Skip to content
TrackPodcasts
technologyMar 10, 202620:53

Iran's Asymmetrical Responses Have A Long History

About this episode

Iran's Asymmetrical Responses Have A Long History by Nick Espinosa, Chief Security Fanatic

Get every episode summarized

Each time The Deep Dive Radio Show and Nick's Nerd News publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

219 searchable segments. Every word is indexed and playable.

Iran's Asymmetrical Responses Have A Long History

The Deep Dive Radio Show and Nick's Nerd News

0:00
20:53

Full transcript

The Deep Dive Radio Show and Nick's Nerd NewsIran's Asymmetrical Responses Have A Long History. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Iran's war-fighting asymmetry has a very long history. I'm Nick Espinoza, your chief security fanatic, and let's dive in. Now, Iran does have a long history of asymmetrical responses to the United States over the years, but some news that was reported about a week before the U.S. and Israel launched, I think is a good primer for what we're talking about in terms of Iran's history. Now, this is coming from February 20th, about a week or so before the actual strike started from any bow of CNBC. And basically, bow reported that a federal grand jury indicted three Silicon Valley engineers on charges of stealing trade secrets from Google and other tech companies and transferring that sensitive data to Iran. This is according to prosecutors that are basically bringing the charges. So, Samine Gandali, age 41, her sister Soror, Gandali, age 32, and Mohamed Javad,

Korsaravi, age 40, all residents of San Jose, California were arrested that Thursday, about a couple of weeks ago, and appeared in federal district court the same day. Now, the indictment identified the defendants as Iranian nationals. Soror was in the U.S. on a non-immigrant student visa. Samine later became a U.S. citizen, and Korsaravi, her husband, became a U.S. legal permanent resident. Prosecutors said that Korsaravi previously served in the Iranian army. Now, this trio faces charges of conspiracy to commit trade secret theft, theft, and attempted theft of trade secrets, and obstruction of justice. This is according to the U.S. Attorney's Office for the Northern District of California. Prosecutors alleged the three defendants exploited their positions at leading tech firms that develop mobile computer processors to obtain hundreds of confidential files, including materials related to processor security and cryptography. So, that's the backdrop, but I wanted to basically talk about how this Google-slash tech

company trade secret theft case fits into the backdrop of the ongoing U.S. Iranian conflict, because this didn't start a week and a half ago or so. So, first, I want to talk about essentially the incident that happened here, because this is a classic pre-war economic espionage, and Iran has a pattern of these. Now, in general, this type of high security intellectual property theft activity fits a long-standing pattern seen before enduring geopolitical conflicts, where states seek to basically close technological gaps with adversaries by covertly acquiring that kind of intellectual property. Remember, Iran has been essentially in a de facto embargo for decades, and so they basically resort to a lot of these different kinds of things. And to be very clear here, military capability is basically increasingly depending on advanced semiconductors in cryptographic systems. So, if a country cannot easily build

these technologies domestically due to sanctions or just simply industrial limitations, then espionage becomes that shortcut to try to catch them up. So, basically, Iran, as I mentioned, has faced decades of sanctions restricting access to Western technology, which then creates a very strong incentive for them to basically get it through indirect means for lack of a better term. On top of this, semiconductor technology is now considered a strategic military asset. The stolen information reportedly relates to processor security and cryptography used in modern chips. This is considered dual-use technology, meaning that it has both civilian and military applications and modern military capabilities depend heavily on these chips. So, think about it, missile guidance systems, drone control systems, encrypted communications, electronic warfare, AI-driven targeting systems, and on and on and on. And this is why the United States has increasingly treated semiconductor technology as national security infrastructure first. On top of this, basically, this case that we're

