Western intelligence warns of Iranian cyber threats targeting dissidents
The United States, the United Kingdom and the Netherlands issued a coordinated advisory warning that Iranian-linked spyware is being used to target critics of the Iranian government living in the West. Intelligence agencies identified a spyware family called CHOSEN BRICK and said Iran’s Ministry of Intelligence and Security has employed such tools in spear-phishing campaigns on messaging platforms to steal information and damage targets’ reputations.

Why It Matters
The advisories underscore a pattern of cross-border cyber operations that combine surveillance of dissidents with disruptive attacks on companies and infrastructure, highlighting ongoing risks to personal privacy and organizational resilience abroad.
Key Facts
- Issuing agencies: FBI (US), National Cyber Security Centre (UK), AIVD (Netherlands)
- Primary spyware identified: CHOSEN BRICK
- Attributed actor: Iran’s Ministry of Intelligence and Security (MOIS), according to the FBI
- Reported tactics: Spear-phishing on messaging platforms including WhatsApp and Telegram to steal emails, messages and access devices
- Notable past incidents cited: March attack that crippled Stryker’s global networks and data posted by a persona called 'Handala Hack'; alleged access to personal emails of Kash Patel; July water-systems cyberattack in Minnesota resembled Handala activity
The intelligence services of the United States, the United Kingdom and the Netherlands issued a joint warning that Iranian state-linked cyber operations are being used to target critics of the Iranian government living in Western countries. The FBI, Britain’s NCSC and the Netherlands’ AIVD released coordinated advisories saying the campaign is "almost certainly" aimed at collecting information on opponents of the regime.
Britain’s NCSC director Paul Chichester pointed to a spyware family known as CHOSEN BRICK, which is reportedly deployed to exfiltrate sensitive information. According to the advisory, these tools have been used in spear-phishing campaigns delivered via messaging platforms such as WhatsApp and Telegram to steal emails and messages and to gain access to devices.
The FBI said the Iranian Ministry of Intelligence and Security has used the malware to gather intelligence, publish data leaks and inflict reputational harm on intended targets. The recent bulletin follows earlier warnings: in March the FBI described alleged MOIS activity that collected data later posted online by a persona called 'Handala Hack.' That March incident was also linked to an attack that disrupted the global networks of medical device maker Stryker, with an Iran-linked group claiming responsibility.
U.S. officials have continued to connect similar events to the same actors; the Handala persona has claimed to have published material taken from personal accounts, and in July a cyberattack on water systems in Minnesota was said to resemble the Handala operation. The agencies’ joint advisories emphasize a recurring pattern of surveillance and disruptive cyber activity directed at critics and organizations outside Iran.
Keep Reading

AI agents now have a place to snitch

SpaceX will try to put Starship in orbit for the first time on September 22

The AI graveyard: a running list of projects and startups that didn’t make it
