Israel claims to have carried out a successful strike on a compound in Tehran that housed Iran’s “cyberwarfare headquarters” and “Intelligence Directorate,” among other things. However, the impact of this on Iran’s cyber capabilities remains unclear. The Israel Defense Forces (IDF) said that it had bombed Iran’s eastern front, where several critical military and intelligence units were reportedly housed.
See also: Iranian Cyberattacks: The Threat Remains Intense
The IDF enumerated seven main services, including the headquarters of the Islamic Revolutionary Guard Corps (IRGC), the cyber-electronics and the headquarters of the Intelligence Directorate.

Neither Israel nor the United States, which are coordinating the attack on Tehran, shared further comments or details about this operation. However, the IDF released a digital depiction of the alleged complex that was attacked. The IRGC-linked cyber operatives have previously targeted the 2024 US elections, for which Washington has even issued and placed proclamations for any information regarding them.
Israel's claims that it struck Iran's cyberwar headquarters come after threat monitoring shows that Iran-aligned cyber operations are increasing in number. According to threat monitoring reports from cybersecurity firm Cyble covering the period of the conflict, the relationship between the destruction of physical infrastructure and operational cyber capability remains unclear.
See also: US-Israel and Iran exchange cyberattacks

Iran’s internet connectivity collapsed to around 1-4% of normal levels following the joint US-Israeli attacks on February 28 – a near-total nationwide outage that continued for over 120 hours. However, this outage stemmed primarily from the coordinated cyber-kinetic operation that targeted Iran’s communications infrastructure at the same time as the kinetic attacks, rather than the physical destruction of the complex housing the cyberwarfare headquarters.
Security researchers note that the degraded connectivity on the internet is likely hindering the state actors based inside Iran more than physical damage to the headquarters. The outage limits the command and control infrastructure for the Advanced Persistent Threat groups that usually operate from Iran's borders, but the pre-positioned capabilities and externally operated assets continue to function.
See also: US banks on alert for Iranian cyberattacks

When internet connectivity in Iran is restored, threat analysts expect a possible increase in state-directed cyber operations. The full impact of Israel's strike on Iran's cyber-war headquarters may not become apparent for weeks or months, as security researchers monitor whether Iran's advanced APT campaigns resume at their previous operational tempo or if the disruption causes a lasting degradation of Tehran's offensive cyber capabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
