Iran–United States Cyber Conflict: From Stuxnet to the 2026 War

An evidence-led history and current assessment of the Iran–United States cyber conflict, including espionage, industrial disruption, critical-infrastructure operations, cloud strikes, cyber-enabled targeting, and unresolved claims.

Begin on 28 February 2026: the war becomes visible

Evidence cutoff: 14 September 2026. The newest chapter began on the morning of 28 February. United States and Israeli aircraft struck across Iran; Iranian forces answered across the region; and ordinary Iranians watched their connection to the outside world collapse. Within hours, network observers saw national traffic fall almost to zero. The digital conflict did not begin that morning, but years of espionage, industrial access, surveillance, censorship and retaliation suddenly met an open shooting war.

Follow the events from the viewpoint of the systems they crossed. A camera above a Tehran street could be a policing tool, a source for a foreign intelligence service, and evidence after a strike. A controller in an American water facility could be ordinary municipal equipment one day and a channel for coercive disruption the next. An AWS building in the Gulf could host civilian banking and business applications while Iran alleged that American cloud capacity supported military functions. Each object acquired several meanings at once.

The conflict is broader than malware exchanged between two governments. It includes espionage against research and government targets, disruptive campaigns against financial and industrial systems, access to operational technology, hack-and-leak activity, attacks on commercial cloud facilities, exploitation of cameras for reported targeting support, sanctions and indictments, and military strikes against infrastructure inside Iran. The practical definition of cyberwarfare is useful here: classify an event by objective, authority, context, target and effect instead of calling every hostile digital act war.

The central finding is bounded. Iran and the United States have engaged in sustained cyber conflict for more than a decade, and cyber activity now interacts directly with armed hostilities. Public evidence does not support assigning every pro-Iranian claim to Tehran, every coalition strike inside Iran to the United States, or every attack on digital infrastructure to the category “cyberattack.” Those unresolved distinctions are operationally important.

The first chapter: Natanz changes what cyber operations can mean

The story reaches back to Natanz. Stuxnet was disclosed in 2010 after code built for a narrow industrial environment escaped into wider view. Investigators found logic designed around particular controllers and centrifuge behavior: change the physical process, conceal the change from operators, and let ordinary displays preserve a false sense of normality. Public reporting attributed the operation to the United States and Israel, but neither government has supplied a complete public operational record.

Iran learned two lessons at once. Digital access could produce physical effect without an airstrike, and an operation that remained hidden long enough could still become public, reverse engineered and politically formative. The rest of the conflict would unfold under that shadow.

United States prosecutors later alleged that seven Iranian nationals working for IRGC-sponsored entities conducted distributed denial-of-service attacks against the American financial sector between 2011 and 2013. The same indictment alleged repeated unauthorized access to the Bowman Avenue Dam’s SCADA system in New York. The gate was disconnected for maintenance, limiting possible control. The Bowman Dam indictment is an allegation and explicitly preserves the defendants’ presumption of innocence; it is nevertheless a primary record of the United States government’s attribution and theory of the case.

Subsequent cases show a diversified portfolio: intelligence collection, credential theft, exploitation of known vulnerabilities, extortion, disk encryption, persona-driven publicity and targeting of Israeli-made industrial controllers. The pattern is not a simple ladder toward ever greater destruction. Operations vary with opportunity, political signaling, target exposure, organizational mandate and the value of plausible deniability.

The pressure cycle accelerates: June 2025 to open war

After United States and Israeli strikes against Iranian nuclear sites during the June 2025 conflict, a joint CISA, FBI, NSA and Defense Cyber Crime Center fact sheet warned that Iranian-affiliated actors and aligned hacktivists might target vulnerable American networks. It emphasized opportunistic exploitation of unpatched systems, weak credentials, exposed operational technology, defacement, data leaks and possible ransomware cooperation. This was a defensive warning based on capability and geopolitical conditions, not proof that every predicted action occurred.

Before the next war began, a domestic crisis transformed the operating environment. Protests that started after the rial’s collapse on 28 December 2025 spread across Iran and challenged the political system. From 8 January, rights organizations documented coordinated mass killing by IRGC, Basij, police and plain-clothes forces while authorities imposed a national communications blackout. Published counts differed, but government, activist and independent reporting all placed the dead in the thousands. Reports that Iraqi militia fighters entered to reinforce the crackdown were based principally on anonymous Iraqi and European security sources and remain unverified at the level of individual deployments and killings. The full evidence record and its limitations are traced in Iran’s internet censorship machine.

