How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved

In the week since July 26, concurrent cyberattacks have impacted water facilities across at least six U.S. states. Reflecting the scope and seriousness of the risk posed to the water sector, the attacks prompted the U.S. Cybersecurity and Infrastructure Security Agency to upgrade an advisory it had published just days before, warning operators to disconnect operational or publicly exposed technology from the internet as soon as possible. Although these attacks are yet to be attributed, signs point towards Iranian cyber actors as the likely culprit. This provides a useful moment to evaluate how Iran has used its cyber capabilities so far in its conflict against the United States and Israel, and whether this constitutes an escalation.

This commentary provides an updated analysis as to how Iran’s use of cyber operations and capabilities have evolved since the conflict broke out in February 2026, revisiting the author’s initial take. So far, the original assumptions have held: Iranian cyber actors are active, but shaped and likely still constrained by various environmental and doctrinal factors. That said, there has been a discernible uptick in Iran’s cyber operations over the last 4–6 months; Iran’s cyber apparatus has firmly re-geared in direct support and alignment with Iran’s war effort against the United States, Israel, and regional rivals, and is using cyber operations to shape the operating environment in a way that is favorable to its interests.

Key Strategic Trends in Iran’s Use of Cyber Capabilities

Since the outbreak of the conflict, Iran has undertaken a broader shift in its military strategy, centered around asymmetric means to frustrate its global and regional adversaries. This includes exploiting the vulnerabilities of U.S. and Israeli conventional forces, cutting off access to the Strait of Hormuz to impose costs to global energy markets and regional rivals, and a concerted information warfare campaign to shape global narratives on the conflict. Across each of these methods, but especially Iran’s information warfare objectives, cyber capabilities are a critical enabler, and they have played a vital part in causing attrition to Iran’s adversaries, as well as enabling power projection across the globe.

This has been reflected in a notable uptick in Iran’s cyber operations since March 2026. This has encompassed a broad range of activity, including (1) cyber espionage, (2) establishing technical accesses, (3) disruptive cyber operations, (4) cyber-enabled information operations, (5) deploying spyware, and (6) conflict-themed cyber crime. Three strategic trends have become apparent from this increased activity:

1. Iran’s Cyber Apparatus Has Directly Shifted to Support Its War Effort

In the earlier stages of the conflict, Iran’s cyber activity could be understood primarily as “opportunistic disruption,” whereby Iran’s operators were utilizing existing technical accesses they had already accumulated to throw quick, unsophisticated cyber operations at targets with weak cyber defenses, or conducting hacktivist attacks (such as website defacements, or hack-and-leak attacks) with little strategic effect. This was accompanied by some cyber espionage, and cyber-enabled information operations.

That activity has since evolved into a more concerted approach that reflects a recalibrated cyber apparatus, working in clearer and direct strategic alignment with Iran’s wartime objectives. Nowhere is this better reflected than through the prioritization of cyber espionage operations to support Iran’s war effort. In July 2026, it was discovered that Iran had hacked SS7 (a technical protocol to route data through telecommunications networks) to identify the location of U.S. troops stationed in the Middle East, directly informing kinetic strikes against them that resulted in injuries. Iran has also targeted high-value U.S. and Israeli senior officials with the likely intent to understand strategic decisionmaking, particularly pertaining to diplomatic negotiations with the United States to end the conflict. Iran has hacked security cameras in various countries, both to inform kinetic targeting by drones or missiles, and to assess post-strike damage. Reporting also points to an expansion of Iranian cyber espionage against the aviation, aerospace, defense manufacturing, telecommunications,, and space and satellite sectors—all of which are relevant to the defense industrial base critical to the conflict.

2. Iran Is Using Offensive Cyber Capabilities to Proactively Shape the Operating Environment

Just as the United States and Israel reportedly used offensive cyber capabilities to degrade Iran’s infrastructure in the opening stages of this conflict, Iran has also been utilizing cyber capabilities to shape the operative environment to its advantage. Iranian cyber actors are increasingly waging cyberattacks for information warfare purposes; Iran considers the key battlespace to be in the information domain, and from a doctrinal perspective, it relies upon information warfare as a key lever to achieve strategic depth by projecting power far beyond its borders.

Iran’s cyber-enabled information operations can be viewed in two ways: breadth and depth of targets. In terms of breadth, Iranian cyber actors have conducted various disruptive cyber operations across the United States (e.g., targeting local government systems in St Joseph’s Country, Indiana, in April, breaching tank readers at gas stations in May, hacking water facilities in California in June, and likely conducting the current attack against U.S. water facilities), whilst pro-Iranian hacktivist groups have continuously attacked organizations across the Middle East. In terms of depth, Iranian cyber actors and hacktivists have persistently targeted cyberattacks against U.S. and Israeli current and former officials—particularly hack-and-leak attacks—including against former Prime Minister Naftali Bennett and former Israeli Army Chief of Staff Herzl Halevi, and the alleged publishing of personal data of U.S. Marines stationed in the Gulf and Israeli military and intelligence personnel. It is worth noting that the presence of hacktivists itself is important, demonstrating another core component of Iran’s cyber ecosystem mobilizing in direct alignment with the war effort.

