The broadcaster said in a statement published on Sunday that the operation involved accounts created on messaging platforms including WhatsApp and Telegram that falsely presented themselves as managers, reporters and producers working for the network.
“The main objective of these deceptive contacts is to make fraudulent interview requests or distribute malicious links designed to hack devices, steal sensitive information and conduct phishing attacks,” the statement said.
Iran International attributed the operation to hackers linked to the Islamic Revolutionary Guards Corps, describing the activity as a coordinated effort aimed at individuals who regularly interact with the network.
According to the statement, the fake accounts have contacted a range of public figures and invited them to participate in interviews or engage through links sent via messaging applications.
The broadcaster urged journalists, experts, activists and guests appearing on its programs to verify the identity of anyone claiming to represent the network before responding to messages.
It advised recipients to confirm the authenticity of contacts through official communication channels, including email addresses using the Volantmedia.net domain.
The network also warned users not to click on links sent through suspicious messages, particularly those related to unfamiliar online interview platforms, identity verification requests or file attachments.
Iran International called on anyone receiving such messages to block and report the accounts involved and to notify local security authorities of suspected phishing attempts.
The broadcaster said it condemned what it described as unlawful actions targeting the security of activists and freedom of expression.
“Security and privacy for our experts and guests remain a priority,” the statement said.
Iran International added that it would pursue technical and legal action regarding the cyber campaign through international channels.