CENTCOM states that it commenced Operation Epic Fury on 28 February 2026 at presidential direction. Its Operation Epic Fury record describes strikes intended to dismantle the Iranian security apparatus and prioritize locations assessed to pose an imminent threat. Israel conducted operations in parallel. Public reports frequently use “U.S.-Israeli strikes” when the individual attacker is unknown; responsible analysis must preserve that ambiguity.

Iranian media reported strikes on science-and-technology universities in Tehran and Isfahan, and the IRGC threatened retaliation against American- and Israeli-linked universities in the region. Those institutions may contain military-relevant research, civilian education, or both. Publicly available evidence is insufficient to determine the target basis, attacker and expected military advantage for every incident. Describing these sites simply as “IT companies blown up by the United States” is therefore inaccurate.

The war travels outward and reaches the cloud

On 1–2 March 2026, AWS reported physical damage at facilities in the United Arab Emirates and Bahrain during Iranian drone attacks. Two UAE facilities were directly struck; a strike near a Bahrain facility physically affected infrastructure. AWS reported structural damage, interrupted power, fire suppression and prolonged recovery. Associated Press AWS strike reporting documented three affected facilities and localized service disruption.

This was kinetic action against the physical layer of cloud computing, not code delivered through a network. Its cyber significance came from the functions riding on the facilities: compute, storage, identity-dependent applications, financial services and regional digital connectivity. Geographic redundancy reduced the effect but did not make damaged availability zones interchangeable without customer preparation, capacity and tested failover.

Iran-linked reporting later framed cloud and technology companies as legitimate targets because of alleged support to United States military and intelligence activity. That is a belligerent justification, not an independently validated legal conclusion. The standalone analysis of cloud infrastructure under kinetic attack examines military use, civilian dependence, proportionality, precautions and resilience without presuming that an entire commercial cloud becomes a lawful target.

While strikes continue, operators reach into civilian systems

A multiagency 2026 joint PLC advisory, updated on 22 July, states that Iranian-affiliated actors disrupted PLCs in American government, water, wastewater and energy environments beginning in March. Investigators observed targeting of exposed controllers from several manufacturers, use of programming software and, at one victim, a malicious project file containing logic that overrode instructions associated with safe operating parameters. The advisory attributes the activity to Iranian-affiliated actors and assesses disruptive intent; it does not make every incident an order directly proven to originate from senior Iranian leadership.

On 11 March, medical-technology company Stryker confirmed a cyberattack disrupted its global network. The Handala persona claimed responsibility and presented the action as retaliation for deaths in a strike on a school in Minab. Company confirmation establishes the incident and disruption; the persona’s statement establishes a claim. Neither alone proves state command. This separation is the core discipline of cyber attribution.

Researchers and government bodies also reported attempts to compromise cameras in Israel and Gulf states. Such access can support observation, geolocation or damage assessment, but the military use of a particular feed requires case-specific evidence. The resource on cyber-enabled targeting explains how analysts can evaluate the connection between digital access and kinetic effect without turning claims into facts.

Behind the dramatic names, an ecosystem comes into view

The Iranian cyber ecosystem includes intelligence and military bodies, front companies, contractors, criminal collaborators, patriotic volunteers and media-facing personas. These relationships are not interchangeable. A company can supply personnel to an IRGC organization; an operator can reuse state-associated infrastructure; a persona can amplify genuine access, exaggerate it, or claim an unrelated outage.

In August 2026, the Department of Justice announced charges against 17 alleged members of the Iran-based Mabna Institute. The Mabna Institute case alleges intrusions into 144 United States universities, 178 foreign universities, companies, agencies and nongovernmental organizations, with more than 31 terabytes of academic and proprietary data stolen. The indictment alleges that some work served the IRGC and other Iranian clients. Because it is an indictment, its allegations must not be written as adjudicated fact.

Sound assessment separates four questions: which technical activity belongs together; who operated it; what organization sponsored or benefited from it; and whether available evidence supports state responsibility. Confidence may differ at every layer. Public attribution also serves diplomatic, legal and deterrent purposes, so analysts should describe the issuing authority and evidence basis rather than treating an official statement as neutral telemetry.

