Iranian cyber operations have gone from being disruptive single events to ongoing campaigns against governments, infrastructure providers, technology companies, and research organizations. Their ability to operate inside the same tools and infrastructure that defenders rely on makes these intrusions difficult to detect. The stakes extend well beyond espionage. For example, in 2022, Iranian-linked attackers caused damage to systems throughout the Albanian government and shut down multiple Albanian agencies. As a result, Albania severed diplomatic relations with Iran after the attack. With the current Iran conflict, cybersecurity experts are monitoring for increased Iranian attacks against critical infrastructure and government networks. The…
