AEGIS I AHSAM Analysis — How Tehran's Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved
ANALYSIS

How Tehran's Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved

Cyber & Information Warfare Assessment

Bottom Line Up Front (BLUF)

In the week following 26 July 2026, concurrent intrusions struck water-sector facilities across at least six U.S. states, prompting the U.S. Cybersecurity and Infrastructure Security Agency to upgrade an advisory issued only days earlier and urge operators to disconnect exposed operational technology from the internet. Formal attribution remains unconfirmed, but the operational signature points toward Iranian state or state-aligned actors. We assess with high confidence that Iran's cyber apparatus has, since roughly March 2026, re-geared in direct support of its wartime objectives against the United States, Israel, and regional rivals — shifting from opportunistic, low-sophistication disruption toward espionage-enabled targeting, information warfare, and AI-augmented operations. We assess with moderate confidence that this activity, even where attributable to Iran, remains constrained by Tehran's doctrine of calibrated escalation and by continuing damage to its own cyber and telecommunications infrastructure — meaning it is best read as a persistent, adaptive risk rather than a signal of imminent, large-scale cyber war.

Key Judgments

ConfidenceJudgment
High Iran's cyber posture has moved from opportunistic, low-sophistication disruption in the conflict's early weeks toward operations tightly integrated with wartime objectives, prioritizing espionage that directly enables kinetic effect — including a July 2026 exploitation of SS7 telecommunications-signaling infrastructure to geolocate U.S. personnel in the Middle East ahead of strikes that caused injuries.
High Cyber operations function primarily as an information-warfare multiplier: broad, low-sophistication disruption of U.S. local government, fuel, and water systems runs alongside sustained hack-and-leak operations against senior U.S. and Israeli figures, aiming to erode adversary confidence and generate domestic friction rather than achieve narrow tactical effect alone.
Moderate–High Artificial intelligence is now embedded across the full life cycle of Iranian cyber and information operations — reconnaissance, malware development, social engineering, and content generation — functioning chiefly as a multiplier of speed and scale rather than a change in Iran's underlying strategic logic.
Moderate Even if the July–August 2026 water-sector intrusions are confirmed as Iranian, they are best understood as consistent with a decade-plus targeting pattern (dating to at least 2013) and with Tehran's doctrine of "calibrated escalation," rather than a deliberate move toward full-scale cyber conflict.
Moderate Iran's cyber capacity remains materially constrained by reported strikes on IRGC cyber and information-warfare infrastructure and by continuing attrition of Iranian telecommunications infrastructure, partially offset by a parallel "two-tier" internet architecture and satellite-based connectivity.
Low–Moderate Formal, public attribution of the multi-state water-sector intrusion campaign to an Iranian state or state-aligned actor remains unconfirmed as of this assessment.

I. From Opportunistic Disruption to Strategic Realignment

In the conflict's opening weeks, Iranian cyber activity was best characterized as opportunistic: operators leaned on technical accesses obtained before the war, launched unsophisticated intrusions against poorly defended targets, and supported hacktivist website defacements and hack-and-leak operations with limited strategic value, alongside a lower baseline of espionage and information operations. That posture has since given way to a more deliberate model, aligned directly with Iran's wartime goals and spanning six recognizable lines of activity: cyber espionage, the establishment of technical accesses, disruptive operations, cyber-enabled information operations, spyware deployment, and conflict-themed cybercrime. Espionage has become the clearest priority. In July 2026, reporting confirmed that Iran had exploited SS7 — the signaling protocol that routes traffic across telecommunications networks — to geolocate U.S. troops stationed in the Middle East, intelligence that appears to have directly informed kinetic strikes causing injuries. Iranian actors have also targeted senior U.S. and Israeli officials, likely to gain insight into negotiating posture on ending the conflict, and have compromised security cameras in multiple countries to support both strike planning and post-strike damage assessment. Separately, reporting points to expanding Iranian espionage against the aviation, aerospace, defense-manufacturing, telecommunications, and space and satellite sectors — the backbone of the defense industrial base underpinning the wider conflict.

II. Cyber as an Information-Warfare Multiplier

Much as the United States and Israel reportedly used offensive cyber tools to degrade Iranian infrastructure early in the conflict, Iran has pursued a parallel strategy of shaping the operating environment to its own advantage. Doctrinally, Iran treats the information domain as the decisive battlespace, using information warfare to project strategic depth well beyond its borders — and its cyber-enabled information operations are best understood along two axes: breadth and depth. In breadth, Iranian actors have conducted disruptive intrusions across the United States — local government systems in St Joseph County, Indiana, in April 2026; fuel-pump tank-reader systems at U.S. gas stations in May 2026; a California water facility in June 2026; and, most likely, the ongoing multi-state water-sector campaign now under investigation — while pro-Iranian hacktivist groups have sustained a continuous drumbeat of attacks against organizations across the Middle East. In depth, Iranian actors and aligned hacktivists have persistently pursued hack-and-leak operations against current and former senior U.S. and Israeli officials, including former Israeli Prime Minister Naftali Bennett and former IDF Chief of Staff Herzl Halevi, alongside the alleged publication of personal data belonging to U.S. Marines stationed in the Gulf and Israeli military and intelligence personnel. The persistent involvement of aligned hacktivist groups is itself notable, evidencing a broader mobilization of Iran's cyber ecosystem behind the war effort. These operations should not be read narrowly as disruption for its own sake. First, they serve Iran's power-projection goals by demonstrating reach into the Israeli ruling elite and the U.S. military, chipping away at perceptions of their competence and security. Second, by imposing a constant layer of friction on ordinary citizens and businesses, Iran cultivates fear, division, and a sense of chaos at a distance — shaping a more favorable global information environment, particularly where it dampens international support for the conflict.

