Nation-State

Iranian Hackers Targeted WhatsApp Accounts of Staffers in Biden, Trump Administrations, Meta Says

Meta said it discovered a network of Iranian hackers, who posed as tech support agents for companies including AOL, Microsoft, Yahoo and Google.

Meta said it discovered a network of Iranian hackers, who posed as tech support agents for companies including AOL, Microsoft, Yahoo and Google.

The same Iranian hacking group believed to have targeted both the Democratic and Republican presidential campaigns tried to go after the WhatsApp accounts of staffers in the administrations of President Joe Biden and former President Donald Trump, Meta Platforms said Friday.

Meta said it discovered the network of hackers, who posed as tech support agents for companies including AOL, Microsoft, Yahoo and Google, after individuals who received the suspicious WhatsApp messages reported them. Meta’s investigators linked the activity to the same network blamed for the hacking incident reported by Trump’s campaign.

The FBI this week said a hack by Iran of the Trump campaign and an attempted breach of the Biden-Harris campaign was part of a broader Iranian effort to interfere with the U.S. presidential election.

A statement Friday from Meta, the parent of Facebook and Instagram, said that the hackers had tried to target the WhatsApp accounts of individuals in the Middle East, the United States and the United Kingdom, as well as political and diplomatic officials — including unidentified officials associated with the Trump and Biden administrations. A “small cluster” of accounts was blocked by Meta, the company said.

“We have not seen evidence of the targeted WhatsApp accounts being compromised, but out of an abundance of caution, we’re sharing our findings publicly, in addition to sharing information with law enforcement and our industry peers,” Meta said in a statement.

In a report this month, Google’s threat intelligence arm said the same Iranian group, which it linked to the country’s Revolutionary Guard, had tried to infiltrate the personal email accounts of roughly a dozen people linked to Biden and Trump since May. That report expanded on a separate study released days earlier by Microsoft that revealed suspected Iranian cyber intrusion in this year’s presidential election.

Advertisement. Scroll to continue reading.

U.S. intelligence officials say Iran’s increasingly aggressive use of cyberattacks and disinformation has several motives: to confuse and polarize voters in an effort to undermine confidence in U.S. democracy, to erode support for Israel, and to oppose candidates that it believes will increase tension between Washington and Iran.

Iran has vowed revenge against Trump, whose administration ended a nuclear deal with Iran, reimposed sanctions and ordered the killing of an Iranian Gen. Qassem Soleimani.

In July, Director of National Intelligence Avril Haines said Iran’s government gave covert support to American protests against Israel’s war against Hamas in Gaza. Groups linked to Iran posed as online activists, encouraged campus protests and provided financial support to some protest groups, Haines said.

Messages left with the Trump and Harris campaigns were not immediately returned Friday.

Related: Iran Is Accelerating Cyber Activity That Appears Meant to Influence the US Election, Microsoft Says

Related Content

ICS/OT

California Water Service says there is no indication of operational disruptions to its water and wastewater systems. 

ICS/OT

The hackers published 5GB of data, including customer personal information and credentials for the RTKBase platform.

Privacy & Compliance

The Meta-owned communications app is filing a federal court contempt order against NSO.

Nation-State

The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors.

Malware & Threats

Nimbus Manticore has continued its operations during and after the US military campaign against Iran.

Nation-State

Likely perpetrated by MuddyWater, the attack combined social engineering, persistence, credential harvesting, and data theft.

Vulnerabilities

The vulnerabilities were reported to Meta through its bug bounty program and were patched with updates released earlier this year.

Cyberwarfare

US service members received WhatsApp messages claiming they would be targeted with drones and missiles.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version