Iran’s Shadow War Comes to America

As U.S.-Iran hostilities intensify again, Washington must confront a second front in the conflict: the possibility that Tehran could seek to retaliate through covert networks, cyber operations, and other asymmetric means far beyond the Middle East.
The latest escalation between the United States and Iran has renewed attention to the military balance in the Middle East. But the most consequential Iranian response may not necessarily take the form of another missile barrage, drone attack, or conventional military exchange.
It could take place somewhere else.
As Washington and Tehran enter a more volatile phase of their confrontation, the United States must prepare for the possibility that Iran will seek to impose costs through the instruments in which weaker powers often find their greatest advantage: intelligence operations, cyberattacks, illicit finance, criminal intermediaries, proxy relationships, and covert action.
That possibility gives the conflict an immediate domestic dimension.
The central question is no longer simply how the United States will respond to Iranian actions in the Middle East. It is whether Tehran, facing sustained military and economic pressure, will attempt to extend the confrontation beyond the battlefield—and whether the FBI and its Joint Terrorism Task Forces are positioned to detect and disrupt any credible threat before it matures into violence on American soil.
Iran does not need to defeat the United States in a conventional war to impose costs on Americans.
It can operate in the shadows.
A military setback for Tehran would not automatically eliminate its capacity for retaliation. Airstrikes can destroy military infrastructure, but they cannot erase intelligence contacts, financial channels, cyber capabilities, criminal relationships, or covert facilitators developed over many years.
Indeed, the renewed intensity of the conflict may increase the strategic value of such tools. A state unable—or unwilling—to match American conventional power directly has strong incentives to search for forms of retaliation that are less predictable, less attributable, and more difficult to deter.
This is where the FBI’s role becomes central.
The Bureau and its Joint Terrorism Task Forces were created to confront precisely the problem that arises when foreign threats acquire a domestic dimension. Their task is not to assume that every Iranian connection represents a danger, nor to transform legitimate concern about hostile intelligence activity into collective suspicion of Iranian Americans or any other community.
Such an approach would be both morally wrong and strategically counterproductive.
The task is more demanding: to distinguish between association and intent, between hostile rhetoric and operational preparation, and between a theoretical danger and a threat beginning to take concrete form.
The United States is entering a period in which the risk of escalation cannot be measured solely by the number of aircraft deployed, missiles launched, or military facilities destroyed. Modern conflict rarely remains confined to conventional battlefields. States under pressure increasingly seek opportunities to exploit vulnerabilities in the societies confronting them.
For Iran, those opportunities could include cyber operations, transnational repression, intelligence activity, threats against dissidents, or the use of intermediaries whose relationship with Tehran is deliberately difficult to establish.
The immediate challenge for American counterterrorism is therefore not to predict that an attack will occur. There is an essential difference between recognizing a heightened threat environment and claiming knowledge of a specific plot.
But uncertainty is not a reason for complacency.
The appropriate response to a deteriorating strategic environment is disciplined vigilance: identifying credible indicators of hostile activity, connecting intelligence across jurisdictions, protecting vulnerable targets, and acting when evidence demonstrates that capability, intent, and preparation are beginning to converge.
That is the immediate test now facing the FBI.
The conflict with Iran may be unfolding thousands of miles from the American homeland. But if Tehran concludes that indirect retaliation offers advantages that conventional confrontation does not, the distinction between a foreign war and a domestic security threat could become considerably less clear.
Washington’s objective must be to ensure that it never does.
The Limits of Ambiguity
The particular difficulty of confronting covert action is that ambiguity is itself a strategic asset.
A missile attack has an identifiable trajectory. A conventional military operation has an observable chain of command. A covert campaign may instead rely on intermediaries whose connection to the state directing or benefiting from their actions is deliberately obscured.
Criminal organizations can provide logistical assistance. Cyber actors can operate remotely. Financial networks can conceal the movement of resources. Individuals can be recruited for discrete tasks without understanding the larger structure of an operation.
The objective is not always mass destruction.
Sometimes it is intimidation.
That is why Iran’s record of transnational repression deserves particular attention. A foreign government that threatens, surveils, harasses, or attempts to coerce its opponents beyond its borders is doing more than pursuing political adversaries. It is challenging the sovereignty of the country in which those individuals reside.
The United States cannot accept the proposition that political opponents of a foreign government become less secure simply because they have crossed an international border.
Iranian dissidents, journalists, activists, former officials, and others regarded by Tehran as adversaries may therefore require heightened attention when credible threats emerge. The same principle applies to individuals and institutions that could be selected because of their perceived connection to American or Israeli interests.
