
This Flare brief covers confirmed and credibly reported cyber operations over the last 24 hours running July 7 through July 8, 2026, linked to the US-Israel-Iran conflict. The intervening period between reports saw a June 14 memorandum of understanding, signed June 17 by both presidents, intended to terminate hostilities within a 60-day window, followed by a fragile and repeatedly violated interim ceasefire.
The defining development in this window is kinetic, not cyber. On July 7, Iranian forces struck three commercial vessels transiting the Strait of Hormuz off the coast of Oman, including a Qatari LNG tanker and a Saudi-flagged crude tanker. US Central Command responded with a series of strikes on more than 80 Iranian targets, including air defenses, radar sites, anti-ship missile capabilities, and more than 60 IRGC small boats. The US Treasury revoked the waiver that had authorized Iranian oil sales. President Trump stated that the ceasefire is over. The strikes coincided with the multi-day state funeral for Supreme Leader Ali Khamenei, during which mourners publicly called for retaliation against US and Israeli leadership. The UK Maritime Trade Operations Centre raised the Strait of Hormuz threat level to severe.
No new attributed cyber operation falls inside the 24-hour window. The cyber threat picture remains governed by the detection baselines established in April and sustained through the reporting series: DomainTools unified MOIS attribution (Apr 20), CISA AA26-097A PLC advisory (Apr 7), Unit 42 CL-STA-1128 FactoryTalk-on-VPS tradecraft (Apr 17), Check Point Void Manticore TTPs (Apr 2), and FBI FLASH-20260320-001 Telegram C2 malware. The operationally significant change is the collapse of the interim ceasefire and the return to active kinetic exchange, which resets the retaliation clock. Iranian cyber operations across the conflict have consistently been timed to kinetic events. Hold all established detection posture at maximum sensitivity. Treat the resumption of strikes and the public revenge framing around the Khamenei funeral as a probable trigger for a renewed hacktivist surge and for MOIS-directed information operations against US and Gulf targets. This window is an early-warning window, not a post-incident window.
We will continue to update this timeline with the most recent information as the situation develops.
For customers seeking further details, please reach out to your Customer Success Manager, and for non-customers please reach out here.
US-Israel-Iran Conflict Timeline & Cyber Context
The cyber operations documented in this brief are responses to three major kinetic escalations:
Confirmed & Credibly Reported Cyber Attacks
Note: This update covers the 24-hour window 7 to 8 July 2026. Events from February 28 through May 4, 2026 are tracked in prior revisions. No new attributed cyber operation was publicly reported inside the window. The entries below record the anchoring baselines that remain in force and the kinetic trigger condition that governs the near-term outlook.
No New Attributed Cyber Operation in Window; Kinetic Re-Escalation Is the Governing Event (Jul 7-8, 2026)
- Threat Actor: Not applicable; no attributed cyber operation in window. Governing event is kinetic (Iranian IRGC maritime strikes; US Central Command retaliatory strikes)
- Target: Commercial shipping in the Strait of Hormuz (Qatari LNG tanker, Saudi-flagged crude tanker, third tanker off Oman); Iranian air defense, radar, anti-ship missile, and IRGC small-boat assets
- Attack Type: Kinetic. Iranian projectile and drone strikes on transiting vessels; US precision strikes on more than 80 Iranian targets. No cyber vector attributed in window
On 7 July, three commercial vessels were struck while transiting the Strait of Hormuz off the coast of Oman. Iranian state television indicated at least one vessel was attacked after ignoring warnings, though Tehran did not directly claim the strikes. Qatar and Saudi Arabia condemned attacks on their flagged tankers. US Central Command stated it launched a series of strikes against Iran, hitting more than 80 targets with precision munitions, including air defense systems, command and control networks, coastal radar, anti-ship missile capabilities, and more than 60 IRGC small boats. President Trump, attending the NATO summit in Ankara, approved the strike plan and stated the ceasefire is over. The US Treasury revoked the general license authorizing Iranian oil and petrochemical sales.
No cyber operation has been attributed inside the 24-hour window. This is consistent with the observed sequencing across the conflict, in which cyber activity follows kinetic escalation by hours to days rather than preceding it. The absence of an attributed operation in the window should be read as an early-warning condition, not an all-clear. The Khamenei state funeral, running concurrently, featured public calls for retaliation against US and Israeli leadership, which raises the probability of MOIS-directed information operations and a hacktivist surge in the near term.
Defender takeaway: treat the resumption of strikes as the trigger condition. Move detection and response posture from steady-state to elevated. Prepare to validate and respond to breach and leak claims, which historically appear within hours of kinetic escalation and are frequently exaggerated for psychological effect. Do not wait for an attributed operation to raise posture.