talking about here reflects that broader tech Cold War situation that Iran finds itself in. Incidents like this usually occur years before hostilities because nations try to prepare technologically before the conflict escalates. In this case, with the Iranians getting bombed in late February, they may not have been prepared for that at that level. Now, historically, the pattern essentially looks like this when we are talking about this generically, and Iran does fit this mold as well. So, first, its economic sanctions and technological restrictions on a country that is basically followed then by industrial espionage and cyber espionage as a response, then cyber conflicts, then proxy conflicts in terms of kinetic warfare, and then just straight up open military confrontation, which is where we find ourselves today. So, that brings us to Iran's history of asymmetrical warfare against the United States. And to be fair, the United States has been sanctioning Iran in supporting the opposite or opposition of the proxy wars that Iran finds itself in. Think about Yemen and the Houthis backed by Iran

versus the Saudi-backed government and on and on and on. So, everything I'm about to discuss is basically Iran's actions since the 1980s after the Iran Contra affair, if you recall that. So, let's start basically categorically here with direct and proxy terrorism against the United States and U.S. facilities here and around the world. In April of 1988, the frigate USS Samuel B. Roberts struck a mine in a deliberately laid Iranian minefield in the Persian Gulf, prompting the Navy's operation praying mantis. Now, this is classic asymmetry from a country that cannot compete ship for ship. Iran uses mines and basically deniable deniability for maritime harassment rather than a conventional fleet battle. We just recently saw Iran's flagship or one of their flagship cruisers coming back from war games in India that was sunk by a U.S. submarine. So, basically, this is what we are talking about here. They can't compete at that level with the

might of the U.S. Navy. So, we resort to asymmetry. On top of this, the FBI said in 1996, the Kobar Towers truck bombing in Saudi Arabia that killed 19 U.S. service members and wounded hundreds more. They linked that to Iran. U.S. prosecutors charged members of Saudi Hisbalah describing the group as a pro-Iran group linking an additional charged participant to Lebanese Hisbalah as well. The GAO also treats the Kobar Towers as one of the major state-sponsored terrorism cases tied to U.S. victims, essentially, using Iranian cutouts. And then there's a long standing support for Hisbalah and other anti-U.S. militant and extremist groups. The State Department's terrorist reports continue to say Iran funds, arms and trains groups, including Hisbalah and other militant partners across the Middle East and region in various regions. And even when Iran does not pull the trigger directly, this proxy architecture is one of the main asymmetric tools against U.S.

personnel, facilities and partners. And then we have Iran's actions in essentially the Iraq war era, essentially proxy warfare 101 actually in Iraq as well against the United States military presence. So, U.S. Treasury stated in 2008 that the IRGC, that's the Iranian Revolutionary Guard Corps, specifically the Kud's force that was run by Qasim Soleimani until President Trump in his first term had Soleimani essentially executed. The Kud's force in Iran is that basically group that supports terror operations and military operations outside of Iran. Anyway, the Kud's force officers in 2008 were leading terrorist operations against coalition forces and Iraqi security forces as well. Later, Treasury actions described Iran-backed militias such as Qatib, Hisbalah and Asib al-Hawk receiving report. Basically, they're receiving support,

lethal aid and financing from the Kud's force as well. This period is critical because Iran's use of Iraqi militias was one of the most effective post-Aran contra asymmetric campaigns against the United States. And a lot of reporting on this essentially said so. I've got plenty of links for you to ask me for them on these things. And then there's essentially the militia attacks, the rocket attacks, all of those kinds of things in Iraq as well. The U.S. reported for years that essentially this was tied to Iranian support and to Iraqi militia attacks using rockets, IEDs, especially explosively formed like penetrating weapons. We've seen this in that warfare as well, where a hummer or whatever would get hit on the side of the road and it would be essentially akin to an ambush. IEDs were prolific through this era. And also, basically, the public U.S. position has long been that Iran armed and enabled militias that essentially killed maimed or otherwise harmed U.S. forces in and around Iraq. On top of this, we have proxy attacks in

