InfoGuard Cyber Security and Cyber Defence Blog

InfoGuard Threat Intelligence Report Q3/26: Europe's Cyber Risk, Iran's Impact on Operational Technology, and AI-Powered Attacks

Written by Mathias Fuchs | 21 Sep 2026

Compared to the report on the second quarter of 2026, the geopolitical cyber landscape has become significantly clearer in the third quarter. What was still described in Q2/26 as a risk of escalation and geographic expansion is now evident in confirmed incidents with physical consequences and official attributions.

The reporting period for Q3/26 makes this development tangible: Actors attributed to Iran caused destructive effects on European energy infrastructure for the first time. China is largely expanding its pre-positioned access points (pre-positioning campaigns) in Northern Europe, while Russia is operating below the escalation threshold with official attribution and parallel hybrid sabotage. AI-powered attack chains are widening the detection gap.

How Europe’s Cyber Risk has Changed since Q2/26

This overview shows the changes at a glance and highlights what they mean for cyber defense. We then delve deeper into the key developments and derive concrete priorities for action.

Topic

Q2/2026 Status

Q3/2026 Update

Threat Level

Iran

  • Iran back online as of April 17 (47 days of isolation).

  • Coordinated APT operations possible.

  • OT shift to Rockwell FactoryTalk.

  • RedKitten active.

  • First confirmed OT impact in Europe: Iran-linked shutdown of a small British power plant (4 days).
  • Expanded infrastructure in the UK/Europe (Tortoiseshell).
  • Continued focus on OT (Rockwell, Siemens, Schneider).

🔴 Critical — destructive escalation in Europe

China

  • Salt Typhoon officially detected in Scandinavia (Norway) for the first time.
  • ODNI: Pre-positioning.

  • Ongoing activity in European telecom networks.
  • New Initial Access clusters (Sylvanite) for Voltzite/Volt-Typhoon-like operations.

  • Living-off-the-land (LOTL) and edge device abuse remain central.

🟠 High — persistent and geographically established

Russia

  • Poland, Dec. 2025: first confirmed destructive OT incident in the EU.
  • Below-threshold strategy.
  • Official EU/UK attribution of the Poland attack to FSB Center 16.
  • Further edge device and OT campaigns.
  • Hybrid sabotage (physical + cyber) is on the rise.

🟠 High — Below-threshold attacks have become normalized and are being attributed

AI attacks / automation

  • Fully autonomous, agent-based AI systems are operational.

  • 90% intrusion automation by nation-states.

  • Remains an operational reality.

  • AI-assisted reconnaissance, exploit generation, and lateral movement documented.

  • Asymmetry: Human-in-the-loop remains central.

🔴 Critical — qualitatively established

U.S. (alliance context)

  • CYBERCOM 2.0.
  • Offensive permanent presence.

  • CLOUD Act unresolved.

⚪ Not hostile — prioritizing our own interests

Table 1: Changes in escalation areas compared to Q2/26

 

When applied to one’s own cyber defense, this raises the question of which of these developments are actually relevant to one’s own organization. Cyber Threat Intelligence provides the necessary context to classify current threats, assess one’s own risk exposure more precisely, and prioritize security measures accordingly.

1. Iran: From “Reconnection” to Destructive OT Impact in Europe

In the Q2 report, we used the term “reconnection” to describe the renewed and intensified cyberactivity of actors attributed to Iran following a period of reduced activity. In the third quarter, this trend intensified further: for the first time, a cyberattack attributed to these actors in Europe led to a physical operational disruption. The incident demonstrates that exposed OT access points at energy utilities and industrial facilities are increasingly coming under scrutiny.

