• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CybersecuritySecurity

Cyber retaliation from Iran is a problem for U.S. companies — ‘It’s in the hands of a 19-year-old hacker in a Telegram room,’ ex-NSA operative says

Amanda Gerut
By
Amanda Gerut
Amanda Gerut
News Editor, West Coast
Down Arrow Button Icon
Amanda Gerut
By
Amanda Gerut
Amanda Gerut
News Editor, West Coast
Down Arrow Button Icon
March 1, 2026, 4:54 PM ET
A veiled Iranian woman holds her cellphone displaying a portrait of Iran's Supreme Leader, Ayatollah Ali Khamenei,
A veiled Iranian woman holds her cellphone displaying a portrait of Iran's Supreme Leader, Ayatollah Ali Khamenei.Photo by Morteza Nikoubazl/NurPhoto via Getty Images

As strikes hit Tehran on Saturday morning, millions of Iranians got a strange push notification on their phones. The BadeSaba Calendar prayer app, which has more than 5 million downloads, had been compromised, and the app issued alerts saying, “Help has arrived!” and called for a “People’s Army” to defend their “Iranian brothers,” according to an assessment from cyber intel firm Flashpoint. On Sunday, the app sent with surrender instructions for rank-and-file members of the Islamic Revolutionary Guard and safe locations for protesters to gather. 

Recommended Video

Then regime loyalists quickly struck back.

According to Flashpoint, what followed on Sunday was the “most aggressive” use so far of what’s known as Iran’s “Great Epic” cyber campaign, which is a loosely coordinated group of cyber operatives under a channel called the “Cyber Islamic Resistance.” Under the group’s umbrella, various cyber attackers have shut down gas stations in Jordan, and led attacks against U.S. and Israeli military providers to destroy data as well as conduct psychological operations mimicking the BadeSaba hack.

The next 48 hours are likely to be a period of “extreme volatility” where hacktivists and proxies “take the lead in escalation to fill the vacuum left by Tehran’s central command,” Flashpoint noted in an update. These actors are allegedly using Telegram and Reddit as a coordination hub, posting screenshots of alleged attacks as proof, although it takes weeks and sometimes months to verify accuracy, said Kathryn Raines, a former NSA expert who is now a threat intel team lead at Flashpoint. 

The BadeSaba hack demonstrates the template that Iranian proxy groups could now try to deploy in reverse against Western companies and others. Plus, with Iranian leadership effectively decimated by Saturday’s strikes, the command structure that oversaw Tehran’s cyber operations is essentially gone, said Raines.

“The Iranian leadership vacuum is likely going to lead to more unpredictable, decentralized proxy attacks,” she told Fortune.

In practice, that means aligned hacktivists and proxy groups are making their own targeting decisions, without approval from central authorities. So if a highly aggressive group decides to hit a mid-sized logistics firm because to make a statement, the risk cascades beyond Tehran, Washington, D.C., or New York, said Raines. 

“It’s in the hands of a 19-year-old hacker in a Telegram room with really no oversight or direction,” she warned. 

Accordingly, U.S. business leaders need to be prepared for continued uncertainty, said Brian Carbaugh, co-founder and CEO of AI-based security firm Andesite and former director of the CIA’s elite Special Activities Center (SAC). Iranians have consistently shown over the years that they are incredibly resilient as a government and resistance force. And given that the regime is bombarding its neighbors, people should expect Iran to continue unleashing their formidable offensive cyber capabilities in addition to other aspects of national power like their missiles and armed proxies around the world, he said.  

“Aggressive and creative resistance is baked into the ethos of the Iranian security apparatus and across the Islamic Republic of Iran,” said Carbaugh, who previously served as chief of staff to two CIA directors. “For business leaders and those protecting businesses and making decisions at a very high level, they need to be prepared for this to continue on for some time and for the conflict to take a number of different courses of direction and swerve around the road.”

As U.S. and Israeli attacks degrade Iran’s conventional military capabilities, cyber attacks appear more attractive, said Carbaugh. It’s low-cost to deploy, difficult to attribute, and extremely capable of creating outsized psychological and operational disruption relative to the investment required. Iran has shown that it is capable of emulating and building on cyber attack methods first shown by Russia, for example.

“The Islamic Republic has always had great pride in cyber capabilities within the security services,” said Carbaugh. That pride isn’t likely to evaporate with the loss of senior leadership, and may intensify as other options narrow. 

According to Raines, most corporate security plans aren’t ready for attacks like the BadeSaba hack, which pushed a notification to potentially millions of Muslims in Iran who use the app to track daily religious schedules at the moment the strikes were starting. 

“Companies aren’t really prepared for what I’ll call nihilistic psychological operations that are really meant to target the mental state and trust of their workforce,” she explained, contrasting them with attacks designed to steal data and disable systems.

It could manifest in businesses like this: Staff in the Gulf region start getting what appear to be urgent messages, perhaps deepfake audio attributed to their regional leader or CEO, or communications purportedly from the company on evacuations. But with local news offline and scant internet service, people will have very little ability to fact check anything.

