As a researcher who has spent more than two decades studying counterterrorism and radical Islamist organizations in the Middle East, I want to address the Department of Homeland Security directly, along with its new secretary, Markwayne Mullin, who understands the nature of the regime ruling Iran.

The threat posed by the Islamic Republic on American soil is not hypothetical. Its record reveals an operational pattern of proxy terrorism, criminal recruitment, target surveillance, and assassination plots.

In March 2026, a federal jury in Brooklyn convicted Asif Merchant, a Pakistani man who testified that a Revolutionary Guard intelligence operative trained and tasked him, in a plot to assassinate American political figures. Evidence in the case identified President Donald Trump among the potential targets. The FBI has likewise warned of Iranian plots against former U.S. officials.

The danger is more acute after seven months of war have left Tehran weakened, humiliated, and increasingly isolated, while Russia and China have proved less dependable than its rulers imagined. A regime sustained largely by two machines, propaganda and repression, now confronts an Iran approaching potentially historic upheaval.

Sleeper cells and the threat architecture

The ruling Shiite clerical establishment has long employed terrorism, intimidation, and what we commonly call "sleeper cells" as instruments of pressure and ideological coercion. Its worldview divides humanity between its own supposed truth and a universe of enemies, infidels, and conspirators.

The resulting threat extends far beyond a conventional terrorist cell awaiting orders from Tehran. It encompasses dormant networks, facilitators, criminal proxies, logistical intermediaries, and pre-positioned assets. American intelligence and law-enforcement agencies have themselves described an Iranian threat involving terrorism, intelligence operations, kidnapping, assassination, cyberattacks, and the targeting of dissidents inside the United States. Most dangerous, however, is a regime approaching possible collapse with neither the restraint nor the fear of consequences that would prevent another crime.

An FBI agent standing watch outside an apartment complex during an immigration raid Wednesday in Denver.
An FBI agent standing watch outside an apartment complex during an immigration raid Wednesday in Denver.DAVID ZALUBOWSKI/AP

DHS and the FBI therefore cannot afford to underestimate networks inside the United States whose activation may ultimately be directed from Tehran, Qom, Mashhad, or elsewhere within the regime's security and ideological apparatus. At the center is a triangle: the Quds Force, the IRGC, and the Ministry of Intelligence. All three have long histories of working through proxies, intermediaries, criminal actors, and overlapping networks abroad.

The intersection of transnational religious, terrorist, and criminal networks increasingly blurs traditional counterterrorism categories. From Tehran's perspective, a sleeper network is not merely a group awaiting orders to attack. It is a card to be played, an instrument of pressure, and a means of ideological influence. Its operational spectrum can run from an intelligence officer dispatched abroad to an ideological supporter already inside America, from a logistical facilitator or criminal proxy to a lone actor living an apparently ordinary life until circumstances change or an instruction arrives.

Beyond the conventional operative

Washington must therefore look beyond the conventional profile of an Iranian operative. Universities, lobbying networks, media outlets, religious institutions, charities, clerics, and political organizations can provide environments that hostile intelligence services seek to penetrate, influence, or exploit. When American-funded or American-based media give sympathetic platforms to Hamas, Hezbollah, or the IRGC, questions of influence deserve scrutiny, not dismissal.

This does not make everyone in such environments an Iranian agent. It means counterintelligence cannot afford complacency where influence operations, recruitment, propaganda, logistics, and covert activity may intersect. Whether the final actor is an intelligence officer, criminal proxy, ideological recruit, or lone actor matters less than identifying the architecture that can connect someone inside America to a decision made thousands of miles away.

A doctrine, not isolated cases

The lives of President Trump and other American officials are part of this threat. Washington should stop treating the cases already uncovered as unrelated criminal prosecutions. Together, they reveal an operational doctrine.

Tehran wants supporters and enemies alike to believe that nowhere is beyond its reach. Radical Islam sought to convey a similarly terrifying message through Sept. 11: that even America could be penetrated and struck.