1.1 What does the First confirmed OT Impact Mean for Europe?

In July 2026, Iran-linked actors forced a four-day shutdown of a small British energy producer. British authorities saw no threat to the national grid and did not name the location for security reasons. The attribution is based on press reports and intelligence-backed assessments; technical details are not currently available. Nevertheless, the incident marks a qualitative threshold: Following the reconnection in April and the focus on Rockwell FactoryTalk documented in Q2/26, a cyberattack led to a physical operational disruption in European energy infrastructure for the first time.

The parallels to Iranian OT campaigns against U.S. water and wastewater systems (multiple states, July/August) and the continued exploitation of internet-exposed PLCs from Rockwell, Siemens, and Schneider reveal a clear pattern. Iranian actors are systematically searching for poorly secured OT access points—regardless of whether they are pursuing geopolitical or opportunistic goals.

1.2 What does Tortoiseshell’s Infrastructure Expansion in Europe Reveal?

In August 2026, Group-IB and other analysts identified new server and domain infrastructure belonging to the Iran-affiliated actor Tortoiseshell, also known as UNC1549 or Tortoise Shell, including hosting infrastructure in the United Kingdom. This geographic expansion into Europe is no coincidence and follows the pattern of opportunistic and targeted secondary attacks that had already emerged in Q1/26 and Q2/26.

The group has been attacking targets in the defense, aerospace, and technology and military-related sectors for years and ranks among the most prolific Iranian APTs in 2026. At the same time, the intermingling of state-sponsored APT operations, proxy groups, and hacktivist personas such as Handala deliberately complicates attribution.

Assessment of the Cyber Situation with Iran, Q3/26

Iran’s reconnection did not signal an all-clear. It marked the start of a more dangerous phase. The incident at the British power plant shows that a cyberattack can cause a physical operational disruption in Europe’s energy infrastructure. Organizations in the energy, water, industrial, and critical infrastructure sectors should make it a priority to reassess their exposure to internet-facing PLCs, remote access solutions, and OT systems and platforms from Rockwell FactoryTalk, Siemens, and Schneider. Default credentials, lack of MFA, and unsegmented OT networks remain the most common points of entry.

2. China: Salt Typhoon and Volt Typhoon remain Active

Chinese actors continue to expand their long-term presence in European networks. In Q3/26, evidence of ongoing activity in telecommunications networks and new initial-access clusters—that is, groups or infrastructures used to gain initial access to target environments—has intensified. This includes Sylvanite as a potential access provider for Voltzite- and Volt Typhoon-like operations. Meanwhile, the methodology remains unchanged: Living-off-the-Land (LOTL), compromise of edge devices (firewalls, VPN concentrators, routers), SOHO devices as relays, and long-term persistence without conspicuous malware.

The strategic goal remains pre-positioning and “Signals Intelligence (SIGINT)” collection. European infrastructure continues to serve as a lever and observation post. The detection gap regarding LOTL and inadequately monitored perimeter devices persists.

Assessment of the Cyber Situation with China, Q3/26

The question is no longer whether Chinese actors are present in European networks, but whether and where their presence has already been detected. Telecommunications, energy, and defense companies, as well as organizations with critical network devices at the perimeter, should systematically search for anomalies in authentication, configuration changes, and unusual administrative access—regardless of traditional “Indicators of Compromise (IOC)” matches.

3. Russia: Below-Threshold Warfare takes Hold

In July 2026, the EU and the United Kingdom formally attributed the December 2025 attack on Poland’s energy infrastructure to the FSB’s Center 16. Sanctions were imposed concurrently. The incident resulted in permanent damage to control systems and industrial equipment. The attribution confirms Russia’s strategy: to cause maximum physical damage without crossing the Article 5 threshold and thereby triggering a collective military response. It remains the clearest European example to date of Russia’s below-threshold warfare.

Further developments in Q3/26 underscore this continuity: edge-device campaigns target critical infrastructure in the energy and telecommunications sectors, as well as managed service providers (MSPs). Pro-Russian hacktivist groups exploit OT access points and are capable of causing physical damage. At the same time, hybrid activities are on the rise, including sabotage, GNSS jamming, and physical attacks on infrastructure and defense contractors. The “test—escalate—freeze—repeat” pattern is well established.

