The Message That Wasn't
Late on a Sunday night in Karachi, viewers of Geo News—Pakistan's most-watched television channel—found their screens hijacked. The broadcast cut away without warning, replaced by what the channel's management would later describe only as an "inappropriate" and "subversive" message . Within hours, Pakistan's National Computer Emergency Response Team had launched an investigation into what appeared to be a coordinated assault: multiple television channels, websites, and mobile applications had been compromised simultaneously .
Geo News management acknowledged that for the previous 24 hours, persistent attempts had been made to breach their systems . The channel moved quickly to disavow any connection to the unauthorised content , but the incident revealed something more troubling than a single broadcaster's security failure. Thousands of miles away, in Minnesota, a different kind of infrastructure was under siege.
Between Sunday, 26 July and Monday, 27 July, technology systems at more than 30 community water facilities across Minnesota came under coordinated cyberattack . The targets were dispersed, the timing precise. And whilst officials in Islamabad and Minneapolis scrambled to understand what had happened to their respective systems, the answers lay not in local grudges or criminal opportunism, but in a conflict that had erupted half a world away—one that had begun not with the traditional fog of war, but with the calculated severing of an entire nation's digital lifelines.
Darkness Before Dawn
On 28 February 2026, U.S. and Israeli jets began a bombing campaign against Iran . The kinetic strikes were devastating: Supreme Leader Ali Khamenei died, along with several senior government officials . But hours before the first bombs fell, a different kind of assault had already begun.
Iran's internet connectivity collapsed to 4% of normal traffic on that same day, signalling an almost total shutdown of nationwide access . Over 90 million people found themselves cut off from the digital world . The blackout would last 47 days before Iran began restoring even limited access —a period during which the country existed in a state of enforced isolation unprecedented in the modern internet age.
The shutdown was "regime-imposed," according to multiple sources , though the designation raises as many questions as it answers. Was this Tehran's attempt to control information flow during a national crisis? Or had U.S. and Israeli cyber operations so thoroughly compromised Iran's digital infrastructure that disconnection became the only defensive option available? The evidence suggests both realities coexisted: Iran's government pulling the plug even as foreign actors maintained the capability to leave it dark.
Cyber operations, it emerged, had played a significant role from the beginning of the war, disrupting communications and sensor networks across Iran . Traffic cameras went dark. Television broadcasts failed. The digital sinews that connect a modern state to its citizens—and its military to its sensors—were severed with surgical precision before conventional weapons ever left their hardpoints.
The Arsenal Nobody Sees
The U.S.-Israel strike of 28 February represented the culmination of years of preparation in the cyber domain . But understanding what happened requires acknowledging what Iranian state-sponsored actors had been doing for years beforehand: conducting disruptive cyber-enabled information operations to further Iran's geopolitical objectives and the regime's interests .
These weren't sophisticated, zero-day exploits targeting hardened military networks. Iranian threat actors had instead focused on something more insidious: they opportunistically targeted poorly secured critical infrastructure networks and internet-connected devices around the world, including those associated with water and energy sectors . The strategy was one of patient accumulation—building access, maintaining presence, waiting for the moment when accumulated capabilities could be unleashed for maximum effect.
That the Minnesota water systems came under attack in July—months after the February strikes—suggests Iran had indeed stored capabilities and was waiting for high-risk moments to launch attacks on U.S. businesses and infrastructure . The water facilities represented soft targets with hard consequences: municipal systems that, if compromised, could affect public health and erode confidence in critical services. The message was clear: if you can reach into our country, we can reach into yours.
Yet Iran's cyber doctrine had always been more opportunistic than elegant. In March 2026, researchers at Unit 42 discovered a new cluster of threat activity designated CL-STA-1128, targeting Rockwell Automation's operational technology and industrial control system equipment . These are the devices that run factories, manage power grids, control manufacturing processes—the unglamorous digital backbone of industrial civilisation. The targeting suggested Iranian actors were probing for vulnerabilities that could translate into real-world disruption: production halts, safety incidents, economic damage that compounds over time.
"Iran will very likely use its cyber programme to respond to the joint U.S. and Israel combat operations against Iran."
This assessment, made by analysts tracking the conflict , has proven grimly accurate. But it also points to a troubling asymmetry: whilst the U.S. and Israel demonstrated the ability to effectively blind Iran through comprehensive cyber operations coordinated with kinetic strikes, Iranian responses have been characterised by diffusion and persistence rather than decisive effect. The Geo News hack, the Minnesota water systems, the industrial control system probing—these are the actions of an actor striking where it can, rather than where it wishes.
The Stretched Defenders
As the Iranian hacking threat escalated, America's lead cyber agency found itself stretched dangerously thin . This wasn't supposed to be how it worked. The U.S. Cyber Command, the National Security Agency, and the Department of Homeland Security's cybersecurity division had spent years building offensive and defensive capabilities intended to establish dominance in the digital domain. The February strikes demonstrated that offensive capability convincingly. But defence—the unglamorous work of protecting thousands of municipal water systems, regional power grids, hospital networks, and industrial facilities—proved a different challenge entirely.
