Middle EastThe invisible war: Iran's evolving cyberattacks bring battlefront to small-town America
Notably, a war that began with airstrikes over Iran is now being felt in places far from the Middle East.
Notably, a war that began with airstrikes over Iran is now being felt in places far from the Middle East.
Article outline
- What happened
- The key numbers
- Why it matters
- Official response
- Background
- The bottom line
Key points
- US authorities attributed the attack to Iran and rolled out counter cyberoperations.Between 2013 and 2017, Iran-based Mabna Institute targeted computer systems of 144 American universities and 42 private sector firms.
- Then came the Minnesota incidents.Over 30 community water systems were targeted on July 26 and 27.
- More than 30 community water systems were targeted on July 26 and 27.
- On February 28, the US and Israel unleashed Operation Roaring Lion.
- US authorities have not conclusively attributed the attacks to Tehran, but Iranian-linked actors are among the suspects.CyberAv3ngers.
On February 28, the US and Israel unleashed Operation Roaring Lion. Dramatic footage of missiles striking military, nuclear and administration targets throughout Iran was broadcast worldwide.But as the physical assault unfolded, another battle raged in parallel – one with no fighter jets in the sky and no missiles streaking throughout the horizon.Coordinated cyberattacks tore through Iran's networks, compromising news platforms and a popular prayer app, disrupting communications and replacing state television broadcasts with messages from Donald Trump and Benjamin Netanyahu.The physical assault was visible to the world; the digital blitzkrieg was largely invisible.It was a glimpse of a new kind of warfare. When cyberattacks hit water and wastewater facilities throughout at least 12 US states, including more than 30 systems in Minnesota, and Iran fought back.Iranian cyberoperators and affiliated groups targeted US and Israeli systems, stole sensitive information and disrupted infrastructure, increasingly extending the conflict far beyond the Middle East.The latest warning came in July.
US authorities have not conclusively attributed the attacks to Tehran, but Iranian-linked actors are among the suspects.CyberAv3ngers. It is affiliated with the Islamic Revolutionary Guard Corps (IRGC), issued a release regarding cyberattacks; while APT IRAN, which is linked to CyberAv3ngers, declared in an August 11 statement on its Telegram channel: "The attack on Minnesota was the work of the CyberAv3ngers and us, and we take direct responsibility for it." We have carried out attacks on US infra, and we warn America to back down. Threatening Iran's infra and shedding the blood of Iran's children has a particularly heavy rate. Our intention in attacking Minnesota was only to warn. US electricity, telecommunications, water is under our control, and whenever America acts arrogantly, we will press the button.
What began as a shadowy adjunct to conventional warfare is now a battlefield in its own right – one where the target may not be a military base, but the network controlling a water pump in small-town America.The physical war may be thousands of kilometres away. The cyberwar is already knocking on America's door. The invisible war.
Within the first hours of the 2026 US-Israeli strikes, multiple pro-regime Iranian news agencies were simultaneously compromised.Legitimate-looking but fabricated content was injected into their front pages, designed to degrade morale of pro-regime forces using classic PSYOPS tactics. The sites were rapidly taken down and restored, but not before reaching a wide audience during the most critical early hours. By injecting content at the exact moment Iranians turned to state media for strike coverage, the attackers maximised psychological impact during the regime's most vulnerable window. The physical assault was visible to the world; the digital blitzkrieg was largely invisible.
Notably, the simultaneous compromise of multiple outlets suggests pre-positioned access – these intrusions were prepared well in advance and activated on cue.Shortly after, BadeSabaa, a popular Iranian prayer time app with over 30 million installations from the Iranian app store, was hijacked.Push notifications were sent to its entire user base, calling on army members to surrender and join the individuals if they wanted to survive.The target selection was precise. As a prayer time app, its users skew heavily religious and conservative, a demographic overlapping significantly with pro-regime supporters and military personnel.During the second day of strikes, Iranian national television's Channel 3 satellite streams on IntelSat were hijacked. Viewers were shown video broadcasts of speeches by Trump and Netanyahu instead of regular programming.In repsonse, Iran went into full internet blackout, not only as a reaction to the cyberattacks but to stifle any dissent, and control information reaching the public. Iran retaliates.
In the 6 months preceding the 2026 US-Iran war, the global distribution of cyberattacks reflected projected threat trends: the US led with 18% of all incidents, followed by India (6%), Israel (6%), Indonesia (5%), and Thailand (5%).But in the 24 hours after the February 28 strikes, the picture shifted dramatically. Attacks on Israel spiked within 24 hours after the Iran war began.