IRGC efforts to recruit people inside the United States to kill specific targets are hardly unknown to DHS or the FBI, and American law enforcement deserves credit for disrupting such plots. But operational success must not breed strategic complacency. Every disrupted plot is also intelligence, a window into the tradecraft, networks, and architecture of the next one.

Dissidents are a homeland-security issue

Iranian dissidents in America must be viewed through the same homeland-security lens. After two decades of researching the regime's treatment of its opponents, I regard targeting an Iranian-American dissident on U.S. soil as no less a violation of American security than targeting an American official.

Tehran fears exposure because it strips away the mythology sustaining the regime. We saw the same instinct during the bloodshed of January 2026, when communications, mobile service, electricity, and internet access were cut as repression intensified. Trump repeatedly cited estimates that tens of thousands of Iranians had been slaughtered while the clerical establishment and IRGC fought for survival. A regime prepared to unleash extraordinary violence against its own population should not be presumed to observe civilized restraints against its enemies abroad.

Homeland Security Secretary Markwayne Mullin speaks at a news conference in New York on Sept. 1, 2026.
Homeland Security Secretary Markwayne Mullin speaks at a news conference in New York on Sept. 1, 2026.AP Photo/Ted Shaffrey

Plausible deniability by design

The Islamic Republic's operational method is multilayered by design. Tehran need not deploy an official IRGC assassination team. It can use intermediaries, criminal gangs, cash payments, non-Iranian operatives, or actors whose connection to the regime can be denied. Plausible deniability is integral to its tradecraft, and American intelligence has repeatedly documented the Quds Force's use of partners and proxies abroad.

This is why DHS, the FBI, CBP, the State Department, and the intelligence community must approach Iranian terrorism as a converging threat. That means linking intelligence coordination, financial networks, surveillance, criminal intermediaries, cyberwarfare, protection of officials, and preparedness for unconventional threats, including biological or chemical scenarios.

Strategic ambiguity in Washington

The vulnerability, however, is not merely bureaucratic. Washington remains uncertain about its ultimate Iran policy. Trump and the White House have yet to demonstrate consistent resolve on regime change, while the aspirations of the Iranian people remain subordinated to the search for an elusive "deal." Tehran watches that strategic ambiguity carefully.

In my assessment, the most dangerous trigger for desperate action is the increasingly serious prospect of regime collapse, a reality that a mafia-like system steeped in radical and apocalyptic thinking refuses to accept. Direct confrontation with America, blows against the IRGC, domestic upheaval, and the desire for revenge all increase the incentive for asymmetric retaliation.

DHS and the FBI have already confronted plots associated with revenge for Qassem Soleimani's killing. But the system neither began nor ended with Soleimani, Ali Khamenei, or Hossein Salami. Gholam-Hossein Mohseni-Eje'i, Ahmad-Reza Radan, Mohammad Bagher Ghalibaf, Masoud Pezeshkian, Esmail Qaani, Hossein Taeb, and other powerful figures remain embedded in Iran's political-security establishment.

The catastrophic scenario

The catastrophic scenario may therefore be more complex than American agencies anticipate. Homeland-security planning cannot be confined to assassinating an official, striking a diplomatic target, threatening Jewish or Israeli communities, sabotaging critical infrastructure, or coupling cyberattack with physical violence. The regime thinks in multiple layers and across multiple fronts.

The FBI has already discussed surveillance linked to Jewish and Israeli targets, but DHS bears an especially grave responsibility: homeland security requires seeing the entire threat architecture, not isolated components. Counterintelligence, intermediary networks, targeted protection, allied intelligence-sharing, financial tracking, organized crime, cyber defense, border security, and local law enforcement must function as parts of one defensive architecture.

America has already disrupted multiple Iranian plots, but that success must not be misread. Success in stopping previous plots is not evidence that the threat does not exist; it is evidence that it does.

Washington cannot dismiss targeted assassination, recruitment inside the United States, hired criminals, or combinations of these methods, nor assume every plot will be discovered in time. As the prospect of regime collapse grows more serious, a cornered regime may become more unpredictable, not less.

Warning, however, is not prediction. I do not claim to know when or how an operation will occur. I am warning that among the dangers America faces from Tehran, a major act of violence on American soil must be taken seriously.