The conflict between the United States and Iran entered a new and dangerous phase on February 28, 2026, when the United States and Israel launched large-scale joint strikes against targets in Iran.
What initially appeared to be a predominantly military confrontation has since evolved into a multidimensional conflict extending far beyond the skies over Iran and the battlefields of the Middle East. Iran’s documented capabilities include cyber operations, proxy warfare, intelligence activity, and the use of transnational networks. Other reported activities remain unverified or are still under assessment by U.S. and allied authorities.
For American homeland security, one distinction is especially important: a possible threat, a credible threat, an identified operational network, a sleeper cell, a formally designated terrorist organization, and a confirmed terrorist operation are not the same thing. They require different levels of evidence and carry different levels of confidence. Yet the combination of documented Iranian asymmetric capabilities, assessed hostile intent, reported clandestine activity, and potential threats beyond the Middle East has created a security environment that the Department of Homeland Security cannot afford to dismiss as merely theoretical. The conflict may be centered overseas, but its consequences could reach the American homeland and must be treated as a serious counterterrorism and homeland-security concern.

During this period, the conventional military balance has clearly shifted against Tehran. But the degradation of the regime’s military infrastructure should not be confused with the elimination of the threat it poses. On the contrary, weakening conventional capabilities may increase the relative importance of asymmetric tools. The Iranian regime has never relied solely on missiles, naval assets, air-defense systems, or conventional military power. For decades, it has built a parallel architecture of influence and coercion through intelligence operations, proxy organizations, ideological militias, cyber capabilities, covert networks, and global propaganda.
Some elements of that architecture are extensively documented. Others remain assessed, alleged, or only partially understood by Western intelligence and law-enforcement authorities. This distinction matters. A documented capability does not automatically demonstrate an active operation. An identified network is not necessarily a sleeper cell, and assessed hostile intent is not the same as evidence of an imminent attack. Still, the destruction of launchers, vessels, command facilities, or air-defense batteries does not by itself dismantle the clandestine infrastructure through which Tehran has historically projected power beyond Iran’s borders. As the conflict evolves, that reality may become even more consequential.
For DHS, this evolving threat environment presents a strategic challenge that extends well beyond the conventional battlefield. The conflict with Tehran cannot be understood only as a distant military campaign whose consequences end at the borders of the Middle East. The Iranian regime has a documented history of conducting intelligence operations, supporting coercive activity, and sponsoring terrorism beyond its borders. The Islamic Revolutionary Guard Corps, the Quds Force, the Ministry of Intelligence and Security (MOIS), and affiliated organizations have been linked to operations and networks across multiple continents.
Yet analytical precision remains essential. The documented existence of Iranian intelligence or terrorist activity abroad does not, by itself, prove the presence of an active operational cell on U.S. soil. An alleged clandestine network must be distinguished from an identified network; an identified network from a sleeper cell; and a sleeper cell from a confirmed operational plot. DHS’s central task is not to blur these categories, but to assess them with discipline: to determine when a possible threat becomes credible, when hostile intent develops into operational preparation, and when an assessed network begins showing signs of mobilization. In counterterrorism, recognizing that transition before an attack occurs is precisely where intelligence can save lives.

Among the most serious concerns is the possibility that Iranian intelligence services or regime-affiliated networks may maintain dormant relationships or clandestine infrastructure that could be activated during a period of acute confrontation. Iranian intelligence services, including MOIS and the IRGC Intelligence Organization, have a documented history of developing covert networks and conducting or supporting operations outside Iran. That history, however, should not be transformed automatically into the claim that every suspected network is an active sleeper cell within the United States.
A sleeper cell should be understood narrowly: a clandestine operational element deliberately positioned to remain dormant until activated. An identified network may consist of facilitators, intermediaries, intelligence contacts, or other individuals without evidence of an imminent terrorist mission. A possible threat may exist even when neither an operational cell nor a specific plot has been confirmed. Even so, the present conflict may make dormant relationships, facilitators, and covert infrastructure more operationally relevant. For DHS and its federal partners, the critical task is to identify credible indicators of activation—surveillance of potential targets, unusual communications, logistical preparation, acquisition of weapons or dual-use technology, suspicious financial activity, or other forms of pre-operational behavior—without confusing suspicion with evidence or possibility with a confirmed operation.