Few companies have plans in place for what employees’ reality will be in the hours that follow, while risk modeling is often based on state behavior and assumed “red lines” that prevent total war, Raines noted. 

For boards and C-suites convening this upcoming week, key questions for security leaders will have to do with the maximum amount of time business functions can be offline before it hits revenue and reputation, she predicted. 

“We’re less interested in the block rate, and more interested in recovery time,” said Raines.

Carbaugh said if he were on a board call this week, he would want to know if the business was at an elevated level of risk based on what’s happening in Iran. If the answer is yes, he would want to know what’s being done to mitigate. If the answer is no, he would ask even more questions.

Leaders should find out what steps have been taken to ensure businesses aren’t at risk, figure out how companies have engaged with partners and others to find out how they’re detecting attacks, and how AI is currently being used in doing so, Carbaugh said. 

He reiterated that this isn’t a crisis with a near-term resolution, and it translates into cyber risk that won’t immediately dissipate. 

“This conflict could take many twists and turns and move in a lot of different directions,” said Carbaugh. “I don’t think this is going to be one we’re going to tidily wrap up and move on from in a few days. This will require constant vigilance and protection of our cyber networks, physical security, and all other assets.”

In 2001, Fortune first convened “The Smartest People We Know,” bringing together CEOs and founders, builders and investors, thinkers and doers. Since then, Fortune Brainstorm Tech has been the place where bold ideas collide. From June 8–10, we will return to Aspen—where it all began—to mark 25 years of Brainstorm. Register now.
About the Author
Amanda Gerut
By Amanda GerutNews Editor, West Coast

Amanda Gerut is the west coast editor at Fortune, overseeing publicly traded businesses, executive compensation, Securities and Exchange Commission regulations, and investigations.

See full bioRight Arrow Button Icon

Latest in Cybersecurity

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Cybersecurity

President Donald Trump in Washington, D.C. on May 4, 2026. (Photo: Kent Nishimura/AFP/Getty Images)
NewslettersFortune Tech
Trump may seek to review AI models before launch
By Andrew NuscaMay 5, 2026
5 hours ago
dario
CommentaryAnthropic
Anthropic’s most powerful AI model just exposed a crisis in corporate governance. Here’s the framework every CEO needs.
By Jeffrey Sonnenfeld, Stephen Henriques, Dan Kent and Holden LeeMay 2, 2026
3 days ago
Apple CEO Tim Cook in Washington, D.C. on December 10, 2025. (Tom Williams/CQ-Roll Call/Getty Images)
NewslettersFortune Tech
Tim Cook’s advice for Apple’s next CEO
By Andrew NuscaMay 1, 2026
4 days ago
Meta's Hyperion data-center site in Northeastern Louisiana.
NewslettersEye on AI
Big Tech will spend nearly $700 billion on AI this year. No one knows where the buildout ends
By Sharon GoldmanApril 30, 2026
5 days ago
Jamie Dimon, chief executive officer of JPMorgan Chase & Co., at the Norges Bank Investment Management annual investment conference in Oslo, Norway, on Tuesday, April 28, 2026.
EconomyJamie Dimon
For years, the risk Jamie Dimon was most concerned about was geopolitics. His answer has shifted
By Eleanor PringleApril 30, 2026
5 days ago
Photo of a Disneyland sign
CybersecurityDisney
Disneyland implements facial recognition to keep the lines moving, but guests say they didn’t know it was optional
By Catherina GioinoApril 28, 2026
7 days ago

Most Popular

Diary of a CEO founder says he hired someone with 'zero' work experience because she 'thanked the security guard by name' before the interview
Success
Diary of a CEO founder says he hired someone with 'zero' work experience because she 'thanked the security guard by name' before the interview
By Emma BurleighMay 3, 2026
2 days ago
Current price of silver as of Monday, May 4, 2026
Personal Finance
Current price of silver as of Monday, May 4, 2026
By Joseph HostetlerMay 4, 2026
1 day ago
Current price of oil as of May 4, 2026
Personal Finance
Current price of oil as of May 4, 2026
By Joseph HostetlerMay 4, 2026
1 day ago
America got rich and got sad. A top economist says 2020 broke something that hasn't healed
Economy
America got rich and got sad. A top economist says 2020 broke something that hasn't healed
By Nick LichtenbergMay 3, 2026
2 days ago
As economic despair mounts, Russian official admits the country has had enough of Putin's war on Ukraine. 'We can’t even take one region'
Economy
As economic despair mounts, Russian official admits the country has had enough of Putin's war on Ukraine. 'We can’t even take one region'
By Jason MaMay 3, 2026
2 days ago
America is lucky it’s no longer a manufacturing powerhouse—it’s what’s protecting the U.S. economy from the worst of the oil shock, top economist says
Economy
America is lucky it’s no longer a manufacturing powerhouse—it’s what’s protecting the U.S. economy from the worst of the oil shock, top economist says
By Sasha RogelbergMay 4, 2026
23 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.