What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Microsoft says Iranian state-linked actors have increasingly paired cyber operations with influence activity to pursue political goals and make attacks seem more powerful than their technical effects may warrant. The company calls this combination “cyber-enabled influence operations.” Its published counts describe activity attributed to Iran in 2021 and 2022, while its later examples concern the Israel-Hamas conflict after October 7, 2023—not a live assessment of activity in 2026.
What Microsoft means by “cyber-enabled influence operations”
Microsoft uses the term for activity that combines offensive cyber operations with influence efforts. The cyber component may involve an intrusion or another technical action; the influence component seeks to shape how an audience interprets events. An operation can also publicize or exaggerate an attack claim to create political impact beyond what the underlying cyber activity achieved.
In a May 2, 2023 public summary, Clint Watts, general manager of Microsoft Threat Analysis Center, described Iranian actors as combining cyber operations with “multi-pronged influence operations to fuel geopolitical change in alignment with the regime’s objectives.” This is Microsoft’s characterization and attribution, not an independently established consensus finding.
How the amplification playbook works
Microsoft described a sequence in which a cyber persona claims responsibility for an attack, sometimes overstating its scale or consequences. Other apparently separate, inauthentic online personas then circulate the claim, including in the language of the intended audience. The technique makes a technical event—or even an unverified claim—look like a broader, locally voiced story.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
- Make or claim a cyber action: A group carries out an operation, or a persona says one occurred.
- Publicize and enlarge the claim: The cyber persona presents the event as evidence of a larger disruption or political message.
- Amplify it to the target audience: Apparently unconnected personas repeat the story in relevant languages. Microsoft also identified SMS messaging and impersonation of victims as amplification techniques.
These stages matter because a public claim is not proof that the stated target was compromised or that the claimed damage occurred. Microsoft’s later retrospective explicitly described examples in which public evidence did not substantiate a persona’s claim about a target or impact.
What Microsoft counted in 2021 and 2022
In its 2023 report, Microsoft attributed 24 unique Iranian-government cyber-enabled influence operations to 2022, including 17 between June and December. It had attributed seven such operations to Iran in 2021. Microsoft said the increase in coupling cyber and influence activity began in June 2022. These are the company’s historical attribution counts, not current totals or independently verified counts.
Microsoft also reported that 23% of Iran’s cyber operations were directed against Israel between October 2022 and March 2023. That figure refers to cyber operations during that six-month period; it is not the percentage of influence operations aimed at Israel.
Targets and political objectives Microsoft identified
Microsoft named Israel, Iranian opposition figures and groups, and adversaries among Gulf states as targets. It said the activity sought to advance Iranian political objectives, including:
Rank #3
- Bolstering Palestinian resistance.
- Fomenting Shi’ite unrest in Bahrain.
- Countering normalization of Arab-Israeli ties.
- Embarrassing or discrediting Iranian opposition figures.
Microsoft assessed that most of the cyber-enabled influence operations in its 2023 account were run by Emennet Pasargad, which it tracks as Cotton Sandstorm and formerly tracked as NEPTUNIUM. That assessment applies to most of the operations described; it does not establish that every operation was conclusively attributed to the group.
What Microsoft later observed around the Israel-Hamas conflict
Microsoft’s February 2024 follow-up covered activity after the conflict began on October 7, 2023. It described early Iranian-linked messaging as reactive and misleading, including the reuse of dated material and exaggeration of claimed attacks. The observations below belong to that dated retrospective and should not be read as a 2026 situation report.
Rank #4
| Microsoft’s reported observation | What the measure or example means |
|---|---|
| Ten cyber-enabled operations against Israel in October 2023, compared with a prior monthly high of six in November 2022 | Microsoft’s comparison of monthly operation counts; it noted the earlier November 2022 attacks spanned four countries. This measure is not directly comparable with the annual 2021 and 2022 totals. |
| 43% of Iranian nation-state cyber activity focused on Israel after October 7, 2023 | Microsoft said this was more activity than against the next 14 targeted countries combined. Its date range and definition differ from the 2023 report’s figures. |
| News-site traffic rose 42% in the first week of the war, then remained 28% above pre-war levels three weeks later | Microsoft measured traffic to Iranian state and state-affiliated news sites. This is a traffic measure, not evidence of how many people believed or were persuaded by the content. |
| A fake news video interrupted streaming television services in early December 2023 | Microsoft said the video featured an apparently AI-generated anchor and reached audiences in the UAE, UK, and Canada. |
The retrospective also described Iran-aligned personas claiming attacks on Israeli infrastructure and devices. Microsoft’s account cautioned that public evidence did not substantiate some claims about targets or effects. Those claims should therefore be treated as claims made by personas, not as confirmed attack outcomes.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to interpret the claims and figures
The reports are Microsoft Threat Intelligence and Microsoft Threat Analysis Center assessments. Their figures use specific periods and definitions: a count of unique influence operations, a share of cyber operations, and a share of nation-state cyber activity are different measures. They should not be combined into one trend line or treated as a current count.
Quick Recap
Best Value
- Keep attribution attached: say “Microsoft attributed” or “Microsoft reported,” rather than presenting its assessments as settled consensus.
- Separate cyber action from publicity: an online claim about an attack does not establish that the claimed intrusion or damage occurred.
- Keep dates and denominators with percentages: Microsoft’s 23% figure concerns Iran’s cyber operations from October 2022 to March 2023, while its later percentages concern different periods and measures.
- Do not infer persuasion from reach: the reported traffic increase to news sites does not show that audiences accepted the content.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

