InfoGuard AG (Headquarter)
Lindenstrasse 10
6340 Baar
Switzerland
InfoGuard AG
Stauffacherstrasse 141
3014 Bern
Switzerland
InfoGuard Deutschland GmbH
Frankfurter Straße 233
63263 Neu-Isenburg
Germany
InfoGuard Deutschland GmbH
Landsberger Straße 302
80687 Munich
Germany
InfoGuard Deutschland GmbH
Am Gierath 20A
40885 Ratingen
Germany
InfoGuard GmbH
Kohlmarkt 8-10
1010 Vienna
Austria
Compared to the report on the second quarter of 2026, the geopolitical cyber landscape has become significantly clearer in the third quarter. What was still described in Q2/26 as a risk of escalation and geographic expansion is now evident in confirmed incidents with physical consequences and official attributions.
The reporting period for Q3/26 makes this development tangible: Actors attributed to Iran caused destructive effects on European energy infrastructure for the first time. China is largely expanding its pre-positioned access points (pre-positioning campaigns) in Northern Europe, while Russia is operating below the escalation threshold with official attribution and parallel hybrid sabotage. AI-powered attack chains are widening the detection gap.
This overview shows the changes at a glance and highlights what they mean for cyber defense. We then delve deeper into the key developments and derive concrete priorities for action.
|
Topic |
Q2/2026 Status |
Q3/2026 Update |
Threat Level |
|
Iran |
|
|
🔴 Critical — destructive escalation in Europe |
|
China |
|
|
🟠 High — persistent and geographically established |
|
Russia |
|
|
🟠 High — Below-threshold attacks have become normalized and are being attributed |
|
AI attacks / automation |
|
|
🔴 Critical — qualitatively established |
|
U.S. (alliance context) |
|
|
⚪ Not hostile — prioritizing our own interests |
Table 1: Changes in escalation areas compared to Q2/26
When applied to one’s own cyber defense, this raises the question of which of these developments are actually relevant to one’s own organization. Cyber Threat Intelligence provides the necessary context to classify current threats, assess one’s own risk exposure more precisely, and prioritize security measures accordingly.
In the Q2 report, we used the term “reconnection” to describe the renewed and intensified cyberactivity of actors attributed to Iran following a period of reduced activity. In the third quarter, this trend intensified further: for the first time, a cyberattack attributed to these actors in Europe led to a physical operational disruption. The incident demonstrates that exposed OT access points at energy utilities and industrial facilities are increasingly coming under scrutiny.
In July 2026, Iran-linked actors forced a four-day shutdown of a small British energy producer. British authorities saw no threat to the national grid and did not name the location for security reasons. The attribution is based on press reports and intelligence-backed assessments; technical details are not currently available. Nevertheless, the incident marks a qualitative threshold: Following the reconnection in April and the focus on Rockwell FactoryTalk documented in Q2/26, a cyberattack led to a physical operational disruption in European energy infrastructure for the first time.
The parallels to Iranian OT campaigns against U.S. water and wastewater systems (multiple states, July/August) and the continued exploitation of internet-exposed PLCs from Rockwell, Siemens, and Schneider reveal a clear pattern. Iranian actors are systematically searching for poorly secured OT access points—regardless of whether they are pursuing geopolitical or opportunistic goals.
In August 2026, Group-IB and other analysts identified new server and domain infrastructure belonging to the Iran-affiliated actor Tortoiseshell, also known as UNC1549 or Tortoise Shell, including hosting infrastructure in the United Kingdom. This geographic expansion into Europe is no coincidence and follows the pattern of opportunistic and targeted secondary attacks that had already emerged in Q1/26 and Q2/26.
The group has been attacking targets in the defense, aerospace, and technology and military-related sectors for years and ranks among the most prolific Iranian APTs in 2026. At the same time, the intermingling of state-sponsored APT operations, proxy groups, and hacktivist personas such as Handala deliberately complicates attribution.
Assessment of the Cyber Situation with Iran, Q3/26
Iran’s reconnection did not signal an all-clear. It marked the start of a more dangerous phase. The incident at the British power plant shows that a cyberattack can cause a physical operational disruption in Europe’s energy infrastructure. Organizations in the energy, water, industrial, and critical infrastructure sectors should make it a priority to reassess their exposure to internet-facing PLCs, remote access solutions, and OT systems and platforms from Rockwell FactoryTalk, Siemens, and Schneider. Default credentials, lack of MFA, and unsegmented OT networks remain the most common points of entry.
Chinese actors continue to expand their long-term presence in European networks. In Q3/26, evidence of ongoing activity in telecommunications networks and new initial-access clusters—that is, groups or infrastructures used to gain initial access to target environments—has intensified. This includes Sylvanite as a potential access provider for Voltzite- and Volt Typhoon-like operations. Meanwhile, the methodology remains unchanged: Living-off-the-Land (LOTL), compromise of edge devices (firewalls, VPN concentrators, routers), SOHO devices as relays, and long-term persistence without conspicuous malware.
