U.S. officials said U.S. Cyber Command conducted cyber operations that disrupted Iranian communications and sensor networks ahead of joint U.S.-Israel military strikes on Iran, with the stated effect of degrading Iran’s ability to assess, coordinate, and respond to the kinetic campaign. The Pentagon also warned that the U.S. and Israel were preparing for retaliatory Iranian cyberattacks, indicating an elevated risk environment for regional critical infrastructure and organizations with Middle East exposure.
Separate reporting described the broader conflict and weapons employed during the strikes and subsequent Iranian retaliation, but did not add technical detail on the cyber operations beyond the context of the campaign. A different SC Media brief covered the FBI’s Operation Winter SHIELD and calls for faster intelligence sharing to counter Chinese cyber threats; that item is not part of the Iran-focused Cyber Command activity described above.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Following the military and cyber operations, U.S. and Israeli officials were reported to be preparing for possible Iranian cyber retaliation. The expectation of follow-on cyber activity reflected the broader escalation of the conflict.
Bellingcat highlighted repeated false identifications of munitions remnants on social media, including drop tanks mislabeled as missiles and interceptor debris miscast as Iranian weapons. It also noted a pre-1974 U.S.-made MIM-23B HAWK component was falsely claimed to be an ATACMS remnant.
As the conflict continued, reports surfaced that unexploded Tomahawk warheads had been found in Iraq and Syria. Bellingcat cited these findings while tracking munitions and strike remnants across the region.
Bellingcat reported the first known combat use of the U.S. LUCAS one-way attack drone during the conflict. The system was described as a Shahed-like platform identified through open-source imagery.
In the first two days after the strikes, Iran reportedly launched hundreds of missiles and drones at Israel and multiple Gulf states. Bellingcat also documented Shahed drone impacts and missile booster debris falling in neighboring countries as the conflict widened.
The strikes were reported to have killed Iranian Supreme Leader Ayatollah Ali Khamenei along with other senior Iranian officials. Both references treat his reported death as a major consequence of the initial U.S.-Israeli attack.
The United States and Israel reportedly carried out major strikes across Iran, with Bellingcat citing more than 2,000 Israeli bombs dropped in the first 30 hours and over 1,000 U.S. targets struck in the first 24 hours. Open-source imagery reviewed by Bellingcat indicated use of weapons including Tomahawk missiles, JDAM-equipped bombs, AGM-154C JSOW, Precision Strike Missile, SPICE-guided bombs, and RAMPAGE missiles.
Ahead of joint U.S.-Israel military action, U.S. Cyber Command conducted operations that disrupted Iranian communications and sensor networks, according to Gen. Dan Caine. He said the activity hindered Iran's ability to assess, coordinate, or respond to the coming strikes.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebellingcat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.