As the United States and Israel wage their most publicly visible military campaign against Iran through standard strikes and public exhibitions of military hardware, a concurrent and significantly more covert battle is taking place in cyberspace. Whilst American and Israeli officials have been forthcoming about their use of jets, ships and missiles, they have remained notably reluctant about cyber activities. Yet evidence suggests digital combat has proven pivotal in the conflict, with US Central Command recently confirming strikes extending “from seabed to space and cyber-space”. Iranian hackers have already claimed their first significant cyber assault on a US company, targeting medical technology firm Stryker. Behind the scenes, cyber operations have allegedly been crucial in preparing the ground for military action, with US and Israeli operatives acting as what Pentagon officials describe as the “first movers” in compromising Iran’s ability to respond.
Preparing the Operational Environment: Initial Cyber Operations
Cyber-espionage and intrusion activities have long served as essential precursors to armed warfare, enabling what defence analysts term “pre-positioning” for war. According to Department of Defence representatives, months and sometimes years of careful preparation preceded the actual strikes, with digital specialists working to establish what is known as the “target set” — locating and readying key infrastructure for attack. US and Israeli cyber specialists are believed to have breached essential digital systems across Iran well before any missiles were launched, concentrating especially on systems managing air defences and defence communications. This preparation proved invaluable in ensuring the success of subsequent kinetic operations.
General Dan Caine, chairman of the Joint Chiefs of Staff, outlined how this preparatory phase was fundamental to the conflict’s progression. Cyber operations throughout this phase were not intended as immediately destructive; rather, they served to collect information, establish vulnerabilities and develop routes for future action. The sophistication of these pre-strike operations underscores a significant change in modern warfare, where cyber penetration and intelligence gathering now come before traditional armed conflict. By the time standard military units were deployed, the cyber battlefield had already been thoroughly charted and compromised.
- Cyber operatives compromised Iranian military and air defence communication networks several months prior to strikes
- Pre-positioning involved creating weaknesses and collecting information on critical infrastructure targets
- Digital intelligence gathering supported traditional human intelligence gathering and espionage activities
- Cyber operations created strategic advantages facilitating subsequent conventional military operations
Observation Via Connected Devices
One particularly striking aspect of cyber operations involved the compromise of networked camera systems, including CCTV and traffic systems. According to sources cited by the Financial Times, Israeli operatives reportedly compromised these devices across Iranian cities to establish an comprehensive monitoring system. The objective was to establish comprehensive behavioural profiles for high-ranking Iranian defence and government officials, including Ayatollah Ali Khamenei and his top military leadership. Such live video surveillance data proved essential for operational planning, as these cameras offered what digital security specialists describe as affordable operational visibility of streets, facilities and personnel movements.
Sergey Shykevich, a threat intelligence expert at cyber-security firm Check Point, noted that internet-connected cameras have become prime targets in modern cyber warfare precisely because they offer affordable, real-time intelligence gathering capabilities. This approach represents a significant evolution in intelligence practices, augmenting traditional surveillance methods with cyber-infiltrated infrastructure. When combined with intelligence from human sources and communications intelligence, such digitally-obtained information produces a complete assessment of targets and their routines, substantially improving the precision and effectiveness of military strikes.
Blinding and Silencing: Disruption During Active Conflict
As traditional military operations began, cyber operations transitioned from intelligence gathering to direct interference. General Dan Caine, chairman of the joint chiefs of staff at the Pentagon, described US Cyber Command and US Space Command operatives as the “first movers” in the conflict, responsible for progressively undermining Iran’s defensive systems. These digital operations were designed to compromise Iran’s capacity to identify incoming threats, coordinate responses and maintain command-and-control structures during the crucial initial stages of armed conflict. By infiltrating systems that Iran depended on for operational awareness and defensive synchronisation, cyber warfare established a strategic window of vulnerability that conventional forces could leverage.
