**Title: Western Intelligence Issues Warning on Iranian Cyber Threats Targeting Dissidents**
**Date: September 15, 2026**
In a coordinated effort, intelligence agencies from the United States, the United Kingdom, and the Netherlands have issued a stark warning regarding the use of Iranian spyware to target dissidents residing in Western countries. The advisory highlights an ongoing cyber campaign by Iran aimed at repressing critics of the regime through digital surveillance tactics.
The warning was disseminated on Tuesday, with the FBI, the UK's National Cyber Security Centre (NCSC), and the Netherlands’ AIVD intelligence service all emphasizing the seriousness of the threat. According to these agencies, Iran is "almost certainly" employing cyber operations to hunt down Iranian dissidents and critics living abroad.
Paul Chichester, the director of the NCSC, stated, “The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices.” He specifically pointed to a spyware family known as "CHOSEN BRICK," which is reportedly utilized by Iranian state-linked cyber actors to extract sensitive information through "spear-phishing" campaigns on popular messaging platforms such as WhatsApp and Telegram.
The FBI further elaborated on the activities of Iran’s Ministry of Intelligence and Security (MOIS), indicating that the agency is using this malware to gather intelligence, execute data leaks, and inflict reputational damage on its targets. This warning is part of a broader pattern of alerts from Western intelligence agencies regarding Iran's efforts to undermine dissidents and critics outside its borders.
This latest advisory follows a previous warning issued by the FBI in March, which detailed the MOIS's attempts to leverage similar malware to collect sensitive data on targeted individuals. This data was then disseminated online by a persona known as "Handala Hack." That incident in March was notably linked to a significant cyberattack that disrupted the global networks of Stryker, a leading medical device company. The Iranian-linked hacking group responsible for that attack claimed it represented "the beginning of a new chapter in cyber warfare."
The so-called Handala hackers have also been implicated in gaining unauthorized access to the personal emails of high-profile individuals, including Kash Patel, the director of the FBI. They reportedly shared photographs and documents from his official email account, raising concerns about the security of sensitive information.
In July, U.S. officials noted that a cyberattack targeting water systems in Minnesota bore similarities to the Handala Hack, further underscoring the potential risks posed by Iranian cyber operations. The increasing frequency and sophistication of these attacks have prompted Western intelligence agencies to remain vigilant and proactive in warning potential targets.
As the geopolitical landscape continues to evolve, the implications of these cyber threats extend beyond individual dissidents to broader international relations. The use of cyber capabilities by state actors like Iran raises significant concerns about privacy, security, and the protection of human rights for individuals who oppose authoritarian regimes.
The warnings from Western intelligence agencies serve as a critical reminder of the ongoing challenges posed by cyber warfare and the need for enhanced cybersecurity measures to protect vulnerable populations from state-sponsored digital threats. As the situation develops, the international community will be closely monitoring Iran's cyber activities and their impact on global security.