Previously, I asked you to do something intentionally strange. For a few pages, I asked you to stop looking at Iran from the outside and instead inhabit the strategic problem from Tehran. Not because I know what Iranian decision-makers were thinking — I don’t. Not because I believe I can reverse-engineer the private deliberations of a state from public information — I can’t. The exercise was narrower than that.
I’d started from a premise about reasoning itself: if advanced machine reasoning has made technical search dramatically cheaper, then cyber operations should begin changing in ways that are difficult to see if we keep organizing our analysis around the old constraint. If access was once scarce, access naturally became the center of the model — who could get in, what vulnerability did they exploit, what malware did they use, what infrastructure did they control, which actor had the expertise required to operate against that particular kind of target. Those are still useful questions. But if reasoning across unfamiliar technical environments is becoming dramatically more scalable, they may no longer be the questions doing most of the explanatory work. The actor may be. What do they want? What do they need the adversary to believe? What uncertainty are they trying to reduce for themselves? What level of escalation can they tolerate? What capability do they want to reveal, and what do they want to preserve? What consequence would be useful now, under the particular strategic pressure they’re facing at that moment?
That was the model. The next step was obvious: go look. Not for “Iranian cyberattacks” — that would immediately poison the exercise by turning it into a search for confirming evidence. Instead I wanted to look for events that would become interesting if the model were right. Disruptions, outages, control anomalies, ransomware incidents, operational failures. Events that crossed sectors. Events that were tightly bounded. Events that appeared at strategically meaningful moments. Events whose publicly stated causes remained incomplete. Events that looked utterly unrelated if organized by technical category, but perhaps less unrelated if organized around the strategic problem an actor might have been trying to solve. And crucially — events that could turn out to have absolutely nothing to do with Iran.
That last condition matters. If the model only works when every unexplained outage becomes part of the pattern, it isn’t a model. It’s a story generator. So what follows isn’t an attribution. It’s the record of what happened when I took the generating function from the last piece and laid it over the actual substrate. You can decide for yourself what, if anything, is there.
Start With What We Actually Know
The easiest way to destroy this exercise would be to blur together several very different categories of evidence, so I’m not going to do that. Some of the incidents below are confirmed cyberattacks. Some are confirmed ransomware. Some are verified operational disruptions whose technical trigger remains unspecified. Some were initially described as equipment failures or software problems and only later reclassified as potentially cyber-related. Some remain unverified at the trigger level. And in almost all of them, there’s no formal attribution to Iran. That’s not an inconvenience to work around — it’s the evidence state.
The incident register I built preserves those distinctions explicitly. A verified disruption is not treated as a verified cyberattack; a threat-group claim is not treated as formal attribution; suspicion is not treated as confirmation.
With that floor in place, we can ask the more interesting question. Not “which of these incidents can I prove Iran conducted?” but “if the strategic model from the previous piece were approximately right, which of these events would I have found interesting, and why?”
Before the War: Learning Without Spending the Capability
The model predicted that before direct conflict, a rapidly expanding cyber capability might remain surprisingly quiet. That initially sounds backward — if you suddenly become much more capable, why wouldn’t you use it more? Because capability has informational value before it has destructive value. If your adversary doesn’t know how far your reach extends, that uncertainty is an asset. Every visible operation reveals something about the frontier. And if you don’t yet know where the frontier lies either, the early problem is as much epistemic as operational.
You explore. You probe. You learn what classes of systems have become tractable. You test whether models built in controlled environments survive contact with reality. You accumulate options without necessarily spending them. That makes the prewar period hard to observe from the outside by design. But it also gives us a baseline: if the later campaign begins showing increasing breadth, increasing precision, or increasing control over effects, the important comparison isn’t merely with earlier Iranian cyber activity. It’s with what an actor learning a radically expanded option space might rationally reveal, and when.
February: Reach
Direct conflict changes the optimization problem immediately. Restraint still matters, but silence no longer carries the same value. A weaker conventional actor has an obvious strategic need: demonstrate that overwhelming battlefield superiority doesn’t create strategic impunity. In the model, that made reach the first useful wartime message — not maximum destruction, not sophistication for its own sake. Reach. The conflict can touch you too.
Once I started looking at the incident chronology through that lens, February became interesting. On February 17, Meriden, Connecticut suffered a municipal network disruption that took all city departments offline, forced staff onto manual records, and moved 911 dispatch to the Connecticut State Police Academy. The city described it as an “interruption attempt” and did not initially classify it as ransomware; a ransomware group claimed the incident more than five weeks later.
