Pandorex
Security

Iran Deadline Expired: What Happened After the 8:00 PM Threat Against 18 US Tech Companies

Published Pandorex Redaktion·8 min read
—

This article is an update to our situation report from April 1, 2026 and our background article on the IRGC threat.

The Deadline

On March 31, 2026, the Islamic Revolutionary Guard Corps (IRGC) published via the semi-official Tasnim news agency a list of 18 US technology companies that would be considered "legitimate targets" starting April 1, 2026, at 8:00 PM Tehran time (6:30 PM CEST). The IRGC called the companies "key actors in terrorist operations" and demanded employees leave their workplaces immediately. Residents within a one-kilometer radius were told to evacuate.

The 18 Named Companies

Apple, Google, Meta, Microsoft, Nvidia, Intel, IBM, Dell, Cisco, HP, Oracle, Palantir, Tesla, Boeing, GE, JP Morgan, as well as two companies based in the United Arab Emirates: G42 (AI company, Abu Dhabi) and Spire Solutions (cybersecurity, Dubai).

According to the IRGC statement, the justification lies in the role of these companies in US-Israeli military operations: AI-powered targeting, cloud infrastructure for military operations, and surveillance technology. Several of the named companies — including Palantir, Microsoft, Google, IBM, and G42 — have documented ties to the Israeli military or Israeli defense companies (AP News).

What Had Already Happened Before the Deadline

The threat did not come out of nowhere. Since the war began on February 28, 2026, there had already been confirmed attacks:

  • Amazon AWS (early March): Iranian drone strikes hit two AWS data centers in the UAE and one in Bahrain. Amazon confirmed structural damage, power outages, and water damage from firefighting efforts. The data centers also host parts of US military infrastructure. (Source: AWS Health Dashboard, CNBC)
  • Stryker (March 12): The medical technology company confirmed a cyberattack that caused a "global network disruption" of its Microsoft environment. The Iran-linked hacker group Handala claimed responsibility. The group's logo appeared on Stryker login pages. (Source: CBS News, Wall Street Journal, Brian Krebs)
  • Kuwait Airport (April 1): A drone attack caused smoke above the international airport on the same day as the deadline. (Source: TIME, Reuters)

What Is Known After 8:00 PM Tehran Time

As of April 2, 2026, 1:00 AM CEST — approximately 4.5 hours after the set deadline — there are no confirmed new attacks on the 18 named tech companies. Neither CNBC, Reuters, BBC, nor Al Jazeera have reported attacks that can be clearly attributed to the deadline.

This does not mean the situation is resolved. Several scenarios are plausible:

  • Delay: Drone and cyberattacks require lead time. The deadline may have been symbolic
  • Cyberattacks already underway: Chris Krebs (former CISA Director) told CBS that Iran is running an "all-hands-on-deck" approach — all groups, whether military, intelligence, proxies, or hacktivists, are attacking
  • Negotiation pressure: The threat itself is the goal — evacuations and the cost of protective measures as an asymmetric weapon
  • Attacks were repelled: The White House stated that Iranian missile attacks had decreased by 90% and drone attacks by 83%

Context: The War

Since February 28, 2026, the US and Israel have been at war with Iran. The trigger was surprise airstrikes that killed, among others, Supreme Leader Ali Khamenei, IRGC Commander Mohammad Pakpour, and Security Chief Ali Larijani. Since then, according to Al Jazeera, at least 1,937 people have been killed in Iran and 24,800 injured. 13 US soldiers have been killed.

Iran has responded with retaliatory strikes on US military bases in the region and Israel. The threat against tech companies marks an escalation: from military targets to civilian infrastructure.

What IT Leaders Should Do Now

  • Threat Intelligence: Keep IOCs for Iranian APT groups (Charming Kitten, MuddyWater, Handala) up to date. CrowdStrike, Mandiant, and Microsoft are publishing continuous updates
  • Review cloud dependencies: Anyone using AWS, Azure, or GCP in the Gulf region should test failover scenarios. The AWS data center attacks show: physical destruction of cloud infrastructure is no longer a theoretical risk
  • Have Incident Response ready: The coming days and weeks remain critical. The deadline was possibly just the beginning
  • Do not overreact: Panic helps no one. The concrete risks for European companies are currently lower than for US firms with presence in the Gulf region. But supply chain effects (cloud outages, disrupted supply chains) can affect anyone

We will update this article as new confirmed information becomes available.

Sources: TIME, Gizmodo, CBS News, Al Jazeera, CNBC, Wall Street Journal, Reuters, AWS Health Dashboard, Tasnim News Agency. All facts cross-checked multiple times. No assumptions, no speculation about unconfirmed attacks.

Comments

Sign in to write a comment.

Swipe up
Next Article

Supply Chain Attack on GitHub: Over 300 Repositories Compromised, AI Code and Customer Environments Affected

Security