to the nuclear Non-Proliferation Treaty (NPT), Iran has the right to develop nuclear technology, including enrichment, for peaceful purposes. Iran says it would never produce nuclear weapons. It is, however, the only country to enrich to 60% without making a bomb.

The IAEA has said the amount it has enriched to that level is of serious concern. The IAEA estimates Iran had 440.9 kg of uranium enriched to that level before its sites were bombed. That is enough, if enriched further, for 10 nuclear weapons, according to an IAEA yardstick.

strikeUnverifiedUSIsraelIranUN
1 source

The US and its allies Britain, France and Germany are pushing other countries on the UN nuclear watchdog's board to pass a resolution next week reporting Iran to the UN Security Council for the first time in 20 years, diplomats said on Friday. If passed, the resolution would follow up on one adopted on June 12 of last year declaring Iran in breach of its non-proliferation obligations for not fully cooperating with an investigation into uranium traces found at undeclared sites.

The US launched an air war against Tehran on February 28 in which, together with Israel, it destroyed or badly damaged Iran's uranium-enrichment facilities. Iran has not let International Atomic Energy Agency (IAEA) inspectors return to the bombed sites since then or verify what remains of its stocks of enriched uranium, some of which was enriched to up to 60% purity, a short step from weapons grade.

Resolution would be culmination of standoff over IAEA's access to nuclear sites A resolution by the IAEA's 35-nation board reporting Iran to the Security Council would also be the culmination of a standoff over IAEA access to those sites, since the board has passed two resolutions in the past year demanding Iran declare its enriched uranium stocks and grant the IAEA full access to verify them.

A draft text for the resolution has yet to be formally submitted to the board and negotiations between countries over the exact wording are ongoing, diplomats said. A draft is usually formally submitted early in the week of a board meeting. As a party to the nuclear Non-Proliferation Treaty (NPT), Iran has the right to develop nuclear technology, including enrichment, for peaceful purposes.

Iran says it would never produce nuclear weapons. It is, however, the only country to enrich to 60% without making a bomb. The amount it has enriched to that level is "a matter of serious concern" to the IAEA. The IAEA believes well over 200 kg of that highly enriched uranium has survived the bombardments and is held in a tunnel complex at Isfahan and at the Natanz facility.

Location: Jerusalem