Though these appear as disruptive cyber operations at first glance, itIt is crucial to understand these attacks through an information warfare lens: First, they play into Iranian goals of power projection to different global audiences, specifically by demonstrating an ability to reach directly into the Israeli ruling elite and U.S. military, chipping away at their reputations of competence and security. Second, by generating a constant layer of friction that is felt by ordinary citizens and businesses, Iran generates a sense of fear, division, and chaos. In other words, the secondary, informational impact of these cyberattacks is key—it enables Iran to impose cost on its adversaries from a distance, shaping a more favorable information environment for Iran, particularly where it results in reduced support for the conflict among global, online audiences.

Artificial intelligence (AI) has been a vital enabling tool for Iran in shaping the environment. Recent threat intelligence reporting has shown that Iran has deployed AI across the full life cycle of its cyber and information operations, including initial target reconnaissance (e.g., actors linked to the Islamic Revolutionary Guard Corps using ChatGPT in 2024 to understand the technological components impacted in the current U.S. water facility attacks), code writing and malware developing, social engineering operations, and content creation and manipulation. Using AI has served to fundamentally enhance Iran’s modus operandi when it comes to cyber capabilities, by boosting their speed, scale, reach, and impact, rather than by changing the “strategic logic” with which Iran operates in a conflict.

3. Iran Is Still Operating in a Relatively Constrained Way

The scale of the cyberattacks against U.S. water facilities is certainly concerning. If the actor behind them is in fact Iran (which is not yet confirmed), these attacks have the potential to be escalatory; they disabled critical systems in the U.S. homeland, representing a threat to U.S. public safety. However, it is vital to contextualize these attacks within a much longer-term pattern of how Iran operates against its adversaries. Iran has a history of targeting multiple sectors of U.S. critical infrastructure with disruptive operations—especially the water sector (going back to at least 2013)—both in peacetime, and now, during conflict. As detailed above, this would not be the first time Iran has targeted U.S. infrastructure during this conflict.

Indeed, across the full spectrum of Iranian cyber operations so far in this conflict, Iran is effectively operating to the same blueprint that it used in the 12-day conflict with Israel in 2025: Its target base is similar (i.e., the defense industrial base, Israeli infrastructure, the satellite and space sector, and high-value individuals), its use of state actors and hacktivists is the same, and its tactics are remarkably similar, including cyber espionage, hacking cameras, low-sophistication attacks, and information operations. Together, these methods reflect Iran’s use of cyber operations to shape and augment the broader operating environment to its advantage, and to inform subsequent operations, whether for kinetic or cognitive effect. An important feature of Iranian military doctrine is “calibrated escalation”—moves that extend or exacerbate the conflict, but without reaching full-scale war. If the cyberattacks on U.S. water facilities are in fact attributed to Iran, they should be viewed as “opportunistic targeting,” inflicting costs on its adversaries, but without reaching the heights of escalation that other attack types have (including kinetic attacks).

Moreover, Iran may still be subject to operating constraints. Reporting in March 2026 suggested Israel and the United States had struck the Islamic Revolutionary Guard Corps’ cyber and information warfare headquarters early on in their campaign, and Iran also shut down its own domestic internet, impeding its ability to conduct cyber operations. But it is unknown how much of Iran’s cyber capacity has been restored. The uptick of cyber activity described in this commentary demonstrates that more of Iran’s cyber apparatus is online than previously thought—perhaps due to Iran’s “two-tier” internet, which created a parallel structure for elite and state internet access to stay online even as domestic connections were severed, as well as suggestions that Iran is using satellite connectivity to resume its operations. However, U.S. air strikes have hit Iranian telecommunications infrastructure since the conflict began, including one attack in July that took out 100 telecommunications masts, disrupting internet services in southern Iran. Disruptions to Iranian’s digital infrastructure will no doubt be a significant constraint upon Iran’s ability to operate in cyberspace.

Conclusion

It is still too early to fully understand how organizational changes in Iran’s military forces (from a conventional military into a decentralized web of operational commands) trickles down into its cyber apparatus. Nonetheless, its reliance upon asymmetric warfare is clear, as well as where cyber capabilities generate important advantage.

Iran has come to realize that its stranglehold over the Strait of Hormuz is its primary leverage. Cyber capabilities play a vital (albeit secondary) and enabling role: They help to inform, refine, and amply Iran’s kinetic and economic activity, while also proactively shaping the conditions Iran prefers to operate in, giving Iran important strategic advantage. If the cyberattacks on the U.S. water sector are confirmed to be from Iran, they should be evaluated relative to Iran’s wider capabilities—as another asymmetric lever of statecraft that Iran can pull to attrite the United States—but still a constrained lever, relative to its use of drones, missiles, or economic leverage. Iran’s doctrine, degraded physical infrastructure, and historic patterns of targeting are important constraints on how it decides to deploy cyber operations, and will be for some time.

Iran’s cyber operators will likely be working on preparing new technical accesses, and possibly new cyber capabilities to leverage, should the conflict continue over the longer-term or negotiations falter. The key strategic point on the horizon for the United States is the midterms, noting that Iran has a history of targeting U.S. elections and campaigns. This makes the need for cyber resilience across U.S. infrastructure critical. One point of success from the U.S. water facility attacks was that officials quickly reverted to manual processes and reserves, preventing impact upon public water supply. Sustained vigilance will be critical: As stated by Iranian hacktivist group Handala in April 2026, “the cyber war did not begin with the military conflict, and it will not end with any military ceasefire.”

Nikita Shah is a senior fellow with the Intelligence, National Security, and Technology program at the Center for Strategic and International Studies (CSIS) in Washington, D.C.

Senior Fellow, Intelligence, National Security, and Technology Program