Iran’s Cyber War: On February 28, the United States and Israel launched a major military campaign against Iran, dubbed Operation Roaring Lion. As missile strikes targeted Iranian military, nuclear and government facilities, another battle unfolded in cyberspace.
- Iran Targets US Critical Infrastructure
- Cyberattacks Used as Psychological Warfare
- Iran’s Cyber Counterattack Spreads Across the Region
- A Cyber War With More Than a Decade of History
- Stryker Cyberattack Raises Healthcare Concerns
- US Water Systems Face Growing Risks
- Exploiting Weaknesses in Mobile Networks
- AI Could Transform Iran’s Cyber Strategy
Coordinated cyberattacks on Iran disrupted digital networks, news platforms, communications and even a widely used prayer application. Iranian state television was reportedly hijacked and replaced with messages from US President Donald Trump and Israeli Prime Minister Benjamin Netanyahu. Iran responded with its own cyber operations, turning the conflict into a wider digital war.
Iran Targets US Critical Infrastructure
Iran-linked cyber groups have increasingly targeted American and Israeli systems, stealing sensitive information and disrupting critical infrastructure.
In July, cyber incidents affected water and wastewater facilities across at least 12 US states, including more than 30 systems in Minnesota. While US officials have not formally attributed the attacks directly to Tehran, groups linked to Iran’s Islamic Revolutionary Guard Corps, including CyberAv3ngers and APT Iran, claimed responsibility for some of the activity.
The groups warned that American electricity, telecommunications and water infrastructure could remain targets, raising concerns about the vulnerability of critical services during an extended conflict.
Cyberattacks Used as Psychological Warfare
The cyber campaign has not focused solely on infrastructure. Psychological warfare has also emerged as a major component.
During the opening hours of the conflict, several Iranian news networks were reportedly compromised and used to spread false information. A popular Iranian prayer app, reportedly used by more than 30 million people, was also hacked. Attackers allegedly used push notifications to send messages urging Iranian military personnel to surrender.
On the second day, Iran’s Channel 3 satellite broadcast was reportedly hijacked, with speeches by Trump and Netanyahu appearing on the channel.
Iran responded by imposing a nationwide internet blackout, seeking to restrict the spread of information and limit public unrest.
Iran’s Cyber Counterattack Spreads Across the Region
Iran’s response quickly expanded beyond Israel and the United States.
Within 24 hours of the conflict beginning, cyberattacks against Israel reportedly increased 3.5 times. Gulf countries, including the United Arab Emirates, Kuwait and Saudi Arabia, also emerged among the most targeted nations.
An analysis of 179 cyber incidents found that around 37% involved denial-of-service attacks. Other operations reportedly targeted industrial control systems and security cameras connected to American infrastructure.
The pattern shows how cyber warfare can rapidly expand beyond the primary battlefield, affecting countries that are politically or strategically connected to the conflict.
A Cyber War With More Than a Decade of History
The current confrontation is part of a much longer cyber conflict between Iran, the US and Israel.
One of the most significant early incidents was Stuxnet, the sophisticated cyber weapon discovered in 2010 that targeted Iran’s Natanz nuclear facility. The attack encouraged Tehran to strengthen its own cyber capabilities.
Iran subsequently launched major cyber operations, including Operation Ababil, which targeted US banks in 2012, and the Shamoon attack against Saudi Aramco.
Between 2013 and 2017, Iranian hackers linked to the Mabna Institute also stole data from 144 US universities. Cyber activity again surged during the 12-day Iran-Israel conflict in June 2025, highlighting Tehran’s growing readiness for digital warfare.
Stryker Cyberattack Raises Healthcare Concerns
On March 11, US medical equipment manufacturer Stryker suffered a major cyberattack that disrupted its global operations. The Iran-linked hacking group Handala claimed responsibility.
Although Stryker does not manufacture weapons, it supplies essential medical equipment to hospitals. An attack on such a company demonstrates how cyber warfare can target civilian supply chains rather than military systems directly.
Disrupting healthcare logistics could create significant pressure without requiring a conventional attack on hospitals.
US Water Systems Face Growing Risks
US security agencies have warned that Iranian hackers are targeting programmable logic controllers (PLCs) used in industrial systems.
In Minnesota, more than 30 water systems reportedly experienced disruptions to automated controls, forcing operators to switch to manual procedures.
Reports indicate that at least 100 facilities across the US have been targeted. While these incidents did not cause widespread physical destruction, they demonstrated how attackers can potentially disrupt essential services by interfering with pumps, controls and other digital systems.
Exploiting Weaknesses in Mobile Networks
Another concern involves the aging SS7 signalling protocol, which is used by telecommunications networks.
Reports in July suggested that Iranian-linked hackers exploited telecommunications infrastructure and advertising technology to track the locations of US military personnel stationed in Iraq and Bahrain.
The incidents highlight a critical weakness in modern communications: attackers may be able to gather sensitive location information without directly hacking an individual’s phone.
AI Could Transform Iran’s Cyber Strategy
Iran’s cyber strategy reflects the broader concept of asymmetric warfare. Rather than attempting to match the conventional military power of the US and Israel, Tehran can use cyber operations to create uncertainty, disrupt infrastructure and generate psychological and political pressure.
Artificial intelligence is also becoming increasingly important. AI can assist in intelligence gathering, malware development and the creation of misleading digital content.
As the US approaches its 2026 midterm elections, cyber threats could extend beyond infrastructure and military systems to information networks and political institutions.
The growing Iran-US cyber conflict shows that modern warfare is no longer fought only with missiles, aircraft and soldiers. Digital networks, communication systems, critical infrastructure and information platforms have become battlefields of their own.