Assessment of the Cyber Situation with Russia, Q3/26

Below-threshold activity is not a transitional phase, but the new normal. Energy providers, infrastructure operators, and government agencies must treat OT systems as targets for espionage and as potential entry points for physical sabotage. The Polish attribution does not change the operational reality—it officially confirms it.

4. AI and Automation are Exacerbating the Asymmetry in Cyber Defence

Autonomous and highly automated attack chains remain operational. Reports of AI-assisted reconnaissance, iterative exploit and malware generation (“vibe coding”), and multi-agent coordination confirm the trend we described in Q2/26. Nation-state actors are automating large parts of the intrusion lifecycle; criminal actors are following suit with AI-powered negotiation and ransomware systems.

The fundamental asymmetry persists: a failed attack costs attackers very little. An undetected attack or a false negative, however, can have serious consequences for the defense.

That is why human-in-the-loop —experienced analysts and threat hunters who contextualize events and test hypotheses—remains indispensable. Automation on the defensive side is necessary, but it does not replace human judgment.

5. Exposure Deficit: Why State-Sponsored Cyberattacks go Undetected

State-sponsored compromises often go unnoticed because LOTL, cloud-based dead-drop architectures, and autonomous attack chains further complicate signature-based and purely behavior-based detection. Q3/26 thus confirms the key finding from Q1/26 and Q2/26: A significant proportion only becomes apparent through external clues, serendipitous discoveries, or subsequent forensic analysis.

Added to this is risk exposure: OT components exposed to the internet, inadequately hardened edge devices, a lack of segmentation, and unclear dependencies create the conditions under which attacks can be prepared and concealed.

Proactive threat hunting and a systematic assessment of risk exposure (through compromise assessment and exposure management) remain the most effective ways to gain clarity before the next visible incident occurs.

Conclusion: Intensifying cyber risks demand visibility

Q3/26 does not represent a new escalation level in the sense of a major “bang,” but rather the intensification of what was set in motion in Q1/26 and Q2/26. Iran has demonstrated destructive OT capabilities in Europe. China remains a persistent presence. Russia has been officially attributed with the attack on Poland’s energy infrastructure and continues to employ the below-threshold model. AI-enabled and autonomous attacks are operational. The detection and exposure gap persists and is widening.

For European organizations, this does not call for new alarmist rhetoric, but rather the consistent continuation of the approach outlined in previous reports: Early detection of real risk exposure, proactive threat hunting by experienced incident responders, and the reduction of attack surfaces—particularly at the perimeter and in OT environments—are critical to an organization’s ability to respond effectively.

Whether there are already signs of a compromise and which exposures increase the actual risk can only be determined when threat hunting and managed risk exposure are considered together. Insights from threat intelligence, incident response, and the last three quarters provide the technical foundation for this.

Apply these insights to your own threat landscape. InfoGuard supports you in uncovering suspicious traces, assessing risks, and taking targeted action. Talk to our Threat Intelligence Team.

Did you enjoy reading this? Did you enjoy reading this? Then subscribe to our blog updates now and receive the next Threat Intelligence Report directly in your inbox—concise and featuring the most important developments in the cyber threat landscape.

 

Sources & References
Coverage of the Iran-linked UK power plant shutdown (August 2026)
Group-IB on the Tortoiseshell infrastructure expansion
Dragos / Cybersecurity Dive on the Sylvanite, Voltzite, and OT-Access groups
EU/UK attribution and sanctions regarding FSB Center 16 / Poland energy attack (July 2026)
Atlantic Council
CERT-EU Cyber Briefs
Bitkom Study on Intelligence-Driven Attacks on German Companies
• Previous InfoGuard Threat Intelligence Reports for Q1/26 and Q2/26

 

Caption: AI-generated image