The strategic goal remains pre-positioning and “Signals Intelligence (SIGINT)” collection. European infrastructure continues to serve as a lever and observation post. The detection gap regarding LOTL and inadequately monitored perimeter devices persists.
Assessment of the Cyber Situation with China, Q3/26
The question is no longer whether Chinese actors are present in European networks, but whether and where their presence has already been detected. Telecommunications, energy, and defense companies, as well as organizations with critical network devices at the perimeter, should systematically search for anomalies in authentication, configuration changes, and unusual administrative access—regardless of traditional “Indicators of Compromise (IOC)” matches.
In July 2026, the EU and the United Kingdom formally attributed the December 2025 attack on Poland’s energy infrastructure to the FSB’s Center 16. Sanctions were imposed concurrently. The incident resulted in permanent damage to control systems and industrial equipment. The attribution confirms Russia’s strategy: to cause maximum physical damage without crossing the Article 5 threshold and thereby triggering a collective military response. It remains the clearest European example to date of Russia’s below-threshold warfare.
Further developments in Q3/26 underscore this continuity: edge-device campaigns target critical infrastructure in the energy and telecommunications sectors, as well as managed service providers (MSPs). Pro-Russian hacktivist groups exploit OT access points and are capable of causing physical damage. At the same time, hybrid activities are on the rise, including sabotage, GNSS jamming, and physical attacks on infrastructure and defense contractors. The “test—escalate—freeze—repeat” pattern is well established.
Assessment of the Cyber Situation with Russia, Q3/26
Below-threshold activity is not a transitional phase, but the new normal. Energy providers, infrastructure operators, and government agencies must treat OT systems as targets for espionage and as potential entry points for physical sabotage. The Polish attribution does not change the operational reality—it officially confirms it.
Autonomous and highly automated attack chains remain operational. Reports of AI-assisted reconnaissance, iterative exploit and malware generation (“vibe coding”), and multi-agent coordination confirm the trend we described in Q2/26. Nation-state actors are automating large parts of the intrusion lifecycle; criminal actors are following suit with AI-powered negotiation and ransomware systems.
The fundamental asymmetry persists: a failed attack costs attackers very little. An undetected attack or a false negative, however, can have serious consequences for the defense.
That is why “human-in-the-loop” —experienced analysts and threat hunters who contextualize events and test hypotheses—remains indispensable. Automation on the defensive side is necessary, but it does not replace human judgment.
State-sponsored compromises often go unnoticed because LOTL, cloud-based dead-drop architectures, and autonomous attack chains further complicate signature-based and purely behavior-based detection. Q3/26 thus confirms the key finding from Q1/26 and Q2/26: A significant proportion only becomes apparent through external clues, serendipitous discoveries, or subsequent forensic analysis.
Added to this is risk exposure: OT components exposed to the internet, inadequately hardened edge devices, a lack of segmentation, and unclear dependencies create the conditions under which attacks can be prepared and concealed.
Proactive threat hunting and a systematic assessment of risk exposure (through compromise assessment and exposure management) remain the most effective ways to gain clarity before the next visible incident occurs.
Q3/26 does not represent a new escalation level in the sense of a major “bang,” but rather the intensification of what was set in motion in Q1/26 and Q2/26. Iran has demonstrated destructive OT capabilities in Europe. China remains a persistent presence. Russia has been officially attributed with the attack on Poland’s energy infrastructure and continues to employ the below-threshold model. AI-enabled and autonomous attacks are operational. The detection and exposure gap persists and is widening.
For European organizations, this does not call for new alarmist rhetoric, but rather the consistent continuation of the approach outlined in previous reports: Early detection of real risk exposure, proactive threat hunting by experienced incident responders, and the reduction of attack surfaces—particularly at the perimeter and in OT environments—are critical to an organization’s ability to respond effectively.
Whether there are already signs of a compromise and which exposures increase the actual risk can only be determined when threat hunting and managed risk exposure are considered together. Insights from threat intelligence, incident response, and the last three quarters provide the technical foundation for this.
Apply these insights to your own threat landscape. InfoGuard supports you in uncovering suspicious traces, assessing risks, and taking targeted action. Talk to our Threat Intelligence Team.
Did you enjoy reading this? Did you enjoy reading this? Then subscribe to our blog updates now and receive the next Threat Intelligence Report directly in your inbox—concise and featuring the most important developments in the cyber threat landscape.
Sources & References
• Coverage of the Iran-linked UK power plant shutdown (August 2026)
• Group-IB on the Tortoiseshell infrastructure expansion
• Dragos / Cybersecurity Dive on the Sylvanite, Voltzite, and OT-Access groups
• EU/UK attribution and sanctions regarding FSB Center 16 / Poland energy attack (July 2026)
• Atlantic Council
• CERT-EU Cyber Briefs
• Bitkom Study on Intelligence-Driven Attacks on German Companies
• Previous InfoGuard Threat Intelligence Reports for Q1/26 and Q2/26
Caption: AI-generated image