Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI has described Emennet Pasargad as an Iran-based cyber company involved in earlier election-interference activity, and a 2025 multi-agency advisory references a later FBI notice titled “Iranian Cyber Group Emennet Pasargad Conducting Hack-and-Leak Operations Using False-Flag Personas.” That reference confirms the notice’s title, but the advisory does not provide its incident details. The documented account below therefore separates the FBI’s 2022 findings from what is—and is not—established about the later hack-and-leak warning.

What the FBI reported about Emennet Pasargad

In a January 26, 2022 public service announcement, the FBI described Emennet Pasargad, formerly Eeleyanet Gostar, as an Iran-based cyber company and summarized its historical tactics and activity. The notice said two Iranian nationals employed by the company were indicted in October 2021 for their alleged participation in a campaign intended to influence and interfere with the 2020 U.S. presidential election. It also reported that the Treasury Department designated the company and several individuals in connection with attempted election influence. Read the FBI’s January 2022 notice.

What the 2022 notice says about the 2020 election campaign

According to the FBI, beginning in August 2020, Emennet actors obtained confidential U.S. voter information from at least one state election website, sent threatening emails to intimidate voters, made a video containing disinformation about purported voting vulnerabilities, attempted unauthorized access to state voting-related websites, and accessed a U.S. media company’s network. In the voter-intimidation and disinformation activity, the actors claimed to be affiliated with the Proud Boys.

The notice also describes a separate earlier impersonation: in late 2018, the group masqueraded as the “Yemen Cyber Army” in messages critical of Saudi Arabia. These examples show why a claimed identity in an online threat or leak should not, on its own, be treated as reliable proof of who is behind it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is known about the later hack-and-leak warning

A June 30, 2025 joint advisory from CISA, the FBI, the Department of Defense Cyber Crime Center, and NSA lists a separate FBI private industry notification titled “Iranian Cyber Group Emennet Pasargad Conducting Hack-and-Leak Operations Using False-Flag Personas.” The advisory establishes that the later notice was referenced by the agencies; it does not reproduce the notice’s incidents, dates, victims, or detailed techniques. The title alone should not be taken as confirmation of particular attacks or as a complete account of the operation. Read the June 2025 joint advisory.

The FBI’s broader historical activity account

The 2022 FBI notice says Emennet’s cyber-exploitation activity dated back to 2018 and involved targets in news, shipping, travel, oil and petrochemical, financial, and telecommunications sectors in the United States, Europe, and the Middle East. The FBI described reconnaissance of businesses and websites, searches for vulnerable software and default passwords, and attempts to establish persistent access. The notice’s technical examples are historical observations, not a current vulnerability list or proof that every listed sector is under active attack today.

How Emennet differs from other Iranian-linked cases

Other public U.S. government cases involving Iranian-linked cyber activity are separate from the Emennet account. Their attribution, time periods, and evidentiary status should be kept distinct.

Account Period and activity described Source and evidentiary status
Emennet Pasargad The FBI’s 2022 notice describes alleged 2020 election interference and broader historical cyber-exploitation activity; the 2025 advisory references a later FBI PIN by title. FBI public service announcement and multi-agency advisory. The 2025 advisory does not provide incident-level details of the later PIN.
Three IRGC-linked defendants A DOJ account describes allegations of stealing non-public campaign material and trying to pass it to media members and people associated with another presidential campaign during the 2024 election cycle. DOJ announcement of an indictment; a separate case, not attributed in the cited material to Emennet. DOJ’s 2024 case announcement.
MOIS-linked domains In March 2026, DOJ said four domains were used in hacking-related psychological operations, including claims of responsibility for hacks, publication of stolen data, and threats against targeted people. DOJ account of domain seizures involving sites it linked to Iran’s Ministry of Intelligence and Security; it does not attribute those domains to Emennet. DOJ’s March 2026 announcement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Defensive steps in the FBI notice

The FBI’s 2022 recommendations are historical guidance, not a replacement for current vendor guidance, an organization’s incident-response plan, or a fresh technical assessment. The notice recommends that organizations:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Keep anti-virus and anti-malware software enabled and updated.
  • Apply patches where applicable.
  • Review security logs for signs of scanning.
  • Review the notice’s described tactics, techniques, and procedures.
  • Consider a web application firewall to help filter inbound malicious traffic.
  • Consider how information previously exfiltrated from the organization could be reused in further malicious activity.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.