III. Artificial Intelligence as a Force Multiplier

Threat-intelligence reporting indicates Iran has integrated artificial intelligence across the full life cycle of its cyber and information operations: initial target reconnaissance — including reported use of ChatGPT as early as 2024 by actors linked to the Islamic Revolutionary Guard Corps to study the technical systems later implicated in the 2026 water-facility intrusions — as well as code writing, malware development, social-engineering support, and content creation and manipulation. The effect of AI adoption has chiefly been to enhance the speed, scale, reach, and impact of an existing playbook, rather than to alter the underlying strategic logic with which Iran operates during conflict.

IV. Structural Constraints and the Doctrine of Calibrated Escalation

The scale of the water-facility intrusions is genuinely concerning: if Iranian in origin, they disabled critical systems inside the U.S. homeland and posed a real risk to public safety. Even so, the pattern fits a much longer arc of Iranian behavior. Iran has targeted multiple sectors of U.S. critical infrastructure — the water sector foremost among them, with documented targeting dating to at least 2013 — in both peacetime and, now, wartime conditions; this would not be the first time Iranian actors have targeted U.S. infrastructure during the present conflict. Across the conflict as a whole, Iran appears to be following essentially the same blueprint it used during its 12-day confrontation with Israel in 2025: a similar target base (the defense industrial base, Israeli infrastructure, the space and satellite sector, high-value individuals), a similar blend of state actors and hacktivists, and similar tactics — espionage, camera compromise, low-sophistication disruption, and information operations. Together, these methods reflect a doctrine of "calibrated escalation": actions that extend or exacerbate the conflict without crossing into full-scale war. Should the water-facility attacks ultimately be attributed to Iran, they most plausibly represent opportunistic targeting intended to impose cost, rather than a deliberate step toward the higher end of the escalation ladder associated with kinetic action. Iran's cyber capacity also remains genuinely constrained. Reporting from March 2026 indicated that Israeli and U.S. strikes hit the Islamic Revolutionary Guard Corps' cyber and information-warfare headquarters early in the campaign, while Iran's own decision to shut down domestic internet access further impeded its operators. The extent of subsequent recovery is unclear, though the uptick in activity described above suggests more of Iran's cyber apparatus is functioning than previously assumed — plausibly aided by a "two-tier" internet architecture preserving elite and state connectivity, and by reported use of satellite links to sustain operations. Offsetting this resilience, U.S. strikes have continued to degrade Iranian telecommunications infrastructure, including a July 2026 strike that destroyed roughly 100 telecommunications masts and disrupted internet service across southern Iran — a meaningful and likely ongoing constraint on Tehran's cyber reach. On the defensive side, it is worth noting that U.S. water utilities' rapid reversion to manual processes and reserve systems prevented the recent intrusion campaign from disrupting the public water supply — an indicator that baseline critical-infrastructure resilience is holding even as the threat intensifies.

V. Outlook: Elections, Infrastructure Resilience, and Sustained Risk

Organizational change inside Iran's military — its evolution from a conventional force into a decentralized web of operational commands — has not yet fully revealed how it will reshape Iran's cyber apparatus. What is clear is Iran's continued reliance on asymmetric tools, and the specific advantages cyber capabilities provide within that strategy. Tehran appears to regard its leverage over the Strait of Hormuz as its primary strategic lever, with cyber capabilities playing a vital but secondary and enabling role — informing, refining, and amplifying kinetic and economic activity while proactively shaping conditions favorable to Iran. Should the water-sector attacks be confirmed as Iranian, they should be weighed against Tehran's fuller toolkit: a meaningful but still constrained instrument relative to drones, missiles, or economic pressure. Doctrine, degraded physical infrastructure, and a long historical pattern of targeting will likely continue to shape how — and how far — Iran is willing to deploy its cyber capabilities. Iranian cyber operators will likely continue developing new technical accesses and capabilities should the conflict persist or negotiations falter. The clearest near-term horizon risk for the United States is the midterm election cycle, given Iran's documented history of targeting U.S. elections and campaigns — reinforcing the case for sustained cyber-resilience investment across U.S. infrastructure. As the pro-Iranian hacktivist group Handala stated in April 2026:
"the cyber war did not begin with the military conflict" — and, the group added, would not end with any battlefield ceasefire.
Sustained vigilance, rather than a single decisive fix, is likely to remain the operative posture for U.S. critical-infrastructure defense for the duration of the conflict and beyond.

Primary reporting consulted: Center for Strategic and International Studies (CSIS), "How Tehran's Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved," commentary by Nikita Shah, Senior Fellow, Intelligence, National Security, and Technology Program. This AHSAM assessment paraphrases and restructures that reporting for an AEGIS I AHSAM audience and adds no independent attribution judgment beyond what is noted above; formal attribution of the water-sector intrusions to Iran remains unconfirmed at time of writing.