NEWSAR
Multi-perspective news intelligence
SRCAl Jazeera
LANGEN
LEANCenter
WORDS276
ENT12
TUE · 2026-09-15 · 20:16 GMTBRIEF NSR-2026-0915-111535
News/Western intelligence warns of Iranian cyber threats targetin…
NSR-2026-0915-111535News Report·EN·National Security

Western intelligence warns of Iranian cyber threats targeting dissidents

Western intelligence agencies from the United States, United Kingdom, and Netherlands have issued a joint warning about Iranian cyber threats targeting dissidents abroad. These agencies, including the FBI, Britain's NCSC, and the Netherlands' AIVD, state that Iran is "almost certainly" using cyber operations to repress critics of its regime.

By News AgenciesAl JazeeraFiled 2026-09-15 · 20:16 GMTLean · CenterRead · 2 min
Western intelligence warns of Iranian cyber threats targeting dissidents
Al JazeeraFIG 01
Reading time
2min
Word count
276words
Sources cited
3cited
Entities identified
12entities
Quality score
100%
§ 01

Briefing Summary

AI-generated
NEWSAR · AI

Western intelligence agencies from the United States, United Kingdom, and Netherlands have issued a joint warning about Iranian cyber threats targeting dissidents abroad. These agencies, including the FBI, Britain's NCSC, and the Netherlands' AIVD, state that Iran is "almost certainly" using cyber operations to repress critics of its regime. A spyware family known as "CHOSEN BRICK" is allegedly employed by Iranian state-linked actors to steal sensitive information, such as emails and messages, through spear-phishing campaigns on platforms like WhatsApp and Telegram. The FBI attributes these malware activities to Iran's Ministry of Intelligence and Security (MOIS), aiming to collect intelligence, conduct data leaks, and cause reputational harm to targets. This warning follows previous advisories regarding Iran's efforts to target dissidents and includes a March incident where MOIS allegedly used similar malware, with an Iran-linked group claiming responsibility for a cyberattack on medical device company Stryker.

Confidence 0.90Sources 3Claims 5Entities 12
§ 02

Article analysis

Model · rule-based
Framing
National Security
Human Rights
Tone
Mixed Tone
AI-assessed
CalmNeutralAlarmist
Factuality
0.80 / 1.00
Factual
LowHigh
Sources cited
3
Well sourced
FewMany
§ 03

Key claims

5 extracted
01

Iran ruthlessly uses digital surveillance to repress critics of the regime.

quotePaul Chichester (NCSC Director)
Confidence
0.90
02

Western intelligence agencies warn of Iranian cyber threats targeting dissidents abroad.

factualUnited States, United Kingdom, and Netherlands intelligence agencies
Confidence
0.90
03

Iran's Ministry of Intelligence and Security (MOIS) uses malware to collect intelligence, conduct data leaks, and inflict reputational harm.

factualFBI
Confidence
0.85
04

Iranian spyware, known as ‘CHOSEN BRICK’, is allegedly used to steal sensitive information through spear-phishing campaigns.

factualPaul Chichester (NCSC Director)
Confidence
0.85
05

An Iran-linked hacking group claimed responsibility for an attack that crippled Stryker's global networks.

factualArticle
Confidence
0.70
§ 04

Full report

2 min read · 276 words
Western intelligence warns of Iranian cyber threats targeting dissidentsWestern intelligence agencies highlight ‘CHOSEN BRICK’ spyware targeting critics of Iran government abroad.The United States, the United Kingdom and the Netherlands have warned that Iranian spyware is being used to hunt dissidents living in the West.Iran is “almost certainly” using cyber operations to target Iranian critics of the regime, intelligence agencies from the trio of countries cautioned on Tuesday.In coordinated advisories, the FBI in the US, Britain’s National Cyber Security Centre (NCSC) and the NetherlandsAIVD intelligence service all repeated the same warning.“The details of this cyber ⁠campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” said Paul Chichester, the director of Britain’s NCSC.Chichester highlighted a spyware family known as “CHOSEN BRICK” that is allegedly used by Iranian state-linked cyber actors to steal sensitive information through “spear-phishing” campaigns on messaging platforms including WhatsApp and Telegram.The FBI said that Iran’s Ministry of Intelligence and Security (MOIS) was using the malware to “collect intelligence, conduct data leaks, and inflict reputational harm against their intended targets”.The advice is a continuation of regular warnings issued by Western intelligence over Iran’s efforts to target dissidents abroad.In a warning issued in March, the FBI had described alleged MOIS efforts to use the malware to collect data on targets that was then posted online by a persona known as “Handala Hack.”That attack in March crippled the global networks of Stryker, one of the world’s largest medical device companies, with an Iran-linked hacking group claiming responsibility and warning it marked “the beginning of a new chapter in cyber warfare”.
§ 05

Entities

12 identified
§ 06

Keywords & salience

8 terms
iranian cyber threats
1.00
dissidents
0.90
chosen brick spyware
0.80
digital surveillance
0.70
spear-phishing
0.60
ministry of intelligence and security
0.50
cyber warfare
0.40
western intelligence
0.40
§ 07

Topic connections

Interactive graph
Network visualization showing 51 related topics
View Full Graph
Person Organization Location Event|Click node to navigate|Edge numbers = shared articles