Two days later, the University of Mississippi Medical Center suffered a confirmed ransomware attack severe enough to close all 35 clinics statewide, knock Epic offline, cancel surgeries and imaging, and force paper downtime procedures. The FBI was onsite, and the attackers made contact.
Then, on February 25, CME Globex halted COMEX metals and NYMEX natural-gas trading during a sensitive contract-expiry window. CME publicly attributed the interruption to “technical issues” and provided no detailed public postmortem in the underlying record.
Those are three very different systems — municipal government, healthcare, financial markets. Technically, they don’t form an obvious family. Strategically, that may be exactly the point. If the internal question is no longer “can we exploit this one class of system?” but “does this capability generalize across unrelated technical environments?”, heterogeneity itself becomes informative. A successful operation against one familiar architecture teaches you something. Successful effects across unrelated architectures teach you something much more important.
Again, I’m not claiming these three incidents share an actor. I’m saying that if I’d entered February expecting an actor to test reach and generalization, this is the kind of substrate I would have marked for closer attention.
March: From Reach to Breadth
The next thing the model predicted was that repeated success shouldn’t necessarily produce immediately larger destruction. It should produce higher confidence, and higher confidence should allow harder questions. Can we move quickly? Can we operate across different sectors? Can we produce effects against systems with very different architectures? Can we choose between disruption, degradation, and destruction? Can we stay inside a bounded envelope?
March is where the register gets much denser. On March 10, JetBlue requested a nationwide FAA ground stop after what it described as a brief system outage or internal IT issue.
On March 11, Stryker suffered something very different: a cyberattack used Microsoft Intune to wipe devices across the company’s global environment. That incident was later formally attributed by the U.S. government to Iran’s Ministry of Intelligence and Security through the Handala operation.
That matters, but not in the simplistic way. One formally attributed Iranian operation doesn’t magically turn every nearby disruption into an Iranian attack. What it does establish is much narrower and more useful: Iranian state-linked cyber operations were active inside this conflict environment. That changes the prior.
Then on March 14, a ransomware incident struck a water-treatment SCADA server in Minot, North Dakota. Operators unplugged the server, switched to manual gauge readings for 16 hours, and spent more than two weeks recovering. The system served approximately 80,000 users. No actor attribution was recorded.
Five days later, Foster City, California declared a state of emergency after ransomware knocked nearly all municipal systems offline. Police and 911 dispatch remained available, but the broader municipal network did not.
On March 30, Wells Fargo experienced nationwide login, balance, and transfer failures lasting roughly three hours. The underlying record includes no disclosed root cause and no actor attribution.
Now stop organizing these by sector — airline operations, medical technology, water infrastructure, municipal systems, banking. If the old question is “what common vulnerability connects these systems?”, the set looks noisy. If the question is “what would an actor testing breadth, repeatability, and operational generalization want to learn?”, the noise changes character. The heterogeneity becomes the experiment. Can this capability move through radically different environments and still create operationally meaningful effects? Can it produce a global destructive action in one case, a temporary transportation disruption in another, a manual fallback condition in another, and an economic-service interruption somewhere else? If the answer keeps coming back yes, the actor’s posterior changes — which means the next rational test can become harder.
Calibration Is More Interesting Than Destruction
The model from the previous piece suggested that once reach and breadth are no longer the scarce dimensions, the interesting capability becomes consequence control. Can you determine how much happens? Can you approach a dangerous threshold without crossing it accidentally? Can you create an effect visible enough to communicate but bounded enough to preserve escalation control?
This is where I began caring much more about events that were surprisingly limited. A spectacular failure can prove access. A precisely bounded failure may prove choice. That distinction is easy to miss because we’re psychologically drawn toward magnitude — big attack, big capability. But imagine the actor’s actual problem. If you’re conventionally weaker, unconstrained escalation is dangerous. Your ideal operation may therefore be one where the adversary can see the distance between what happened and what could have happened. Water pressure drops but returns. A control system is affected but the water remains safe. A transportation network stops but restarts. A communications service degrades while adjacent capabilities keep functioning. A system is taken offline without cascading into catastrophe.
Those outcomes are ambiguous. They may indicate nothing more than ordinary resilience limiting an attempted attack. They may be ordinary technical failures. They may be ransomware operators behaving pragmatically. Or, under the model, they could occasionally represent something else: selected settings. That possibility became much harder for me to ignore later in the summer.