Israel jumped from 6% to 21% of global incidents – a 3.5x growth. Crucially, Gulf states such as UAE, Kuwait, and Saudi Arabia appeared in the top 5 for the first time, reflecting retaliatory and spillover targeting linked to their proximity to the conflict and hosting of US military assets.Analysis of 179 threat incidents painted a clear picture of the hacktivist playbook.Denial-of-service (DDoS) attacks dominated at 37% of all incidents, consistent with hacktivist preference for high-visibility, low-effort disruption.But the data additionally disclosed more concerning activities: 9 incidents involved compromise of security cameras and industrial control systems applied to operate machinery and infrastructure in the US; alleged breaches of Israeli Defense Forces servers and Ministry of Defence data, and targeted data leaks of military personnel and civilian information.Iran had been preparing. A decade of cyber escalation.
Meanwhile, the invisible war did not start in 2026.The roots trace back to Stuxnet (2010), the US-Israeli cyberweapon that infiltrated industrial systems associated with Iran's nuclear programme and physically destroyed centrifuges at Natanz. The US additionally planned an effort known as Nitro Zeus, a programme to disrupt Iranian air defences, communications and power grid.Iran could not match the US aircraft for aircraft, missile for missile or carrier for carrier. But it could target the networks that connected financial institutions, telecommunications systems, industrial facilities and administration agencies.The Iranian response evolved rapidly.In 2012, Iranian-linked actors were blamed for Operation Ababil, a campaign of distributed denial-of-service attacks against US banks. The attacks temporarily disrupted online banking services and demonstrated that Iran did not need to destroy a bank's physical infrastructure to impose costs on it.The same period saw the Shamoon attack against Saudi Aramco, in which data on thousands of computers was erased. US authorities attributed the attack to Iran and rolled out counter cyberoperations.Between 2013 and 2017, Iran-based Mabna Institute targeted computer systems of 144 American universities and 42 private sector firms. The group may have stolen over 31 terabytes of academic data and intellectual property worth approximately $3.4bn, remarked the US Department of Justice.Over time, Tehran developed a broader ecosystem involving administration organisations, military-linked cyber units, contractors and proxy groups.During the June 2025 12-Day War, cyberattacks surged 700% within 48 hours.Pro-Israel cybersabotage group Predatory Sparrow wiped data of Iran's state-owned Bank Sepah; and burned $90 million in Nobitex cryptocurrency.Over 100 pro-Iranian hacktivist groups mobilised on Telegram. Israel was the most targeted country by geopolitically motivated hackers in 2025, absorbing 12.2% of all global attacks.By February 2026, Iran was primed to employ cyberwarfare to its asymmetric advantage. Iran's strike on Stryker.
On March 11, US firm Stryker suffered a major cyberattack that disrupted its global Microsoft environment.The Iran-linked Handala hacking group maintained responsibility and portrayed the operation as retaliation for the US-Israeli military campaign.Stryker confirmed that it had suffered a cyberattack and was experiencing a global network disruption. The attackers asserted they had wiped more than 200, 000 systems and extracted 50 terabytes of data.The attack represented a major escalation as of what Stryker does.It is not a weapons manufacturer. It makes medical devices applied by US hospitals.That makes the target strategically interesting. An attacker does not necessarily need to strike a hospital directly. Disrupting a firm that supplies the healthcare system can create pressure further downstream.This is what makes modern cyberwarfare so challenging to contain.The target may be civilian. The consequences may be civilian. And the attacker can still regard the operation as part of a military campaign. US water system under cyberseige.
After the attack, the FBI, Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency and Environmental Protection Agency cautioned that Iranian-affiliated actors were exploiting programmable logic controllers (PLCs) throughout American critical infrastructure.PLCs are not glamorous pieces of technology. They are industrial computers that control physical processes: pumps, valves, motors, pressure systems and other machinery.That is precisely why they matter.Compromising a PLC means crossing the line from stealing data to potentially manipulating the physical world.The April advisory remarked Iranian-affiliated actors had already caused operational disruptions and financial losses, including configuration wiping, manipulation of mechanical sensors and disruption of human-machine interfaces. More than 30 community water systems were targeted on July 26 and 27.
Then came the Minnesota incidents.Over 30 community water systems were targeted on July 26 and 27. Investigators have not publicly established Iranian responsibility, but the attacks resembled previous Iranian-linked intrusions into US water infrastructure.The attack expanded and eventually covered systems throughout at least 12 states.Some systems lost remote control, experienced pressure difficulties or had to revert to manual operations. At least 100 facilities throughout the US have been targeted.
Though the names and locations of these facilities were not published.The attacks were not catastrophic, the New York Times documented that at least 100 facilities throughout the US have been targeted. But that is precisely what makes them significant.A missile strike announces itself. A cyberattack can be almost invisible until a pump stops working, a hospital's systems go offline, a company's computers are wiped or a mobile phone quietly reveals the location of a soldier. The SS7 exploit: From opportunistic hacking to wartime strategy.