The problem is one of surface area. Iran doesn't need to breach the Pentagon or take down the power grid for the Eastern Seaboard. Thirty water systems in Minnesota accomplish something almost as valuable: they demonstrate reach, they generate headlines, they force defensive resources to be distributed across an impossibly wide territory. Every small attack requires investigation, remediation, public reassurance. The cumulative cost in attention and resources begins to approach the impact of a single, spectacular breach.
This is asymmetric warfare translated into the cyber domain. The U.S. and Israel can plunge Iran into darkness, but Iran can ensure that American defenders never rest, that the alertness required to protect sprawling, decentralised, often poorly-secured infrastructure becomes its own form of attrition.
Echoes Across Borders
The hacking of Geo News and other Pakistani media outlets represents perhaps the most intriguing dimension of the conflict's cyber component . Pakistan is not a formal party to the U.S.-Israel confrontation with Iran, yet its media infrastructure became a battleground. The coordination—multiple channels and platforms compromised simultaneously—suggests capabilities beyond what criminal hackers or local actors typically demonstrate.
Was this Iranian retaliation targeting a neighbour perceived as insufficiently supportive? Or were these attacks false-flag operations, designed to sow confusion about attribution whilst degrading media capacity in a strategically important country? Pakistan's CERT investigation continues , but the incident underscores how modern conflict refuses to respect geographical boundaries or traditional notions of belligerence.
In an era when a compromised television broadcast in Karachi and a cyberattack on water systems in Minnesota can be understood only in the context of strikes on Tehran, the very concept of a "theatre of war" dissolves. Every internet-connected device becomes a potential foothold, every poorly-secured system a potential target, every country with digital infrastructure a potential battleground.
The Doctrine of Persistent Disruption
What emerges from examining these incidents collectively is a new doctrine of conflict, one that has been theorised for years but is now demonstrably operational. The war against Iran began in cyberspace before it began in physical space, and it has continued in cyberspace long after the conventional bombing campaign's initial phase concluded.
The U.S. and Israeli approach demonstrated how cyber operations can enable kinetic strikes: degrade enemy sensors, disrupt communications, create confusion about what is happening and where forces are positioned. The 47-day internet blackout—whether imposed by Tehran, maintained by foreign operators, or some combination—represented a comprehensive information denial that would have been unimaginable in any previous conflict .
But Iran's response has illustrated a different principle: that even a weaker cyber actor can impose costs through persistence and diffusion. You don't need to take down critical infrastructure if you can force your adversary to defend all of it simultaneously. You don't need spectacular breaches if you can generate steady anxiety through small, repeated intrusions. The water systems in Minnesota didn't fail , but their targeting achieved something nonetheless—a demonstration that American infrastructure remains vulnerable, that the homeland is not a sanctuary, that the costs of distant wars can manifest in local crises.
This is the logic of persistent disruption: accept that you cannot win decisively in the cyber domain, but ensure your adversary cannot either. Make defence expensive, make it exhausting, make it a constant drain on attention and resources. Wait for high-risk moments and strike where defences are weakest. Build a presence across thousands of poorly-secured systems and use that access to create doubt about what else might be compromised.
The War That Doesn't End
Traditional wars have conclusions: treaties signed, forces withdrawn, rebuilding begun. Cyber warfare offers no such clarity. Iran's internet has been restored, at least partially , but the traffic cameras compromised in February may remain vulnerable. The industrial control systems probed in March may still harbour backdoors. The water systems attacked in July have been secured—or have they? And what about the systems that haven't been attacked yet, that may have been penetrated months or years ago, lying dormant until the moment of activation?
The U.S. lead cyber agency remains stretched thin , a condition that seems likely to persist. Because Iran hasn't exhausted its capabilities; it has merely demonstrated them selectively. And other actors—watching this conflict closely—are learning lessons about what works, what doesn't, and what new vulnerabilities emerge as defenders rush to patch old ones.
The bombing campaign that killed Iran's supreme leader was a definitive act with clear consequences . But the cyber operations that preceded, accompanied, and followed those strikes exist in a murkier realm. Some have been acknowledged, others inferred, many remain entirely invisible. The message that appeared on Geo News screens has been disavowed but never fully explained . The mechanisms that plunged Iran into digital darkness have not been detailed. The full extent of Iranian penetration into Western infrastructure remains unknown.
"Iranian state-sponsored cyber threat actors opportunistically target poorly secured critical infrastructure networks and internet-connected devices around the world."
This was true before February 2026 , and it remains true now. The war with Iran may have begun with conventional strikes, but the cyber conflict that accompanied it has no clear terminus. It continues in the background of daily life: in the security updates pushed to industrial controllers, in the monitoring systems watching municipal water facilities, in the investigations still ongoing in Islamabad and Minneapolis and dozens of other locations that haven't made headlines.
We have entered an era where wars begin before they are declared and continue after they have supposedly ended, where the battlefield is everywhere and nowhere, where the distinction between combatant and civilian infrastructure collapses because everything connected to the internet is potentially part of the battlefield. The 2026 Iran war demonstrated cyber operations' potential with unprecedented clarity. But it also demonstrated something more troubling: that once begun, such conflicts may never truly conclude. The weapons are already in place, embedded in systems we depend on, waiting for the next high-risk moment, the next calculated strike, the next message that appears unbidden on screens across a darkened world.