
Smoke rises over Tehran after airstrikes on Iran on February 28, 2026. FATEMEH BAHRAMI/ANADOLU VIA GETTY IMAGES
The federal government’s cyber defense agency is short-staffed, and Tehran is known for its retaliatory cyberattacks.

BY DAVID DIMOLFETTACYBERSECURITY REPORTER, NEXTGOV/FCW
FEBRUARY 28, 2026 06:14 PM ET
Coordinated U.S. and Israeli
strikes on Iranian targets are putting renewed focus on how the United States integrates offensive cyber capabilities into the battlespace — and how prepared federal agencies are for retaliation at home.
Iran has shown a tendency to respond to overseas threats with cyber means, from defacing websites to spying on U.S. and allied targets. Tracking such actions and
alerting the U.S. government and public is a job of the Cybersecurity and Infrastructure Security Agency, which has been operating with
sharply reduced staffing due to a funding lapse for its parent agency, the Department of Homeland Security.
“This is a bad time for Washington’s cyber agency to be operating with limited staff,” said Annie Fixler, director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies, a national security think tank.
That funding lapse comes after Trump-administration moves
shrank CISA’s workforce by about one-third last year and
degraded public-private collaboration mechanisms. This “limits the ability of the federal government to provide timely cyber threat information to the private sector,” Fixler said.
In the wake of the U.S. and Israeli airstrikes, American companies could see a “barrage” of low-level attacks like website defacements and distributed denial-of-service attacks, said Fixler. “Iran might also see some limited success against targets that do not have proper cyber hygiene — exposed edge devices with default passwords, for example.”
Other cyber experts said the U.S. should prepare for a mix of distributed denial-of-service campaigns, ransomware and hack-and-leak operations meant to send a message.
“While it’s not operating at the same technical level as China or Russia, Iranian-linked groups have carried out disruptive attacks against U.S. financial institutions, infrastructure providers and private sector companies,” said Tom Pace, a former Marine intelligence specialist and CEO of NetRise, a cybersecurity supply chain firm.
The conflict will likely see a surge in state-sponsored hacking activity, “specifically targeting operational technology and critical infrastructure through the exploitation of internet-facing industrial control systems and vulnerable [programmable logic controller] hardware,” said Brian Harrell, a former CISA official.
“Threat hunters should be working overtime right now. By combining disruptive attacks with psychological operations, Iran will seek to erode public trust in government institutions and project domestic strength during periods of heightened conflict,” he said.
Elisity CEO James Winebrenner echoed that advice. “We should be vigilant in protecting exposed [industrial controls systems] and expect heightened retaliatory activity in the coming days and weeks,” he said. In late 2023, Iran-linked hackers
digitally defaced U.S. water treatment equipment.
Tehran may play up the effectiveness and scope of their cyberattacks, said Cynthia Kaiser, a former FBI cybersecurity deputy director who leads the Ransomware Research Center at Halcyon. Industry research has
documented these theatrics.
“They’ll turn [an intrusion] into an information operation, and say, ‘Look, we compromised this entire facility,’ even though they compromised just a machine,” Kaiser said.