Perhaps the most striking development is that Iran's cyber campaign is no longer limited to hacking computers.It is increasingly regarding exploiting the digital ecosystem around residents.In July, reporting based on telecom data indicated that Iranian actors had exploited weaknesses in SS7, an old signalling protocol applied by mobile networks, to track the locations of US military personnel and contractors in the Middle East. SS7 is a signalling protocol applied by mobile networks.
SS7 vulnerabilities have long been known. They can allow sophisticated actors to obtain information regarding where a mobile device is located.In this case, the reporting indicated that Iranian actors employed telecom infrastructure and commercial advertising technology to locate US personnel in countries including Iraq and Bahrain. Though the precise operational links remain tough to establish, the information may have assisted subsequent attacks on US personnel. Iranian actors applied telecom infra to locate US personnel in the Gulf.
Notably, the implication is profound.A smartphone does not need to be hacked for it to become an intelligence source.The networks around it can be enough.The same is true of cameras, advertising platforms, cloud services, internet-connected industrial equipment and corporate identity systems. Information warfare.
Iran's cyber strategy is rooted in a broader doctrine of asymmetric warfare. Faced with conventionally superior US and Israeli military capabilities, Tehran has sought ways to impose costs without necessarily confronting those forces symmetrically.Cyber capabilities fit that strategy particularly well.Iranian actors have targeted local administration systems, gas-station payment infrastructure and water facilities in the US. Pro-Iranian hacktivist groups have simultaneously targeted organisations throughout the Middle East. US and Israeli authorities, military personnel and intelligence-linked individuals have additionally faced hack-and-leak operations.At first glance, these attacks can appear disconnected. Meanwhile, a compromised administration system, leaked personal information or disrupted infrastructure may seem to have little direct bearing on a war thousands of kilometres away.But their value can be measured in psychological and political terms. Iran's cyber strategy is rooted in a broader doctrine of asymmetric warfare.
In practice, the objective is partly to demonstrate reach. If Iranian-linked operators can penetrate systems belonging to senior authorities, military personnel or critical infrastructure, they can undermine the perception that those institutions are secure. That can have an effect disproportionate to the technical damage caused.The second objective is friction. Repeated cyber incidents can create uncertainty among businesses, governments and ordinary citizens. They generate a persistent sense that the conflict can reach into everyday life, even when no missiles are falling.This is where cyber operations become information warfare. Their physical effect may be limited, but their psychological effect can be amplified by social media, news coverage and public anxiety. Iran can therefore impose costs at a distance while attempting to shape how the conflict is perceived by domestic and international audiences. AI is making the cyber campaign faster and larger.
Artificial intelligence is adding another layer to this strategy.Recent threat-intelligence reporting indicates that Iranian actors have applied AI throughout multiple stages of cyber and information operations, including reconnaissance, code and malware development, social engineering, and the creation and manipulation of content.AI has therefore not fundamentally altered Iran's strategic logic, but it has rose the speed, scale, reach and potential impact of its operations. The threat actors are conducting reconnaissance and capability development against PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools.
AI does not necessarily offer Iran a revolutionary new weapon. Instead, it can create existing techniques more efficient. Reconnaissance can be accelerated, convincing social-engineering material can be produced at greater scale, and cyber operators can potentially develop or modify malicious code more rapidly.For countries defending critical infrastructure, this means that the challenge is not merely the sophistication of individual attacks. It is the possibility of a sustained volume of activity that continually tests subdued points. For context, the major picture.
Notably, a war that began with missiles and airstrikes over Iran is increasingly being felt in places far removed from the Middle Eastern battlefield.And unlike a missile, the weapon may not arrive with a warning.What began largely as opportunistic disruption, espionage and hacktivist activity has increasingly become an integrated component of Iran's broader war strategy, applied not only to steal information or disrupt systems, but to backing kinetic operations, influence perceptions and impose costs on adversaries far beyond the battlefield.Cyber operations thus function as an enabling layer throughout Iran's asymmetric strategy.The Strait of Hormuz and Iran's ability to disrupt energy flows remain much more powerful sources of leverage. Missiles, drones and economic pressure can produce more immediate physical effects. But cyber capabilities allow Tehran to extend that pressure into domains that are geographically distant and politically sensitive.For the United States, the challenge will be particularly acute as the conflict continues and the 2026 midterm elections approach. Iran has a history of targeting US elections and political campaigns, making cyber resilience increasingly significant not only for critical infrastructure but additionally for the political system. Catch the latest World News and Live updates. Download the TOI app.
For now, middle EastThe invisible war: Iran' s evolving cyberattacks bring battlefront to small remains the part of the story worth watching, and further updates are likely as more details are confirmed.




