/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google says Iran-backed hacking group APT42 has targeted the Trump and Biden campaigns, as well as Israeli military, government, and diplomatic organizations

APT42, which is believed to work for Iran's Revolutionary Guard Corps, targeted about a dozen people associated with both Trump …

Wired Andy Greenberg

Context & Ripple Effects

Google’s disclosure places the activity in a longer pattern of campaign-focused state-linked targeting: in 2020, its researchers reported separate China- and Iran-backed efforts aimed at the Biden and Trump campaigns, with no signs of compromise reported at the time.

The story also sits within a broader Iran-linked targeting picture rather than an isolated campaign incident. Meta subsequently identified WhatsApp accounts tied to APT42 targeting people affiliated with both administrations, extending the concern beyond formal campaign organizations.

First-order effects

  • The Trump and Biden campaigns, along with named Israeli military, government, and diplomatic organizations, must treat APT42 as an active threat actor and review exposure among targeted personnel.
  • Google’s attribution gives the affected organizations and their security partners a shared basis for threat hunting and defensive coordination around the group.

Second-order effects

  • Campaign security teams and government defenders face pressure to widen protection from official systems to the personal and third-party communication channels used by staff and affiliates, as the later WhatsApp-linked targeting indicates.
  • Public attribution by major platforms can make it harder for the same operator to reuse known infrastructure and accounts, pushing defenders toward more rapid cross-platform information sharing.

Third-order effects

  • If repeated reporting across platforms continues, political and diplomatic cybersecurity will increasingly be managed as a persistent state-espionage problem rather than a periodic election-season risk.
  • The pattern strengthens the case for platform companies, campaigns, and public institutions to formalize joint incident-response channels, though the reporting alone does not establish the scale or effectiveness of those arrangements.

The trend: State-linked cyber groups are treating political campaigns, government affiliates, and geopolitical counterparts as interconnected intelligence targets across multiple digital platforms.

Discussion

  • @ericgeller Eric Geller on x
    Google says it has thwarted Iranian government hackers' “small but steady” campaign to breach presidential campaigns, including attacks on personal accounts. Iran got into a Gmail account belonging to “a high-profile political consultant.” (Roger Stone?) https://blog.google/... […
  • @shashj Shashank Joshi on x
    “In the past six months, the U.S. and Israel accounted for roughly 60% of [IRGC] APT42's known geographic targeting, including the likes of former senior Israeli military officials and individuals affiliated with both U.S. presidential campaigns” https://blog.google/... [image]
  • @dnvolz Dustin Volz on x
    Google's security teams say they saw a hacking group linked to Iran's IRGC target in May and June the personal email accounts of “roughly a dozen individuals” affiliated with Biden and Trump, including current and former officials and campaign staffers. https://blog.google/... [i…
  • @levitt_matt Matthew Levitt on x
    You know you're doing something right when the bad guys target you. Here @google's Threat Analysis Group highlights Iranian #APT42 targeted credential phishing efforts masquerading as @WashInstitute. I'm one of the TWI researchers whose email they tried to spoof [image]
  • @a_greenberg Andy Greenberg on x
    Following news that the Trump campaign says it was hacked by Iran, Google now says one group working for Iran's Revolutionary Guard Corps has targeted both campaigns, going after a dozen individuals associated with Trump and Biden in May and June. https://www.wired.com/...
  • @shashj Shashank Joshi on x
    “APT42 masqueraded as the legitimate Washington Institute for Near East Policy [@WashInstitute] in multiple campaigns since April 2024, targeting Israeli diplomats and journalists, researchers at U.S. think tanks, and others.” https://blog.google/...
  • r/stupidpol r on reddit
    Google confirms that Iranian hackers have stepped up targeting of both US presidential campaigns.
  • r/technology r on reddit
    A Single Iranian Hacker Group Targeted Both Presidential Campaigns, Google Says