Admiral Brad Cooper, commander of US Central Command, publicly acknowledged this multi-domain approach at a press conference, stating that operations proceeded “from seabed to space and cyber-space”. This statement, though deliberately vague regarding specifics, confirmed that digital interference constituted a core element of the broader defence strategy rather than a marginal consideration. The integration of cyber operations and traditional military strikes represented a complex interweaving of contemporary combat capabilities, with digital attacks strategically timed to enhance the impact of subsequent kinetic operations. Such coordination underscores how modern defence strategists regard cyber operations not as an standalone instrument but as a force multiplier amplifying traditional military operations.
| Reported Cyber Action | Suspected Impact |
|---|---|
| Disruption of air defence networks | Reduced Iran’s ability to detect and intercept incoming aircraft and missiles |
| Compromise of military communications systems | Prevented effective coordination between Iranian command centres and field units |
| Degradation of radar and early warning systems | Blinded Iranian forces to incoming threats in real-time |
| Infiltration of command-and-control infrastructure | Disrupted decision-making processes during critical operational phases |
Failed Communication
The targeting of operational communications infrastructure constituted a key aspect of cyber operations in active conflict zones. By compromising and disabling the systems through which Iranian military leadership coordinated responses, cyber operatives successfully separated combat forces from centralised command structures. This loss of communications forced Iranian combat forces to function without real-time intelligence updates or unified strategic guidance, significantly hampering their defensive capability. The isolation of command centres from forward units produced interconnected vulnerabilities throughout the Iranian military structure, blocking unified responses to incoming strikes and leaving defensive systems working in fragmented, uncoordinated fashion.
Such communication disruption exemplifies how cyber operations functions as a multiplying force in contemporary warfare. Rather than serving as the main weapons platform, digital attacks enabled conventional forces to operate with substantially reduced resistance. By silencing Iranian military communications, digital strikes ensured that incoming missiles and aircraft faced degraded defences and disorganised reactions. This integration of digital and kinetic warfare demonstrates the evolving nature of military strategy, where concurrent operations across multiple domains—cyber, space, air and naval—create compounding effects that exceed what any single domain could achieve independently.
Iran’s Restrained Cyber Reaction: Competence or Inability?
Whilst American and Israeli cyber operations have been carried out with apparent sophistication and coordination, Iran’s cyber response has remained notably restrained throughout the conflict. Iranian hackers claimed responsibility for a major cyber assault against US medical technology firm Stryker, marking their first prominent offensive action in the digital domain. However, this fairly constrained action raises important concerns about whether Iran’s apparent caution indicates calculated strategic restraint or reveals essential weaknesses in its cyber warfare capabilities. The contrast between the scale of conventional military operations and cyber activity suggests Tehran may be approaching the digital battleground with significantly more restraint than its Western adversaries.
Analysts ascribe Iran’s measured cyber posture to multiple interrelated factors. The nation’s cyber infrastructure remains substantially less advanced than that of the United States or Israel, possibly limiting offensive capabilities. Additionally, Iran may be calculating that intensive cyber attacks could provoke exceptionally harsh international responses or provide justification for further escalation. The regime’s longstanding dependence on government-backed cyber groups rather than centralised military cyber units also generates operational difficulties during active conflict. Furthermore, Iran’s exposure to defensive cyber strikes—given its dependence on critical infrastructure that could be targeted by superior Western cyber forces—may promote careful restraint and emphasis on protection over ambitious offensive campaigns.
- Iranian digital activities continue to be largely reactive rather than tactically aligned with conventional military operations
- Constrained digital attack capacity indicates systemic weaknesses relative to US and Israeli cyber forces
- Risk of escalation through forceful digital strikes may discourage Iranian action from undertaking more ambitious digital operations
The Stryker healthcare Technology Incident
The cyber-attack against Stryker Corporation represented Iran’s most prominent cyber offensive operation during the conflict. Iranian hackers managed to breach the American medical technology firm’s systems, demonstrating capability to penetrate civilian sector facilities. This attack represented a shift from exclusively military-oriented cyber operations, suggesting Iran’s willingness to target non-military industries. The targeting of medical technology raises notable alarm given the likely ramifications for patient safety and healthcare system disruption, though specific details regarding the attack’s scope and impact remained limited.
