Iran keeps the lid on¶
Iran, and the effect it can still contain
A wiper erases tens of thousands of machines. A hack-and-leak dumps a company’s secrets. An intimidating email arrives signed by a false name. The register is theatrical, and the actor behind it is read as ideological, vengeful, a little reckless. The theatre is not incidental. It is most of the point. But reading it as temperament misses the discipline underneath.
What is telling is not what the operations express but what they are careful not to do. The recurring feature of Iranian activity is a preference for effects that stay reversible, deniable or containable, even when a given operation overshoots the apparent line. The pattern is visible in the outcomes. The single strategic intention behind it is much less so, and the lid, it turns out, is not held by one hand. Calibration is still the signature, but it is the calibration of a repertoire rather than a line drawn once.
Asymmetric, deniable, dialled¶
A state under sustained economic pressure, without the resources for a symmetrical contest against better-armed adversaries, finds in cyber operations a domain where the asymmetry runs in its favour: the costs of entry are modest, the deniability is high, and the effects can be dialled. Cheapness is the wrong word for it, since sophisticated intrusion, long-term access and human targeting are not cheap. Asymmetry does the work. The capability is assembled to match. Rather than a single stable apparatus, Iran runs operations through the Islamic Revolutionary Guard Corps and the Ministry of Intelligence and Security, tasking a rotating set of university-linked institutes and private contractor firms, each a front that can be renamed or disowned.
From Europe rather than from the theatre of a wiper, the apparatus looks less like a demolition crew than an intelligence service. ENISA’s 2025 assessment describes Iran-linked activity in the EU as comparatively low in tempo and narrowly aimed at civil society, NGOs, public administration and transport, naming intrusion sets such as MuddyWater, APT42 and Charming Kitten against European targets. The wiper is the loud end of a repertoire whose quiet end is collection. Destruction is one selectable output, and rarely the one selected.
The lid faces inward¶
The substrate has a second face the external chronology hides. The same state that reaches into other people’s networks spends a great deal of effort controlling its own. When protest builds, or a conflict sharpens, Iran throttles or severs the country’s connection to the outside internet: CERT-EU recorded a near-total shutdown during the June 2025 conflict with Israel, and the ECFR describes a nationwide blackout in January 2026 as part of the government’s response to protest, external connectivity cut along with the rest.
Iran does not only use control of networks to cross other people’s boundaries. It uses control of networks to keep its own intact. Suppressing what a population at home can see, and shaping what an audience abroad believes, are the same instrument pointed in two directions: control over what becomes visible. The lid is not held only over foreign targets. It is held, first and most reliably, over Iran’s own information space.
Wipers with the brakes on¶
The loud end is the wiper, a tool built to destroy rather than steal or extort. In 2012 the Shamoon malware erased the master boot records of around thirty thousand computers at Saudi Aramco, reportedly in retaliation for an earlier wiper strike on Iran’s own oil ministry. Later variants followed the same pattern against regional energy and industrial targets: Shamoon 2 and 3, then ZeroCleare and Dustman, the last against a Bahraini oil company. The wiper is the calibrated weapon par excellence. It causes expensive, visible damage, and it stops well short of the physical casualties that would move a conflict into a register Iran has no interest in entering. Analysts describe the class precisely this way: a means to retaliate and signal disdain below the level of armed conflict, while keeping deniability and holding down the risk of escalation.
The same governor is visible when the target is a person rather than a plant. In 2014 a data-wiping attack hit the Las Vegas Sands casino company, whose owner Sheldon Adelson had publicly proposed detonating a nuclear weapon in the Iranian desert as a warning to Tehran; the then US Director of National Intelligence later attributed the attack to Iran. The operation caused substantial disruption, but its effect stayed within the digital domain rather than producing physical casualties. Whether it was sized to embarrass rather than to cripple is an inference from the context; what can be observed is where the damage stopped.
At the lowest rung, the symbolic touch on physical infrastructure: a group calling itself CyberAv3ngers, tied to the IRGC, compromised Israeli-made control devices at water utilities in the United States and Israel, leaving many simply displaying the message “You have been hacked, down with Israel.” Access to operational technology, used to post a slogan rather than to open a valve. The capability was demonstrated; the line was not crossed.
The operation attacks twice¶
Where the effect wanted is on belief rather than hardware, the calibration holds but the method changes, and it is here that the apparatus is most itself. An operation of this kind attacks twice. The first attack is whatever was actually compromised, often modest. The second is the story the target tells itself afterwards about who did it, how deep they got, and what they could do next. If the victim cannot establish what happened, who was behind it, or how much was taken, the room to respond narrows on its own. The lid, at this end, is an information lid.
The contractor front is the calibrated identity that makes the second attack work. The firm behind the 2020 US election operation illustrates it: it began as Eeleyanet Gostar, was charged under the name Emennet Pasargad, and by mid-2024 was operating as Aria Sepehr Ayandehsazan, a fresh shell for the same activity. Alongside the renaming runs a churn of invented hacktivist personas, and the FBI has noted the group’s habit of making exaggerated or fictitious claims of access to inflate the apparent damage. A false name does more than hide the operator. It lets the operator manufacture the attacker the victim imagines.