Iraq and Syria after October of 2023. So, sent-com commander General Kurela testified in March 2024 that Iranian-back militia groups had targeted U.S. forces in Iraq and Syria more than 150 times between October of 2023 through January of 2024. That is a lot of targeting and a very short amount of time. Treasury likewise described the Qat-e-Bhizbullah as being behind a basically a spate of recent attacks against the United States and its partners in Iraq and Syria. On top of it, we also have a lot of different things such as maritime coercion, harassment, pressure in the Gulf as well. Iran has repeatedly used mines as I mentioned in that 1988 incident, small boats. They've also used seizures and harassment in the Gulf and the state of Hormuz as asymmetric pressure against the U.S. but also U.S. protected shipping. CRS has specifically described the publication specifically described Iran's ability to harass tanker traffic and damage infrastructure without fully closing the strait itself. Something that

Iran is attempting to do right now, which is stifling basically the egress oil supply from the Middle East. We are starting to see the effects of that in the economy. There's a plastics plant, for example, a large plastics plant in Japan that is temporarily shut down as a result of not having the access to petroleum products they need. We're going to see gas prices go up around the world. This is something that is happening right now. CRS also noted, though, that in April of 2020, 11 Iranian Revolutionary Guard Navy boats made a high-speed harassing approach or approaches towards U.S. naval vessels, and that also fits with Iran's long-standing pattern essentially of going below the threshold of open warfare. Again, they have to fight asymmetrically because their navy basically is minuscule compared to the might of the entire U.S. Navy and the U.S. allies as well. Iran detained 10 U.S. sailors for the record in January of 2016 after their boats drifted near Farsi Island, which is basically off the southern coast of Iran. While not an

attack per se, it's the same sense as Kobar or militia strikes. It's still essentially asymmetric humiliation, course of messaging as an optics operation against the United States. On top of it, Iran has been cut up in assassinations, kidnappings, plots even on U.S. soil. The DOJ announced charges in 2011 alleging a plot directed by elements of the Iranian government to murder the Saudi ambassador in the United States using explosives. Although the target was Saudi, this was Iranian-directed on U.S. soil, so they're not discriminating there. Not to mention the fact that recently, they've literally threatened the life of President Trump, all these kinds of things. On top of this, the DOJ charged Iranian intelligence operatives in a conspiracy to kidnap a U.S. based journalist and activist Masi Alinajad from New York. This is a clear case of Iranian repression, because it's a rather repressive society that extended into the United States. It's very similar in

my mind to the Jamal Khashoggi situation out of Saudi Arabia, if you recall, Prince Mohammed bin Salman essentially had Jamal Khashoggi kidnapped and then chained Assad to death, which that's a way to go, my God. So with that, and speaking of journalists, the DOJ later prosecuted a murder for higher plot targeting Alinajad and in 2025 and 2026 announced convictions and sentencing tied to that Iran-backed operations. The FBI and Treasury have both publicly framed Iranian-transnational repression as an active threat on U.S. soil. So here we are. And then there's a cyber side of it, and we'll get to the cyber attack. But let's start with cyber espionage against U.S. infrastructure, universities, companies, the government itself, the DOJ charged nine Iranians in 2018 for a massive cyber theft campaign that stole more than 31 terabytes of data from over 140 American universities, 30 U.S. companies and multiple government agencies allegedly acting on

behalf of the Iranian Revolutionary Guard Corps. This is considered one of the clearest public documented examples of large-scale cyber espionage by the Iranians against the U.S. and U.S. infrastructure. CISA, that is the cyber security infrastructure security agency, their threat overview of Iran says that U.S. and partner governments have attributed basically intrusions against critical infrastructure organizations to Iranian cyber actors, ODNI, the Office of Director of National Intelligence. They had a 2025 threat assessment that also said Iran conducts cyber operations against U.S. targets for espionage and strategic advantage. And then we have the actual cyber attacks themselves, not to mention disruptive cyber activity against critical infrastructure across the United States. CISA issued an advisory in 2024 on IRGC affiliated cyber actors, exploiting things like PLC's programmable logic cards in multiple sectors, including water and wastewater systems. I've done segments on water and wastewater of the over 50,000 districts in