The Stryker attack underscores the asymmetric nature of cyber warfare in the Iran conflict. Whilst American and Israeli operatives carried out sophisticated pre-positioned infiltrations of Iranian military networks well ahead of time, Iran’s response proved reactive and restricted in scale. The attack against a civilian firm rather than military infrastructure indicates either deliberate strategic choice or operational constraints. Regardless of intent, the disparity between the scale and sophistication of Western digital operations and Iran’s shown digital response illustrates the considerable technical and structural disparities separating the belligerents in the digital domain.
The Confidentiality Dilemma: Why Nations Remain Tight-Lipped
The marked contrast between Western armed forces openness and digital conflict concealment reveals a core strategic rationale. Whilst the United States and Israel have demonstrated their traditional armed forces strength through glossy videos and press releases—detailing every aircraft carrier and missile strike—cyber operations remain cloaked in intentional secrecy. Admiral Brad Cooper’s indirect allusion to strikes “spanning undersea through space into digital domains” represents among the rare official acknowledgements of digital warfare’s role in the conflict. This reticence is not accidental; it reflects the strictly confidential status of cyber operations and the intelligence sources that underpin them.
The secrecy encircling cyber warfare originates largely from operational necessity. Revealing distinct cyber techniques, techniques, or penetration approaches could compromise ongoing intelligence gathering and lay bare weaknesses in adversary defences. Unlike conventional weapons, which operate in plain sight once deployed, cyber operations often require sustained access to networks for maximum effectiveness. Publicising successes risks alerting targets to breaches and prompting defensive improvements. Additionally, the attribution of cyber-attacks remains genuinely difficult, making public claims arguably disputed. Governments must reconcile the messaging advantage of demonstrating strength with the functional requirement of maintaining covert advantages in the digital domain.
Balancing Transparency and Business Benefits
Military officials face conflicting demands when considering cyber-warfare transparency. Democratic accountability and public openness call for some account of military actions, yet exposing cyber capabilities could undermine their operational effectiveness. The Pentagon’s typical strategy has been to recognise cyber operations exist without specifying their extent, approaches, or specific targets. This balanced position allows governments to take credit for technological contributions to military achievement whilst protecting operational secrecy. However, this approach threatens to giving the public with limited comprehension of contemporary warfare’s genuine character and the extent to which digital operations shape modern conflicts.
The intelligence community’s preference for secrecy also demonstrates genuine concerns about conflict intensification and global standards. Cyber-warfare operates within a diplomatic and legal grey area, with no widely agreed rules governing cyber attacks on military or civilian infrastructure. By remaining vague about digital operations, nations refrain from establishing clear precedents that could provoke global criticism or retaliatory escalation. This calculated ambiguity allows powerful cyber-capable nations to preserve operational flexibility whilst avoiding the diplomatic repercussions that would follow transparent acknowledgement of their cyber warfare capabilities and intentions.
Modern Combat’s Latest Landscape: How This War Exposes
The Iran conflict demonstrates how thoroughly cyber operations have become integrated into current military strategy. Unlike conventional combat, where superiority in jets, missiles and naval vessels can be openly displayed, cyber-warfare operates in the shadows. Yet its impact proves comparably important. The preparatory phase that preceded kinetic strikes relied substantially on digital intrusion, establishment of surveillance networks, and interference with Iranian communications and air defence systems. This hidden dimension of contemporary warfare represents a fundamental shift in how nations wage war, where success often depends on actions invisible to the naked eye and difficult for the public to comprehend or verify.
What comes from this confrontation is a distinct understanding of cyber operations as a force multiplier rather than a standalone weapon. Intelligence gathered through hacked cameras and infiltrated networks provided essential situational awareness that supported traditional espionage and informed targeting decisions. The collaboration of cyber specialists and conventional military forces suggests that future conflicts will increasingly blur the lines between digital and physical domains. As Admiral Brad Cooper’s reference to strikes “spanning seabed, space, and cyber-space” indicates, military planners now view cyber capabilities as integral to comprehensive operational success, fundamentally reshaping expectations about what modern warfare entails.
- Cyber-espionage enables extended periods of pre-positioning prior to any physical military attacks start
- Intercepted camera cameras establish live intelligence systems with minimal operational expense
- Digital attacks blind adversary communications and air defence systems simultaneously
- Cyber capabilities augment traditional intelligence gathering instead of substituting it completely