Security researchers at Barracuda have identified an 88% spike in brute-force attacks targeting SonicWall and FortiGate devices originating from the Middle East, accounting for over half of all incidents seen by the SOC over February and March.
While most attempts were unsuccessful, either blocked outright or aimed at invalid usernames, Barracuda warned that the attackers are on an aggressive campaign of scanning and testing perimeter devices, significantly raising the risk of compromise.
Though there is no direct evidence linking these cyber-attacks to any specific state, and they may simply have been routed through servers in the region, the uptick coincides with the conflict between the US, Israel, and Iran, which has already fuelled anxiety over cyber threats.
Last month, researchers from Sophos warned that Iranian‑linked groups have stepped up their use of social engineering tactics like spearphishing, along with large-scale password-spraying campaigns and the exploitation of weak credentials to target IT and OT environments.
As with Barracuda’s analysis, Sophos found an uptick in attacks directed at newly disclosed or unpatched vulnerabilities in public-facing applications, including in Fortinet FortiOS and Microsoft Exchange ProxyShell.
Added to that, analysts at Palo Alto Networks’ Unit 42 reported an increased risk of wiper attacks targeting both enterprise and consumer sectors, which, unlike ransomware, are designed to permanently delete or destroy data.
Recommended reading
- Oversight Board Slams Meta for Overlooking Fake AI Posts About Iran Conflict
- Threat Actors Leverage Iran Chaos in Phishing Attacks
- How Will the Iran War Impact Cloud, Cyber, and IT Spend?
Coupled with Barracuda’s threat brief, this suggests that, despite a fragile ceasefire now in place, weeks of intense conflict have left the digital landscape highly volatile, with Western firms and CNI organisations among the most likely targets for renewed hostility.
Last week, the US security services issued a joint advisory warning that Iran-backed threat actors had targeted internet-facing OT devices across critical infrastructure, including water utilities and energy networks.
That followed news last month that US medtech Stryker had suffered a “global network disruption” to its Microsoft environment after a cyberattack claimed by Iran-linked hacking groups in apparent retaliation for a strike on an Iranian school.