Within this threat environment, Jewish and Israeli institutions deserve particular attention. The Iranian regime’s ideological hostility toward Israel and its decades-long demonization of Jewish communities are well-established features of its official rhetoric. Iranian-linked terrorist operations and alleged plots have also, at different times and in different countries, involved Jewish institutions, Israeli diplomatic facilities, and individuals associated with Israel.
That history establishes a credible threat context, but it does not prove that a specific attack against a Jewish target in the United States is imminent, nor does it mean that every suspicious activity represents an Iranian-directed operation. DHS and its counterterrorism partners must preserve that distinction. A broad threat environment is not a specific plot; hostile rhetoric is not operational preparation; and an alleged Iranian connection is not proof of a confirmed command relationship. Nevertheless, during an escalating military confrontation, synagogues, Jewish schools, community centers, Israeli diplomatic facilities, and other symbolically significant locations may be plausible targets for surveillance, intimidation, disruption, or terrorist violence by regime-directed operatives, affiliated networks, proxies, or independently motivated extremists.
Protecting these communities requires neither alarmism nor speculation. It requires sustained vigilance, intelligence sharing, careful assessment of pre-operational indicators, and rapid investigation when a possible threat develops into one that is credible and actionable.
Cyberwarfare is another immediate dimension of this threat. Iranian cyber actors may intensify their activity during periods of conflict, demonstrating how asymmetric retaliation can disrupt U.S. critical infrastructure without a conventional military attack. Reported or alleged cyber incidents must, of course, be distinguished from operations formally attributed to Tehran; attribution is an intelligence judgment that requires evidence and a stated degree of confidence. Even so, Iranian cyber capabilities are well documented, and heightened vigilance is warranted.

Hospitals, healthcare networks, transportation systems, communications providers, energy infrastructure, and major industrial suppliers may offer adversaries opportunities to cause disruption at relatively low cost. For DHS and the Cybersecurity and Infrastructure Security Agency, priorities should include resilience, rapid assessment and attribution where feasible, intelligence sharing, and early detection of activity suggesting that a broad cyber risk is developing into a specific operational campaign.
Proxy warfare remains another established component of Tehran’s asymmetric strategy. Iranian-aligned forces have reportedly targeted U.S. and allied interests in the region, reflecting a familiar pattern: when confronted directly, the regime may rely on affiliated militias and transnational networks to widen the conflict while retaining a degree of plausible deniability. Here again, attribution matters. A reported attack, an alleged Iranian connection, and a confirmed operation directed by Tehran represent different evidentiary thresholds.
For DHS, however, the broader lesson is clear. Pressure on the regime may disperse rather than eliminate the threat, shifting risk from visible military confrontation toward less visible networks, proxies, cyber activity, and clandestine operations.
DHS therefore stands at a critical intersection of border security, intelligence coordination, infrastructure protection, and domestic counterterrorism. Its central challenge is not simply to recognize that Tehran possesses asymmetric capabilities, but to detect when capability and hostile intent begin to move toward operational preparation. Meeting that challenge requires deeper intelligence integration among DHS, the FBI, CISA, the intelligence community, state and local law-enforcement agencies, and private-sector infrastructure operators.
Border security should likewise be understood as part of a broader counterterrorism strategy. Potential clandestine networks, cyber activity, suspicious surveillance, financial facilitation, and other pre-operational indicators require disciplined assessment. The goal is not speculation or alarmism. It is to identify the point at which a possible threat becomes credible, when a network becomes operational, and when early warning signs develop into an actionable threat—before that threat becomes an attack.
Effective counterterrorism must focus on conduct, evidence, financing, networks, and operational behavior—not nationality, ethnicity, religion, immigration status, or political belief. Countering threats linked to the Islamic Republic must never become a pretext for collective suspicion toward Iranian Americans, Iranian dissidents, Muslims, immigrants, or any other community not implicated by evidence.
Military campaigns may destroy weapons, infrastructure, and command facilities. Homeland security must prepare for the capabilities and networks that may outlast them: covert infrastructure, cyber capacity, proxy relationships, and the potential for renewed coercion beyond the battlefield. The task is not to predict every attack. It is to recognize the shift from hostile capability to operational preparation early enough to prevent one.