July: The Water Campaign
By late July, the water incidents stop being speculative in one important sense. There was a real cyber campaign. More than 30 municipal water systems in Minnesota were affected within a 48-hour period through access to internet-facing operational technology and programmable logic controllers. The underlying record describes per-target HMI manipulation and notes there were no Minnesota boil-water advisories. CyberAv3ngers was strongly suspected, while the FBI/EPA public notice did not formally name a culprit.
The campaign then broadened across multiple states. Public reporting captured one snapshot of seven affected states on July 30 and another of twelve or more states by August 4. Again, the public federal notice did not formally attribute the campaign, while CyberAv3ngers remained strongly suspected.
Thirty facilities. Twelve states. Every one of them coordinated within the same tight window. Not one triggered a boil-water advisory. That’s a striking amount of control to exercise across that much surface area at once.
The Clayton County Exception
Then there was Clayton County, Georgia — and it’s the incident I keep coming back to, because it’s the one anomaly inside an otherwise flawless campaign, and anomalies inside flawless campaigns are exactly what this exercise is built to notice.
At roughly 1:00 a.m. on July 27, a pump station at the Terry R. Hicks Water Production Plant failed. Customers across northern Clayton County lost pressure or water. A boil-water advisory followed. Pressure returned by about 4:00 a.m., and the advisory was lifted the following day after testing. Initially, the event was treated as an ordinary equipment or pump-station failure. Then, on August 4, the Clayton County Water Authority announced it was investigating unauthorized cyber activity that may have caused or contributed to the disruption, centered on PLCs.
Put next to the other thirty facilities, Clayton County is the outlier that needs explaining. The broader Minnesota-and-beyond campaign was executed across a dozen states with no boil-water advisories anywhere — a remarkable degree of control held constant across enormous scale. Clayton County was the opposite kind of event on every axis that matters. It was a single, isolated target. It wasn’t recognized as cyber-related until more than a week after it happened, and even then only as a possibility under investigation. And it’s the one incident in the entire campaign that actually crossed the threshold into a boil-water advisory.
That’s a strange thing for a flawlessly executed, thirty-facility, twelve-state campaign to produce. If the operators controlling that campaign were skilled enough to hit thirty targets simultaneously without a single one crossing into public-health territory, it’s a stretch to believe the same operators simply lost control once, at one target, for no discernible reason. The more parsimonious read isn’t “they got unlucky in Clayton County.” It’s that whatever happened in Clayton County was not an accident relative to everything else — it was different on purpose.
Here’s the hypothesis worth sitting with: Clayton County wasn’t the campaign’s one failure of control. It was the campaign’s most legible demonstration of control, precisely because it was different from the other thirty.
Look at what the pairing actually communicates once you hold both halves in view at the same time. Thirty facilities, twelve states, perfect coordination, zero public-health consequences — that’s the demonstration of reach and precision at scale: we can touch this much of your infrastructure, simultaneously, and choose to cause you no harm anywhere. Then, quietly, in a single separate system, serving a population large enough to be noticed but nowhere near large enough to be a real disaster, the same capability is walked just over the line that produces a boil-water advisory — and pulled back within hours, fully resolved by the next day. That’s the demonstration of dial control: we can also choose to let you feel it, exactly as much as we intend, and then hand it back to you just as precisely.
The two halves reinforce each other. The massive, harmless campaign proves the reach. The single, narrowly calibrated exception proves the restraint is a choice rather than a limitation — because if it were a limitation, it should have shown up more than once across thirty targets, not exactly once, in the one place seemingly designed not to matter very much.
There’s a further wrinkle worth naming, because it strengthens rather than weakens the hypothesis: if this reading is right, the message only works if it’s hard to see. A Clayton County-style event occurring entirely on its own would likely never have been flagged as cyber at all — it looked, for more than a week, like an ordinary pump failure. Even after the reclassification, nothing about it screams Iran on its own. It only becomes legible as a signal once you set it beside the other thirty facilities and notice the shape of the exception. That’s not a flaw in the theory. An operation built to be recognized only by someone already looking for exactly this kind of asymmetry is a more sophisticated instrument than one built to announce itself outright — and the fact that it requires this much reconstruction to even become visible is itself consistent with an actor optimizing for deniability while still wanting the signal available to anyone doing the work to find it.
