When people picture modern warfare, they still tend to imagine missiles, jets, and soldiers. But the conflict between Iran, Israel, and the United States has spent much of the past two decades unfolding in a much quieter arena — one made of code, credentials, and compromised networks. Since the airstrikes and regional escalation that began in early 2026, that quieter war has moved from the background into plain view, and it has forced governments, companies, and ordinary citizens to reckon with what digital conflict actually looks like when it stops being theoretical.
A Rivalry Built in the Shadows
Cyber conflict between these three countries did not begin with any single event. It has been building for more than fifteen years, through episodes that have become case studies in cybersecurity classrooms: the Stuxnet worm that damaged centrifuges at Iran’s Natanz enrichment facility, the retaliatory attacks that followed against American banks and a Las Vegas casino, and years of espionage campaigns run by intelligence services on all sides. What has changed more recently is the pace and visibility of these operations. When coordinated American and Israeli strikes hit Iranian military and leadership targets in February 2026, cyber operations were not an afterthought — they were reportedly woven directly into the opening phase of the campaign, with U.S. officials saying that cyber and space operations disrupted Iranian communications and sensor networks in the hours before and during the kinetic strikes.
That fusion of digital and physical operations is itself telling. It reflects a shift in how modern states think about conflict: cyber capabilities are no longer a separate track running alongside traditional military action, but an integrated tool used to shape the battlefield itself.
Iran’s Cyber Toolkit
Iran’s cyber program has matured considerably since the days when it was seen mainly as a target rather than an operator. Today, Tehran’s digital capabilities run through a layered ecosystem: state-directed units linked to the Islamic Revolutionary Guard Corps and the Ministry of Intelligence and Security, semi-official contractors, and a constellation of hacktivist personas that let the government claim plausible distance from operations while still shaping their targets and messaging. Groups such as Handala have become recognisable faces of this strategy, framing themselves as independent activists sympathetic to Palestinian and Iranian causes while U.S. authorities have linked the network to Iran’s Ministry of Intelligence and Security (MOIS).
This approach gives Iran flexibility. Hacktivist fronts can claim credit for data theft, website defacements, or leaks without the same diplomatic consequences that would follow a directly attributed state operation. It also means that even when a ceasefire is announced on the battlefield, some pro-Iranian cyber groups have indicated that their operations would continue despite ceasefire arrangements. Following the 2026 ceasefire arrangements, at least one prominent pro-Iranian collective said it would pause operations against the United States but continue targeting Israel — a reminder that digital hostilities can persist, and even expand, in the space that opens up once the shooting stops.
Espionage Beneath the Surface
Much of what happens in this rivalry never makes headlines, because espionage is designed to stay invisible. Iranian-linked groups have long targeted government agencies, defense contractors, energy firms, and financial institutions in the United States and Israel, seeking intelligence on military planning, sanctions policy, and technological capability. Conversely, Israeli and U.S. intelligence agencies have long conducted extensive cyber and intelligence activities directed at Iranian military and nuclear capabilities — a natural extension of decades spent monitoring the country’s nuclear and military programs. This is the least visible layer of the conflict, but arguably the most consequential, since intelligence gathered quietly today can inform decisions made publicly months or years later, including decisions about where and when to strike.
Critical Infrastructure: The Riskiest Frontier
The part of this conflict that worries security professionals most is its potential spillover into critical infrastructure — water systems, power grids, hospitals, and industrial control systems that were never designed with nation-state adversaries in mind. During the 2026 escalation, U.S. authorities and cybersecurity researchers have documented Iranian-affiliated cyber activity targeting industrial control systems well outside the immediate conflict zone, including water treatment operators in the United States.
Some of these claims were exaggerated for propaganda value, which is itself a hallmark of this kind of conflict; digital operations are often as much about perception and psychological pressure as they are about physical damage. But the underlying risk is real. Industrial systems are frequently older, less monitored, and harder to patch than conventional corporate networks, and a successful intrusion — even a modest one — can carry consequences that ripple far beyond the original target, affecting public services and everyday life.
Jordan’s cybersecurity authorities, for instance, confirmed that they had blocked an attempted intrusion into a national wheat silo management system during the height of the conflict — a small but telling example of how attacks aimed at psychological effect can just as easily threaten food and water security if they succeed.
Retaliation as a Political Language
One of the more striking features of this cyber rivalry is how much of it functions as communication rather than pure sabotage. Defacements, leaked data, and disrupted broadcasts are often less about technical damage and more about sending a message — to adversaries, to domestic audiences, and to the wider region. When Iranian state media websites and a widely used prayer application were compromised during the initial 2026 strikes, the operation appeared intended not simply to disrupt services but also to deliver a psychological and political message.
Iranian-aligned retaliatory operations have followed a similar logic, prioritizing visibility and symbolism, from claimed breaches of healthcare and energy companies to leaks timed around politically significant dates. This does not make the attacks any less serious for the organizations caught in the middle. A hospital network or an energy company does not experience a symbolic cyberattack any differently than a purely destructive one — the operational disruption, cost, and risk to safety are equally real, regardless of the attacker’s underlying motive.
The Human Cost Behind the Screens
It is easy to discuss cyber conflict purely in technical terms — malware families, intrusion vectors, attributed threat actors — and lose sight of the human dimension. Internet blackouts imposed inside Iran during periods of unrest and conflict have cut ordinary citizens off from family, information, and emergency services, sometimes for extended periods. Employees at targeted companies face the stress of incident response under geopolitical pressure. Civilians on all sides live with the uncertainty of not knowing whether the next disruption to their bank, their hospital, or their utility provider is a technical glitch or the opening move of something larger. Cyber conflict, in other words, is not a bloodless alternative to war — it is a dimension of war that touches daily life in ways that are easy to underestimate until they are experienced directly.
Where This Leaves Us
The Iran-Israel-United States cyber rivalry is unlikely to resolve neatly, even if the current military conflict eventually gives way to a durable ceasefire. Cyber capabilities are now embedded in how each side pursues its interests, gathers intelligence, and signals resolve, and the barriers to entry for hacktivist and proxy activity remain low. For governments and businesses, this argues for sober, sustained investment in resilience — not panic, but steady attention to the systems that keep hospitals, utilities, and financial services running. For the wider public, it is a reminder that the boundary between digital and physical conflict has become thinner than most people realize, and that the consequences of this quiet war are anything but abstract.
The views presented in this article are the authors’ own and do not necessarily reflect the views of Global Strategic Forum – GSF.

Imran Bhatti
Imran Bhatti holds an M.Phil. in Governance and Public Policy and professional certifications as a Certified Information Systems Security Professional (CISSP) and Project Management Professional (PMP). He is a geopolitical analyst and writer specializing in energy geopolitics, great-power competition, Eurasian strategic affairs, and South Asian security dynamics. His work explores regional geopolitics, border disputes, infrastructure, security, and economic statecraft in an increasingly multipolar world.




Leave a Reply