Modern wars can begin inside networks long before missiles are launched or fighter aircraft cross a border. Iran’s expanding use of cyber operations alongside kinetic warfare offers an important lesson for South Asia, where India and Pakistan are integrating cyber capabilities, artificial intelligence, electronic warfare and conventional military power under the shadow of nuclear escalation.
The danger is not simply that cyberattacks will become more frequent. It is that cyber operations are becoming embedded in conventional warfare while attribution remains uncertain. Between nuclear-armed rivals, an intrusion intended for espionage or limited disruption could be interpreted as preparation for a larger attack.
Iran’s Cyber Playbook
Since the escalation of conflict in 2026, Iranian cyber activity against U.S. and Israeli interests has reportedly included espionage, disruptive operations, spyware, information operations and efforts to establish access to strategically important networks. More significant than the volume of activity is its growing alignment with Iran’s wider military objectives.
Against Israel, Iranian-linked cyber operations have reportedly targeted senior officials, security cameras, infrastructure and other strategically relevant networks. Compromised surveillance systems can potentially provide intelligence useful for military targeting and post-strike assessment, while cyber-enabled information operations can expose vulnerabilities inside Israeli institutions.
However, Iranian cyber activity against the United States has increasingly focused on military-related intelligence and critical infrastructure. Iranian operators have reportedly targeted senior officials and telecommunications systems, while U.S. authorities have warned of Iranian-affiliated activity against operational technology used by American water and energy providers. Recent attacks affecting U.S. water systems have intensified these concerns, although some incidents have not been publicly attributed to Iran.
Together, these operations demonstrate how cyber capabilities can complement conventional warfare. Espionage can improve situational awareness, reveal an adversary’s decision-making and potentially support targeting, while disruptive operations can impose costs far from the physical battlefield.
Cyber power, in other words, is not replacing missiles, drones or conventional forces. It is making them potentially more effective.
Artificial intelligence amplifies this model. AI can accelerate reconnaissance, social engineering, malware development, data analysis and content generation. Its significance lies less in creating a new strategic logic than in allowing existing cyber and information operations to be conducted faster and at greater scale.
Iran’s experience therefore illustrates a defining feature of contemporary cyber power: its greatest value often comes from reinforcing other instruments of statecraft while offering options that can remain below the threshold of major conventional escalation.
South Asia’s Multi-Domain Battlefield
South Asia is undergoing its own transition toward multi-domain warfare. The May 2025 India-Pakistan confrontation demonstrated how air operations can intersect with cyber capabilities, electronic warfare, intelligence and information systems. Pakistan has been developing an integrated military architecture connecting fighters, airborne early-warning platforms, drones, satellites, cyber units, electronic warfare systems and ground-based air defense through information networks.
Operation Divine Bytes, described in Pakistani accounts as part of the Pakistan Air Force’s cyber campaign during the May confrontation, illustrates this transition. The campaign reportedly targeted Indian communications, government systems, energy networks, surveillance infrastructure and other digital assets. Pakistani accounts describe operations affecting numerous organizations and thousands of information and communications technology elements, although the scale and operational effects of some claims remain independently unverified.
One publicly reported incident involved the compromise of the Madhya Pradesh BJP website, which displayed a message referring to the PAF Cyber Force and Operation Bunyan Al-Marsous. More significant than individual incidents, however, was the apparent attempt to integrate cyber activity with air operations, electronic warfare, intelligence and information systems. Divine Bytes therefore matters less as a catalogue of cyberattacks than as an indication that cyber capability is moving toward the center of Pakistan’s multi-domain military planning.
India is simultaneously developing its own cyber and multi-domain capabilities, including institutional structures for military cyber operations and the integration of defensive and offensive capabilities into its evolving cyberspace doctrine. Indian-aligned threat actors have also been associated in open-source reporting with operations targeting Pakistani networks. South Asia’s emerging cyber battlespace is therefore a competitive environment in which both countries are adapting to an increasingly digital military domain.
This transformation changes the logic of air warfare. A modern fighter depends on sensors, satellite navigation, secure communications, airborne early warning, electronic protection, intelligence and data links. Disrupting these systems can degrade an adversary’s operational effectiveness without physically destroying its aircraft.
The May confrontation consequently highlighted the importance of the military “kill chain”: the process through which forces detect, identify, track, decide and engage. Advantage increasingly depends not only on weapons platforms but also on protecting the information architecture connecting sensors, commanders and shooters while disrupting the adversary’s network.
Artificial intelligence adds another dimension. Militaries receive enormous volumes of information from satellites, drones, sensors, communications networks and open sources. AI-assisted systems can process that information more rapidly, shortening the interval between detection and response. The contest is increasingly not simply over who possesses the better fighter, drone or missile, but who can see first, understand first and act first.
But what offers an operational advantage in war can create profound instability during a crisis.
When Cyber Ambiguity Meets Nuclear Deterrence
Cyber attribution is inherently difficult. India and Pakistan have both been associated in open-source reporting with state-linked or state-aligned cyber groups, but establishing responsibility for an individual operation requires technical evidence, intelligence and political judgment. Attackers can route operations through third countries, exploit compromised infrastructure, imitate another actor’s techniques or deliberately create false indicators.
Iran’s experience illustrates a broader feature of cyber conflict: attribution uncertainty can give states room to impose costs while limiting immediate escalation. Cyber operations can remain below the traditional threshold of large-scale conventional warfare, making them useful instruments of calibrated pressure.
For both India and Pakistan, however, the same ambiguity can become exceptionally dangerous during a crisis.
An intrusion into military communications, an air-defense network, a power grid, satellite infrastructure or a nuclear-related system may not immediately reveal whether its purpose is espionage, disruption, coercive signaling or preparation for a larger attack. Political and military leaders may therefore have to make decisions before technical attribution is complete.
The overlap between civilian and military infrastructure compounds the problem. Electricity, telecommunications, satellites, transportation systems and fuel networks support military operations while sustaining civilian life. A cyber operation intended to disrupt military logistics could consequently affect hospitals, water supplies, transportation, businesses or emergency communications.
India and Pakistan therefore need crisis-management mechanisms that evolve alongside their cyber capabilities. A dedicated cyber hotline could provide an emergency communication channel during major incidents. Both countries would also benefit from clearer attribution procedures and evidentiary standards, stronger protection of civilian critical infrastructure, and greater engagement on how international law applies to state behavior in cyberspace.
The lesson from Iran is not that cyber warfare will replace conventional warfare. Nor did May 2025 make aircraft, missiles and other conventional capabilities secondary. Instead, both cases demonstrate that the digital and physical battlefields are becoming increasingly difficult to separate.
The next India-Pakistan crisis may begin inside communications networks, satellites, databases or command systems before anything becomes visible in the skies. The danger may lie less in the sophistication of a cyberattack than in uncertainty about what it means.
When governments cannot quickly determine whether an intrusion represents espionage, limited disruption, coercive signaling or preparation for a conventional strike, the space for misperception and escalation expands.
Between nuclear-armed adversaries, the most consequential cyber weapon may ultimately be uncertainty itself.