Sources: CENTCOM (Jul 7, 2026); CBS News (Jul 7); NPR (Jul 7); CNBC (Jul 7); Fox News (Jul 7); Al Jazeera (Jul 7); Bloomberg (Jul 7)
CISA AA26-097A and Unit 42 CL-STA-1128 Detection Baselines Hold; No New Federal Cyber Advisory in Window (Jul 7-8, 2026)
- Threat Actor: IRGC CEC / CyberAv3ngers / CL-STA-1128 / Storm-0784 / Hydro Kitten / Bauxite
- Target: US water and wastewater systems; energy sector; government services; Rockwell / Allen-Bradley PLC operators; 3,000+ internet-exposed Rockwell devices
- Attack Type: PLC exploitation; project file manipulation; HMI / SCADA display manipulation; configuration wiping; FactoryTalk-on-VPS tradecraft
The April 7 joint advisory AA26-097A on Iranian-affiliated exploitation of internet-facing Rockwell / Allen-Bradley PLCs across US water, wastewater, energy, and government services remains the anchoring federal OT guidance. No new federal cyber advisory was issued in the 24-hour window. Unit 42’s April 17 assessment that the actor installed Rockwell FactoryTalk software on VPS infrastructure to enable exploitation remains the operative detection picture. The exposure population of internet-facing Rockwell devices, over 3,000 per CISA analysis, has not materially decreased.
The kinetic re-escalation raises the salience of this baseline. OT-focused Iranian actors have historically prioritized water, energy, and government-services targets for their asymmetric and symbolic value during periods of active conflict. Hold PLC detections at maximum sensitivity.
Defender takeaway: keep all Rockwell Automation and Allen-Bradley PLCs and OT devices out of direct internet exposure. Monitor ports 44818, 2222, 102, 22, and 502. Hunt for anomalous FactoryTalk client connections originating from VPS or commercial cloud IP ranges. Flag Studio 5000 Logix Designer sessions from non-engineering-workstation source networks. Verify project file and controller logic integrity. Report suspected compromise to CISA and Rockwell PSIRT.
Sources: CISA AA26-097A (Apr 7, 2026); Unit 42 CL-STA-1128 (Apr 17); EPA joint advisory (Apr 7); CSIS (May 12)
For customers seeking further details, please reach out to your Customer Success Manager, and for non-customers please reach out here.
Key Threat Actor Summaries
Relevant Government Advisories
No new federal cyber advisories issued in the seven-day window. Anchoring guidance below remains in effect:
For historical advisories, please reach out to your Customer Success Manager if you are a customer, and reach out here if you are not a customer.
Assessment & Outlook
The conflict has entered its 66th day. The following assessment reflects cyber developments from the previous seven days.
Near-Term Cyber Threat (1 to 4 weeks): CRITICAL & ELEVATED
The previous seven days produced one attributed cyber operation: the Handala WhatsApp threat campaign against US service members at Naval Support Activity Bahrain on April 27 to 28, paired with a Telegram-channel doxxing post claiming the names and phone numbers of 2,379 US Marines stationed in the Persian Gulf. Identical Persian-themed messages were sent to civilian recipients across Israel on the same day. The genuine signal in the window is the shift from enterprise targets to direct intimidation of named US military personnel and their families.
The cyber threat picture remains governed by the detection baselines established earlier in April: DomainTools unified MOIS attribution, CISA AA26-097A, Unit 42 CL-STA-1128, Check Point Void Manticore, and FBI FLASH-20260320-001. Hacktivist DDoS tempo continues at post-April 18 baseline. The Iran internet blackout at Day 66 sustains the VSAT operational shift picture for state-actor infrastructure. The Bahrain campaign is consistent with the Halcyon thesis that prior quiet periods reflected covert execution rather than dormancy. Iranian retaliation probability against US critical infrastructure, IRGC 18-company target list organizations, Israeli defense and telecom, Gulf government portals, and MSC-adjacent vendors remains elevated. The Bahrain campaign also raises the probability that personnel-targeted information operations will spread from US Navy and Marine Corps personnel to other service branches and to defense-contractor employees with classification or critical-infrastructure roles.
Priority Cyber Targets (Updated for Window)
- Strait of Hormuz shipping-adjacent and maritime-logistics networks (CRITICAL, NEW IN WINDOW): The maritime strikes make shipping operators, port authorities, flag-state registries, and maritime-logistics vendors a probable near-term target for disruption and information operations.
- US critical infrastructure with internet-facing Rockwell PLCs and OT devices (CRITICAL, SUSTAINED): CISA AA26-097A remains in effect. Unit 42 CL-STA-1128 FactoryTalk-on-VPS tradecraft remains the active detection picture. Over 3,000 Rockwell devices remain exposed.
- US military personnel and dependents in CENTCOM AOR (CRITICAL, SUSTAINED): The prior-window Bahrain campaign established the personal-device intimidation pattern. Ceasefire collapse raises the probability of renewed personnel-targeted information operations.
- Gulf state digital infrastructure (CRITICAL, SUSTAINED): Qatar and Saudi Arabia were directly affected by the maritime strikes. Gulf government portals, energy operators, and airports remain in scope for DDoS and defacement.
- Israeli defense, telecom, and government (CRITICAL, SUSTAINED): Unified MOIS operation targeting weight sustained against this tier.
- US critical infrastructure and financial services (CRITICAL, SUSTAINED): Iran has previously declared US financial institutions and major technology companies legitimate targets. Elevated probability under renewed kinetic conditions.
At Flare, we will continue to monitor this conflict and update this article as we learn more information.
Threat Intelligence
Monitor State-Linked Cyber Threats as They Emerge
The US-Israel-Iran conflict has unleashed a wave of cyber operations spanning hacktivist groups, nation-state APTs, and ransomware affiliates. Flare continuously monitors the dark web, illicit Telegram channels, and threat actor infrastructure so your team can detect and respond to emerging threats before they reach your organization.