Jewish and Israeli institutions also require sustained, intelligence-driven attention. This does not mean that every synagogue, school, community center, or Israeli-linked institution faces an imminent threat. No responsible security assessment should confuse a hostile environment with evidence of a specific plot.
But Iran’s hostility toward Israel, its record of supporting armed partners, and its history of alleged operations against perceived adversaries establish a threat context that cannot be ignored.
The appropriate response is neither panic nor indiscriminate suspicion.
It is to recognize when concern becomes actionable.
The Cyber Front Is Already Here
The threat is not limited to physical violence.
Iran can impose significant costs without placing a single operative on American soil. Cyber operations offer the possibility of disruption while preserving distance and, in some cases, plausible deniability.
Hospitals, energy systems, water utilities, transportation networks, communications providers, financial institutions, and industrial suppliers all depend on complex digital infrastructure. A serious intrusion can disrupt essential services, damage public confidence, and impose economic costs without resembling a conventional act of war.
That makes cybersecurity part of the broader strategic contest.
Recent U.S. government warnings and investigations have underscored concerns about Iranian-linked activity targeting critical infrastructure and other American networks. The FBI has also emphasized that Iran-related threats extend across cyber operations, foreign intelligence activity, terrorism, illicit procurement, and transnational repression.
The lesson is not that every cyberattack should be attributed to Tehran. Attribution requires evidence, and the distinction between a suspected Iranian operation and an ordinary criminal intrusion remains essential.
But a deteriorating strategic relationship with Iran increases the importance of identifying malicious activity before isolated intrusions can be converted into a broader campaign.
This requires closer coordination among the FBI, CISA, the intelligence community, state and local authorities, and private-sector operators of critical infrastructure. The cyber threat cannot be addressed by any single institution, particularly when the same hostile campaign may involve intelligence collection, criminal intermediaries, psychological operations, and attacks on physical or digital systems.
The FBI’s Strategic Test
This is where the FBI and its Joint Terrorism Task Forces become indispensable.
The threat crosses institutional boundaries. Counterterrorism investigations require intelligence. Intelligence must be connected to law enforcement authorities. Cyber incidents may begin inside private companies. Potential physical targets may fall under the protection of state and local police. Financial networks can operate across multiple jurisdictions and national borders.
No single agency can maintain a complete picture.
The JTTF model exists precisely to overcome that problem by connecting investigators, analysts, intelligence specialists, and federal, state, and local partners before an emergency forces them to cooperate under pressure. The FBI describes the JTTFs as a front-line component of the country’s counterterrorism architecture, while its Iran Threats Mission Center is designed to integrate the Bureau’s work across counterterrorism, counterintelligence, and cyber threats.
That model may now face an increasingly demanding test.
Iran-related investigations should focus on the convergence of behavior rather than broad categories of identity. Relevant indicators can include threats against identified individuals, suspicious surveillance, illicit financial activity, criminal facilitation, suspicious procurement, cyber reconnaissance, or attempts to identify vulnerabilities at sensitive sites.
The central principle should be straightforward: follow evidence, networks, financing, and operational behavior—not ethnicity, religion, nationality, immigration status, or political belief.
Iranian Americans, Iranian dissidents, Muslims, immigrants, and other communities must not become objects of collective suspicion.
Such an approach would not make America safer. It would waste investigative resources, undermine public cooperation, and compromise the constitutional principles that distinguish the United States from the authoritarian governments it seeks to counter.
Effective security requires discrimination in the analytical sense: the ability to distinguish genuine threats from innocent associations.
That is harder work than broad suspicion. It is also the only approach compatible with both effective law enforcement and a constitutional democracy.
A Conflict Must Not Become a Domestic Failure
The most dangerous assumption Washington could make is that Iran must prevail in a conventional military confrontation in order to impose costs on the United States.
It does not.
A successful cyberattack, assassination plot, intimidation campaign, or covert operation against a symbolic target could produce consequences far out of proportion to the resources required to carry it out.
That is the logic of asymmetric conflict.
The appropriate response is neither hysteria nor passivity. It is disciplined anticipation: identifying hostile networks before they mature, connecting intelligence before warning signs become emergencies, protecting vulnerable targets without encouraging indiscriminate suspicion, and disrupting credible threats before they become operational violence.
Twenty-five years after September 11, the United States should understand that homeland security cannot be measured by the force of its response after an attack.
The more meaningful measure is whether institutions recognize a threat while there is still time to act.
As the confrontation with Iran enters a more dangerous phase, the FBI’s responsibility is therefore clear. It must ensure that Tehran’s capacity to operate in the shadows does not allow a foreign conflict to acquire a domestic front.
Iran does not need missiles to threaten Americans.
The United States must ensure that its shadow war never becomes America’s next tragedy.