The operations themselves are audience-shaped. Ahead of the 2020 US election, operators working through the same contractor obtained voter data and sent threatening emails purporting to come from the Proud Boys, a domestic extremist group, to intimidate voters: an election touched without a vote altered. In 2024 the same actor, by the EU Council’s account, reached into the information environment around an internationally visible event, compromising advertising displays during the Paris Olympics to spread disinformation, advertising a French subscriber database for sale, and hitting a Swedish SMS service that reached a large number of EU citizens. During the June 2025 conflict, CERT-EU records Iranian operators posing as an i24NEWS journalist to lure senior Israeli officers into installing spyware. Screen, SMS, inbox, a reporter’s byline: the technical compromise is the means, and the audience is the target. The renaming is not housekeeping. It is the management of what an adversary can be made to believe.
A band, not a ceiling¶
Two things complicate the picture, and the first is the ceiling itself. The image of a fixed line the operations stay under is an inference about Iranian risk calculation, and the recent record strains it. Iran operates, on the record, within a band whose upper edge moves with the conflict, and some actors occasionally leave it. In July 2022 Iran ran a destructive wiper-and-leak attack on Albania, a NATO member, over its hosting of an exiled opposition group, and Tirana severed diplomatic relations in response. That is the case where the apparent calibration failed: destructive, political, against an alliance member, and answered with a diplomatic rupture. It does not disprove calibration. It shows that calibration is a hypothesis that can fail.
If the ceiling is inferred from behaviour, what is an operation that crosses it? Miscalculation, a widening of capability, a shift in political tolerance, delegation to actors whose incentives differ from the centre’s, deliberate escalation, or a ceiling that was never where observers placed it: the outside record does not choose between them.
The second complication is that calibration may over-ascribe coherence, and the 2025 fighting made it vivid. Iranian cyber activity in the conflict read as a mixture of state operations, tasked crews, patriotic hacktivist fronts and opportunists, coordination and effect both uncertain, and attribution hard by design, hacktivist fronts and borrowed personas blurring who acted. To call all of that calibrated implies a single hand on the dial. The lid is real, but many hands hold it, not always in agreement, and a repertoire with more hands on it than its centre is not the same object as a state consciously holding a line.
Seen as effects, the calibration is a balancing loop. Provocation raises the risk of a response the state cannot absorb, that risk raises restraint, and restraint pulls the provocation back down, one lowering edge among the raises, which is what marks the loop B. The governor holds while the state is the only hand on the dial. What hangs off it in grey is what complicates it: proxies and hacktivist fronts can raise provocation outside the state’s direct control, making the calibration harder to read in 2025. Albania was different. It was a state-attributed operation that crossed the inferred ceiling, the clearest case in the record where the governor itself may have failed. There is a plainer possibility underneath. Observed restraint is not the same as chosen restraint. A group cannot destroy a system it has not reached, cannot wipe a controller it never pre-positioned in, cannot exploit access it does not have. Some of the ceiling is politics and fear of retaliation. Some of it is simply capability and access. The lid is partly infrastructural, not only psychological, and the two are hard to tell apart from outside.
Infrastructure in the battlespace¶
The later record changes the question again. The 2025 exchange showed cyber activity operating inside a shooting conflict. The war that followed in 2026 made the boundary harder to draw in another way: digital infrastructure itself became part of the physical battlespace.
The clearest sign is not a cyberattack at all. In March 2026, days into the war that opened with US and Israeli strikes on Iran, Iranian drones struck Amazon data-centre facilities in the UAE and Bahrain, degrading regional digital services. The strike is kinetic, not an intrusion, so it does not belong in the cyber chronology and does not demonstrate a failure of the Iranian cyber governor. What it does show is that the infrastructure on which digital effects depend can itself become a target of war.
That is a different development from the ones above. Albania tested the inferred ceiling of Iranian cyber action. The 2025 conflict complicated who could be said to be operating the dial. The 2026 war complicates the boundary around the dial itself.
The durable line is not between cyber and war. It is between effects Iran can plausibly contain, deny or take back, and effects it cannot.
When the lid fails¶
The destruction, the leaks and the slogans are easy to read as the expression of an ideological, vengeful character. They read better as the output of a repertoire built to keep room for manoeuvre. A false persona can be dropped. A contractor can be renamed. A hacktivist front can claim an attack the state never has to own. A stolen dataset can be released without a fingerprint. A wiper can ruin a network without touching a machine. A slogan can sit on a water controller where a valve could have turned. A real intrusion can be inflated into something larger than it was. Each produces a political effect while leaving the intent, the author, the scale and the consequence uncertain.
That is the capability, and it is not quite restraint. Iran has built a repertoire in which the effect can be turned up without a matching increase in the clarity of who did it, why, or how far the state meant to go. What it does with that is convert uncertainty into influence, and keep the lid on, where the lid now means the preservation of ambiguity and reversibility while an effect is still produced.
Which leaves the uncomfortable question the record will not answer. When the lid fails, as it appears to have done at Albania, was it lifted, blown off, or never fixed to the pot in the first place? And when the hands on the lid multiply, as they did in 2025, is there still a single lid to speak of?