None of that proves Clayton County was Iranian, or that it was intentional, or that my reading of it is correct. It remains entirely possible that Clayton County really was just a pump station that failed at an unlucky moment, later flagged out of caution once cyber activity was already on investigators’ minds elsewhere. But the previous piece predicted that successful, bounded operations could initially look almost indistinguishable from mundane technical failure — first a pump failure, later a possible cyber cause discovered only in hindsight. Clayton County did exactly that, sitting inside an independently documented, multi-state campaign against water-system PLCs at the same time. That’s the kind of event the model tells me not to wave off simply because the first label sounded ordinary.
The important questions aren’t “can this be formally attributed?” They’re: was this effect strategically coherent? Was it bounded? Did it reveal access? Did it test consequence control? Did it occur inside a broader campaign demonstrating breadth? And what would the actor have learned from it? That’s a very different lens than attribution — and it’s the one this whole exercise is built around.
The Pattern Begins to Move Across Systems
The July cluster didn’t stop with water. On July 16, Fairlife suspended all U.S. production after ransomware reached production-related systems. Canada was unaffected. Anubis later claimed the attack.
That same day, AWS recorded a CloudFront disruption attributed publicly to a VPC Origins configuration-load failure. The incident register preserves the event as verified while leaving the trigger analytically unestablished in the underlying handoff.
On July 18, United Airlines suffered a technology failure affecting reservations and check-in systems, with San Francisco, Newark, and Dulles hardest hit.
On July 23, Microsoft Azure West US suffered an outage publicly attributed to a maintenance-automation bug.
On July 28, American Airlines requested a nationwide FAA ground stop after a technology issue briefly affected connectivity across some systems. About 1,100 flights — roughly 30 percent of the airline’s daily schedule — were affected.
Technically, this is a mess: ransomware, cloud infrastructure, airline systems, cloud automation, water PLCs. There’s no obvious common technical mechanism, which is exactly why the old ontology has such difficulty with the set. But the model I’d derived wasn’t looking for a common mechanism. It was looking for a common decision process. If technical search has become sufficiently broad, two events don’t need to share malware, infrastructure, exploit chains, or sector to answer the same strategic question — they only need to create the desired consequence. That possibility is the inversion. The commonality may live above the technical layer.
August: Operational Systems Everywhere
Then August opens with another series of operational disruptions across very different parts of American infrastructure. On August 4, all three North Carolina ports experienced a confirmed cyberattack. Digital systems were isolated and gate processing moved to manual procedures. No actor was attributed.
On August 6, a temporary outage at the Minneapolis Air Route Traffic Control Center led to ground stops affecting Minneapolis–St. Paul and other Midwestern flight operations. The FAA cited telecommunications or equipment failure.
On August 7, Suisun City, California suffered a confirmed malicious-software attack affecting 911 routing, police and fire dispatch, and records. The city shut down its entire IT network, moved dispatch to Solano County, declared a state of emergency, and closed City Hall. No actor was attributed.
On August 8, Verizon suffered a multi-region voice outage affecting users across New York, Los Angeles, Boston, Chicago, Virginia, and North Carolina. Data and text kept working while voice service failed. Verizon disclosed the recovery but not the underlying cause in the record I assembled.
Again, I’m not asking you to believe these events share an actor. I’m asking you to notice what happens when we stop grouping them by industry and start grouping them by effect. Manual fallback. Temporary loss of coordination. Selective communications failure. Operational disruption without catastrophic destruction. Emergency systems degraded but not annihilated. Service restored. Pressure applied. Option preserved. That shape interests me far more than whether two systems happened to run the same software.
The Historical Prior Matters Too
There’s another reason Iran remained the actor I kept returning to as I worked through this. None of this would be especially persuasive if Iran had no history operating in these domains. But it does.
Iranian actors were attributed to a multi-year DDoS campaign against roughly 46 U.S. banks between 2011 and 2013. An IRGC-linked actor set was also attributed to the 2013 Bowman Avenue Dam intrusion, where attackers accessed a SCADA system through an exposed cellular modem. In 2021, an Iranian APT exploited known vulnerabilities affecting transportation and healthcare targets, including a children’s-hospital control network. In 2022, an Iranian APT exploited Log4Shell at a federal agency in Washington, obtained credentials, and established persistence. In 2023, CyberAv3ngers used default credentials against Unitronics PLCs at water systems in Pennsylvania and Ireland. And in 2024, the same group was documented using ChatGPT for PLC reconnaissance and default-credential research. The record does not show novel AI-enabled capability at that point, but it does show the tool entering the actor’s workflow.
