Recent cyber activity attributed to the Iranian hacking group Seedworm has compromised multiple U.S. organizations since early February 2026. This includes a U.S. bank, an airport, and various non-governmental organizations in both the U.S. and Canada, as well as the Israeli operations of a U.S. defense contractor.
Security experts from Symantec identified these intrusions amidst rising tensions following military actions by the U.S. and Israel against Iran. Analysts believe that this activity indicates a potential expansion of Iranian cyber operations targeting Western entities. As a result, they recommend that organizations enhance their monitoring and defense measures in anticipation of further probing by Iranian threat actors.
Seedworm, operational since 2017, has evolved from focusing on Middle Eastern targets to engaging with sectors such as telecommunications and defense across various continents. Their tactics include using customized malware alongside publicly available tools. The CISA has classified Seedworm as part of the Iranian Ministry of Intelligence and Security, further highlighting the group's significance within the broader threat landscape.