While a high-profile military campaign involving the United States, Israel, and Iran dominated global news headlines with missile strikes on government and nuclear sites, a parallel and invisible war was simultaneously being fought in the digital realm. Alongside physical confrontations, coordinated cyberattacks crippled networks, hacked media platforms, and disrupted vital infrastructure, signaling a dangerous escalation in modern warfare.
Cyberattacks Target US Water Systems and Small Cities
As tensions escalated, Iranian cyber operators and affiliated groups shifted their focus toward Western infrastructure, successfully infiltrating sensitive systems and disrupting municipal services. In July, a wave of cyberattacks targeted water and wastewater treatment facilities across at least 12 US states, disrupting operations in more than 30 systems in Minnesota alone.
Although US officials have not formally assigned direct blame to Tehran for every incident, hacker groups linked to the Islamic Revolutionary Guard Corps—such as CyberAvengers and its affiliate APT Iran—claimed responsibility for the Minnesota water facility breaches on encrypted messaging channels. Threat actors warned that American power grids, telecommunications networks, and water utilities remain vulnerable targets, asserting that military actions against Iran would carry a heavy price.
Psychological Tactics and Digital Disruption
The digital campaign featured extensive psychological operations and cyber sabotage from its earliest hours:
Media Hacks: Networks belonging to several Iranian news agencies were hacked to spread disinformation designed to demoralize local supporters.
App Infiltration: Popular local applications, including an Iranian prayer app with over 30 million users, were compromised to send push notifications to military personnel calling for surrender.
State TV Interruption: Broadcast streams on state television channels were briefly altered to display speeches by international leaders, prompting authorities to impose temporary nationwide internet blackouts to curb dissent.
Global Impact and Escalation in the Middle East
The cyber fallout quickly extended beyond the immediate combatants. Within 24 hours of the conflict’s onset, cyberattacks targeting Israel surged more than threefold. For the first time, Gulf nations including the United Arab Emirates, Kuwait, and Saudi Arabia also reported significant spikes in targeted digital incursions.
Security analyses of nearly 180 distinct cyber incidents revealed that a substantial portion relied on denial-of-service (DDoS) tactics, successfully compromising control systems, security cameras, and automated monitoring equipment across Western facilities.
A Decade-Long History of Cyber Conflict
This invisible conflict did not emerge overnight. Its origins trace back to the landmark 2010 Stuxnet cyberweapon incident that targeted Iran’s Natanz nuclear facility. In response, Tehran steadily expanded its cyber warfare capabilities, deploying operations such as Operation Ababil against US financial institutions in 2012, the Shamoon attacks against energy giant Saudi Aramco, and large-scale data exfiltration campaigns targeting university networks between 2013 and 2017.
These capabilities saw further surges during regional escalations in 2025, leaving state-sponsored and affiliated hacking groups well-prepared for prolonged digital confrontation.
Supply Chain Vulnerabilities and Healthcare Attacks
Critical manufacturing and supply chains also found themselves in the crosshairs. A major cyberattack struck global medical equipment manufacturer Stryker, disrupting international operations. Although the company does not produce armaments, it supplies essential medical hardware to hospitals worldwide. Exerting indirect pressure by disrupting healthcare logistics has emerged as a prominent tactic in modern asymmetric cyber warfare.
Exploiting Legacy Protocols and Emerging AI Threats
Security agencies have raised alarm bells over hackers targeting industrial control computers known as programmable logic controllers (PLCs), forcing operators in numerous water facilities to switch to manual oversight. Furthermore, threat actors have exploited vulnerabilities in legacy telecommunications infrastructure, such as the aging SS7 signaling protocol, to track the precise geographic locations of military personnel deployed abroad without needing to compromise individual mobile devices directly.
As asymmetric strategies take precedence over conventional military parity, state and non-state actors are increasingly leveraging artificial intelligence (AI) to accelerate espionage, develop sophisticated malware, and generate deceptive content. As upcoming political cycles approach, these evolving digital threats present unprecedented challenges to both critical physical infrastructure and democratic institutions.