Then, during the 2026 conflict itself, another Iran-nexus group, Ababil of Minab, was reported using ChatGPT to refine database-enumeration scripts during an attack on a U.S. vehicle-GPS company.
That doesn’t prove the capability transition I’m hypothesizing occurred. It does establish something much simpler: Iranian cyber actors weren’t encountering AI-enabled cyber operations as an entirely foreign instrument. They already had history in U.S. critical infrastructure, operational technology, finance, healthcare, and cyber-enabled coercion. So if machine reasoning radically expanded what could be searched, understood, and acted upon, Iran wouldn’t need to invent an entirely new strategic language. It would be applying a radically improved instrument inside a language it already knew how to speak.
What Actually Changed for Me
This is the part I want to be especially careful about. I did not work through this chronology and conclude Iran did all of this. I still don’t know that. What changed was the way I saw the substrate. Events I previously would have treated as unrelated began sorting themselves along different dimensions — not sector, not malware family, not vulnerability class, but strategic function: reach, breadth, friction, reciprocity, calibration, generalization, consequence control, learning, signaling.
And once I started organizing the events that way, something else happened. The absence of spectacular destruction stopped looking like evidence against a sophisticated campaign. Under the model, it could sometimes be evidence of the opposite — if the actor is trying to preserve escalation control, teach an adversary, test itself, and retain optionality, increasingly precise and bounded outcomes may be more informative than indiscriminate destruction. Likewise, apparent randomness stopped being automatically disqualifying. If technical access is broad enough, there’s no reason the actor’s chosen implementations should cluster neatly inside one industry. The coherence may exist at the level of purpose. That’s the thought process. Nothing more magical than that.
What Would Change My Mind?
This is where the model has to stop being merely interesting and start accepting risk. If I’m right that scalable reasoning changes cyber operations by moving the bottleneck from technical access toward strategic selection, some observable consequences should follow.
The campaign should increasingly align with strategic pressure rather than merely technical opportunity. The visible character of operations should change as the actor’s objectives change. Breadth should matter early because generalization is still being tested. Later operations should become more selective. Bounded effects should become increasingly common if consequence control is valuable. Periods in which bargaining is strategically attractive should show contraction, restraint, or a shift toward deniable and reversible effects rather than indiscriminate escalation. Public claims that a particular capability has been neutralized should become unusually attractive test propositions, because falsifying them can cheaply update both sides’ beliefs. And the technical heterogeneity of events should increase rather than decrease if the thing generalizing is reasoning rather than a specific exploit chain.
If those patterns don’t appear, the model weakens. If events cluster randomly with no correspondence to strategic pressure, the model weakens. If destructive magnitude rises monotonically regardless of diplomatic context, the model weakens. If supposedly attractive demonstrations are consistently ignored, the model weakens. If the attack surface turns out to remain far more technically constrained than the underlying premise assumes, the model may collapse entirely. Good. That’s what a useful model is supposed to risk.
So What Am I Saying?
Less than it may sound like. I’m not asking you to accept an attribution. I’m not asking you to believe every outage in this chronology was malicious. I’m not asking you to treat temporal proximity as proof. I’m not asking you to believe my reconstruction of Iranian strategic incentives was correct.
I’m asking you to follow the same path I did. Begin with the premise that reasoning itself may have become dramatically more scalable. Ask what that does to the cyber decision problem. Move the bottleneck from access toward selection. Put that capability inside the strategic constraints of a conventionally weaker state already experienced in asymmetric cyber operations. Derive what kinds of behavior would make sense. Then turn around and look at what actually happened. That’s all I did. And once I did it, the substrate looked different.
Maybe I’m seeing structure where there’s only coincidence. Maybe some of the pattern is real and some of it is noise. Maybe the capability transition is real but Iran isn’t the actor expressing it most clearly. Maybe the strategic model is wrong. Maybe the entire thing falls apart under a better explanation. I genuinely don’t know.
That’s why the next step shouldn’t be another argument. It should be a test. If this model has any explanatory power at all, it should be able to tell us something about events that haven’t happened yet. Not vaguely. Not retrospectively. Specifically enough that reality gets the final word.
That’s where we go next.
About The Author
Jason Hubbard is the founder of SacredLoop and an independent AI architect. His work examines AI runtime architecture, system behavior, and the gap between what the industry claims it has built and what current systems actually do.
Read Jason on Medium | Follow Jason on X | Connect on LinkedIn


