Iran combined conventional strikes with an extensive psychological and cyber campaign that targeted Gulf states, Israel and US interests. Fake alerts, threatening texts and mass hacking attempts — reportedly up to about 500,000 daily early in the conflict — disrupted banking services, forced companies to shift to remote work and prompted arrests for sharing footage. Experts say the goal was to sow fear and undermine confidence in regional stability, even as Iran’s domestic internet shutdown limited some offensive operations.
“Wait for Death”: How Iran’s Psychological And Cyber Campaign Targeted The Gulf, Israel And US Interests

Phones across the United Arab Emirates and Israel received alarming messages as kinetic strikes between Iran, Israel and the United States unfolded — but the campaign went far beyond missiles and drones. Alongside conventional attacks, Iran and Iran-linked actors mounted a coordinated psychological and cyber offensive designed to sow panic, disrupt services and damage regional confidence.
Cyber Surge And Deceptive Alerts
UAE cybersecurity chief Mohamed Al Kuwaiti told state media the country saw a sharp uptick in attacks weeks before the conflict, peaking at roughly 500,000 attempted intrusions per day from Iran-linked proxy groups targeting critical infrastructure. Many operations began as phishing and data-gathering campaigns before evolving into destructive actions.
A hoax alert purportedly from the UAE Ministry of Interior — telling residents to "report immediately in case of any security incident" — was later labeled fake by officials. In Israel, threatening texts signed by the Revolutionary Guards told recipients to “wait for death,” while other deceptive messages mimicked evacuation notices to pressure civilians near critical infrastructure in Gulf states.
Notable Disruptions And Intrusions
In early March, web-server attacks disrupted banking systems in the UAE and Bahrain, pausing transactions and routine services. Iran’s Islamic Revolutionary Guard Corps also released a list naming US tech firms and universities with regional operations — including Meta, Oracle, Nvidia, Microsoft and Google — prompting many organizations to shift staff to remote work as a precaution.
Jordan’s National Cybersecurity Center reported attempts by Iran-linked groups to tamper with storage temperatures in strategic wheat reserves, and officials across the region urged residents to change passwords after reports that hackers were trying to access CCTV and home security cameras. Analysts noted the potential for such intrusions to assist targeting or to assess damage following strikes.
“Thousands of Palestinian children died because of you. You and your family are a target for us. Wait for death.” — Text message sent to Israeli phones, signed by the Revolutionary Guards
High-Profile Leaks And Claims
Hackers claiming Iran links publicized breaches and data leaks beyond the Gulf. Reported incidents included leaked emails from the private account of a US official and intrusions affecting a major US medical device maker. Attackers also claimed responsibility for compromising the personal devices of former Israeli military chief of staff Herzi Halevi, releasing photographs and identification documents to prove the breach.
Domestic Constraints And Regional Effects
Experts note the psychological element of these operations: hackers often boasted publicly about intrusions and exaggerated impacts to amplify fear. Paradoxically, the Iranian government’s decision to restrict foreign internet services at home appears to have limited the reach and intensity of some offensive cyber operations — domestic connectivity reportedly fell to between 1% and 4% after the conflict began.
Gulf governments moved quickly to control information spread. Authorities in the UAE and Qatar arrested people for sharing videos or photography related to the conflict; residents began self-censoring and deleting posts for fear of reprisal. Journalists in the region also took extra precautions, sometimes omitting bylines or photo credits.
Expert Assessment
Analysts say Iran has long invested in asymmetric tools because it cannot defeat US and Israeli militaries conventionally. Cyber and influence operations are now integral to modern conflict, serving to amplify uncertainty, damage reputations and undermine confidence in regional authorities’ ability to protect residents and businesses.
“The primary aim of these campaigns is to diffuse fear and amplify uncertainty in the Gulf,” said Paolo Napolitano, associate director at Dragonfly from Dow Jones. Andy Piazza of Unit 42 added that while Tehran has a proven capability for complex campaigns, its initial offensive efforts were hampered by a significant drop in domestic internet connectivity.
What Residents And Organizations Did
Businesses shifted personnel to remote work, financial institutions hardened defenses, and residents were urged to update passwords and avoid sharing sensitive footage. The combined kinetic, cyber and information campaign has left lasting questions about regional resilience and the evolving role of cyber operations in statecraft.
Help us improve.

