Inside Iran, the state closes the information space—and strains it

As the physical campaign expanded, Iran’s authorities imposed a second battlefield on their own network. Traffic fell below one percent on 28 February while domestic services and selected privileged connections remained available. The National Information Network allowed authorities to preserve approved Iranian platforms and government functions while excluding most people from the global internet. Officials presented the shutdown as wartime security; it also narrowed independent reporting, family contact and public scrutiny.

By mid-March, the controlled network itself showed strain. Measurement organizations observed new collapses inside the already restricted traffic; domestic providers and services suffered outages; and even semiofficial media briefly disappeared. Reports disagreed over whether individual failures came from wartime damage, power loss, operator decisions, defensive isolation or domestic technical problems. The evidence does not support the viral story that one “censorship building” was destroyed. Iran’s internet censorship machine was distributed—and its disruption was distributed too.

The episode reveals why cyber power does not replace conventional force. Digital access can collect intelligence, expose targets, disrupt industrial processes, control information or complicate recovery. Kinetic force can destroy the servers, power and communications on which those operations depend. A state can deliberately restrict connectivity and simultaneously lose control of services it meant to preserve.

Effects on civilians cannot be inferred from the target label. A localized cloud outage can interrupt banking, logistics, healthcare administration or emergency communication. An OT intrusion can create unsafe operator information even when a physical process continues. A strike on a university can affect military research, civilian education, protected people and surrounding infrastructure simultaneously. Analysts should map civilian harm and reverberating effects across services, dependencies, geography and time.

Major unknowns remain: the command relationship behind individual personas; which camera compromises actually contributed to targeting; the intended and realized military advantage of particular infrastructure strikes; undisclosed operations by the United States, Israel or Iran; and the strategic durability of observed disruptions. A professional conclusion preserves those gaps. It does not fill them with symmetry, intent inferred from outcome, or statements made by parties to the conflict.

Where the story stands—and what could still change it

For each new event, create a record containing date and timezone, location, affected organization, target function, delivery mechanism, observed damage, service effect, casualty information, claimant, victim confirmation, official attribution, independent corroboration and confidence. Store the source publication date separately from the event date. Wartime reports are frequently corrected, and a later investigation may identify a different weapon or actor.

Prefer primary technical evidence and direct organizational statements for what happened to a system. Use official military releases to document what a belligerent says it targeted, indictments for allegations made under legal process, and independent reporting to test those accounts. Do not treat government publication as proof of neutrality or social-media imagery as self-authenticating. Record provenance, geolocate carefully, compare timestamps and preserve alternative explanations.

Update the assessment when evidence changes, not merely when attention increases. Material triggers include a victim post-incident report, an official revision, independently verified imagery, forensic linkage, a judicial outcome, a newly acknowledged operation or evidence connecting an operator to a sponsor. Retain the old judgment and explain why it changed. That audit trail is part of the intelligence product.

Frequently asked questions

Are Iran and the United States in a cyberwar?

They are engaged in a long-running cyber conflict involving espionage, disruption, coercion, critical-infrastructure access, influence, and operations connected to armed hostilities. Whether a particular event is cyber warfare depends on its context, purpose, authority, and relationship to hostilities; the label should not replace analysis.

Did the United States recently bomb Iranian IT companies?

Public reporting confirms extensive United States and Israeli strikes in Iran and strikes on Iranian technology universities, but available reporting often does not identify which coalition member conducted a specific strike. The clearest independently reported kinetic attacks on commercial technology infrastructure were Iranian drone strikes that damaged AWS facilities in the UAE and Bahrain in March 2026.

Is a missile strike on a data center a cyberattack?

No. It is a kinetic attack on the physical infrastructure that enables digital services. It belongs in cyber-conflict analysis because the target, dependencies, service effects, intelligence value, and civilian consequences can all be digital.

How reliable are claims made by wartime hacking groups?

A claim establishes that a persona said something, not that it performed the operation or acted under state direction. Analysts should seek victim confirmation, telemetry, infrastructure and malware evidence, temporal consistency, independent reporting, and evidence of a command or sponsorship relationship.