The situation has escalated since our last report on the IRGC threat. The Islamic Revolutionary Guard Corps (IRGC) has set a specific deadline: starting at 8:00 PM Tehran time on April 1, 2026 (6:30 PM CEST), it intends to carry out attacks on US technology companies and their infrastructure in the Gulf region. CNBC, Reuters, and Gizmodo have independently confirmed the threat.
What We Know
- 18 named targets: Apple, Google, Microsoft, Nvidia, Boeing, Tesla, and 12 other companies with presence in the Gulf region
- Justification: Retaliation for "further assassinations" in the context of the Iran-Israel-USA conflict
- Attack types (announced): Physical attacks on data centers, offices, and technology infrastructure. Implicitly: also cyberattacks
- Affected region: Primarily UAE, Saudi Arabia, Bahrain, Qatar
Assessment: How Serious Is the Situation?
The threat is unusually specific. Normally, Iran does not name individual companies. The naming of tech companies with data centers in the region (Azure UAE, Google Doha, AWS Bahrain) suggests that Iran views this infrastructure as strategically valuable and therefore as leverage.
Whether physical attacks will occur is unclear. Historically, Iran has used threats as political signals without direct implementation. However, the escalation dynamics in 2026 have reached a new level: the IRGC has significantly intensified drone attacks on ships in the Strait of Hormuz in recent months.
What is certain: the cyber component. Iranian APT groups (APT33/Elfin, APT35/Charming Kitten, MuddyWater) are among the most active state-sponsored cyber actors worldwide. Physical escalation is almost always accompanied by cyber operations.
What IT Leaders in Europe Should Do Now
- Check cloud regions: Do you have workloads in Azure UAE, Google Qatar/Saudi, AWS Bahrain? If so: check failover readiness. Can workloads be switched to European regions on short notice?
- Update threat intelligence: Load IOCs for Iranian APT groups into SIEM rules. CrowdStrike, Mandiant, and Microsoft regularly publish updated indicators.
- Tighten VPN/firewall rules: Monitor traffic from Iranian IP ranges (if not already blocked) and known TOR exit nodes.
- Inform incident response team: The IR team should be reachable this evening. Not because an attack is certain, but because preparation is free and response is expensive.
- Prepare communications: If a cloud provider reports disruptions: who communicates internally? Who to customers? Prepare templates.
What We Do Not Know
Whether the threat will be carried out. Whether cyberattacks will occur separately or concurrently. Whether European infrastructure could be directly affected (rather unlikely, but not ruled out for cyber operations). And whether the deadline is an ultimate signal or a negotiation tactic.
We will update this article as developments unfold.
Sources: CNBC, Reuters, Gizmodo, Defence Security Asia. As of: April 1, 2026, 7:00 PM CEST.