110 Organizations Hit by 149 Retaliatory DDoS Attacks Following Iran Strikes
Mar 4, 2026 // 21:10 - Tristan Wall


Cybersecurity researchers from Radware and Orange Cyberdefense reported a massive surge in retaliatory hacktivist activity. Between February 28 and March 2, 2026, a total of 149 hacktivist DDoS claims were recorded, targeting 110 distinct organizations across 16 countries. 

The attacks followed a major military escalation in the Middle East, specifically the U.S.-Israel joint strikes on Iran known as Operation Epic Fury (U.S.) and Operation Roaring Lion (Israel). 

Key Findings of the Hacktivist Surge

  • Highly Lopsided Threat: A small number of groups were responsible for the vast majority of the disruption. Three groups—Keymous+, DieNet, and NoName057(16)—accounted for 74.6% of all recorded global activity.
  • Sector Targets: Attackers prioritized critical infrastructure. Nearly 47.8% of all targeted organizations globally belonged to the government sector, followed by finance (11.9%) and telecommunications (6.7%).
  • Geographic Focus: While attacks spanned 16 countries, the majority (107 attacks) were concentrated in the Middle East, specifically targeting Kuwait, Israel, and Jordan. Europe was also heavily affected, receiving 22.8% of the total global activity.
  • Emerging Groups: The first attack in this wave was launched on February 28 by Hider Nex (also known as Tunisian Maskers Cyber Force), a group that emerged in mid-2025 and utilizes a “hack-and-leak” strategy. 

Regional Theater Differences

  • Middle East: Characterized by a “consolidated offensive” where Keymous+ and DieNet drove nearly 70% of the activity, focusing on government institutions.
  • Europe: Dominated by the pro-Russian group NoName057(16), which was responsible for over 73% of European claims. Denmark was the most targeted country in this region, followed by Germany and Spain. 

Strategic Context

According to CloudSek and Sophos, this wave of cyber warfare marks a “hybrid phase” of the conflict. Beyond DDoS attacks, researchers observed AI-enhanced phishing, website defacements, and wiper malware deployment. Palo Alto Networks (Unit 42) noted the formation of an “Electronic Operations Room” on February 28 to coordinate these diverse retaliatory efforts.

#110  #149  #attacks  #ddos  #following  #hit  #iran  #news  #organizations  #retaliatory  #strikes   —   News