the United States and just how insecure they are in Iran one after them. This is not just espionage, right? It's the kind of action that could produce real-world infrastructure disruption. Imagine turning on your faucets and water doesn't come out because the plants had a cyber attack or wastewater doesn't flow properly, you know, or they introduce lie into the water system, which was an event that happened a few years back around 2022 or so in Oldsmart, Florida. That is not attributed to Iran, but it very well could be, which would have poisoned every man, woman, child, and animal drinking from that water source. Fortunately, that was caught in reverse before it got out of hand. On top of it, U.S. authorities have repeatedly warned that Iranian affiliated cyber actors may target American firms and critical infrastructure, especially during periods of geopolitical tension, which is where we find ourselves right now. DHS and FBI have both highlighted essentially homeland risks from Iranian cyber operations. On top of it, Iran has been caught basically working on election interference and influence operations within the United States itself. So if we are looking at this, the DOJ charged to Iranian nationals

for a cyber disinformation and threat campaign designed to influence the 2020 presidential election, intimidate voters, and undermine confidence in the election. Also in 2020, the DOJ seized domain names used by the IRGC as part of a covert influence operation, masquerading, as independent news organizations. We've seen multiple countries hit U.S. infrastructure in disinformation campaigns like this, most notably the Russians, the internet research agency founded by Yavgene Progojian there. The Iranians are doing this as well as are the Chinese, although the Chinese are not nearly as effective. So that obviously is a huge thing. The DOJ said the goal was to spread propaganda covertly, influence the American public secretly, and then so discord in the election. In 2024, the DOJ indicted three IRG cyber actors for a hack and leak quote-unquote operation designed to influence the 2024 presidential election, alleging a broader IRGC backed hacking conspiracy targeting current and former U.S officials. This actually shows continuity

for Iran interestingly enough because basically they're using cyber means to shape or try and shape U.S. politics and a road public trust, and not just steal secrets from governments and corporations like here. On top of it, espionage intelligence collection, insider cultivation, these are things that they have been doing for years and years and years. The FBI's Iran threat page describes a regime as a threat across cyber foreign intelligence and terrorism as well. And in practice, this typically includes classic espionage trade craft, right? Like so we're talking about cutouts, proxies, all of those things, intelligence collection against U.S. persons, and then efforts to target critics and officials alike. So Iran also finances terror, the sanction, basically, or they try to evade sanctions, and they have built covert logistics networks around the entire world. So treasury has repeatedly sanctioned essentially front companies, airline links, militia financiers, and the laundering networks that support the

force brigade outside of Iran, as well as the IRGC, and also Iran line militias in Iraq, Syria, and Lebanon as well. This financial layer actually is incredibly important if you think about it because this is Iran's asymmetric model, basically dependency, right? Because the covert movement of money, weapons, and material is basically what they can do as opposed to a conventional ground war to war fight, which is what they find themselves in right now. Also, they've tried to evade banking laws for years. The Treasury in 2024 had an action against El Huda Bank describing it as a conduit for terrorist financing by Iran, and those kinds of channels for the record are not side issues here. They're actually really core. They are enabling basically proxy and covert ecosystems that Iran would use against US interests. Outside of all of this, the DHS also warned in the wake of the June 21, 2025 bombing of Iran. If you recall the United

States and Israel bombed Iran to try and take out its nuclear program, basically DHS warned of a heightened threat environment in the United States related to that conflict, including possible violence and cyber attacks. Even when Iran does not directly conduct incidents themselves, the US government clearly assesses that Iran and its ecosystem can generate homeland risk through what I've just mentioned, proxies, sympathizers to their cause, cyber actors, the propaganda and disinformation campaigns that they're running. Think about it this way. Iran has consistently preferred asymmetric competition over direct conventional warfare. They've historically relied on proxies and covert action and cyber operations and maritime coercion and the Gulf and the state of Hormuz and all of that and intelligence working disinformation and all of these things. Not to mention repression across the world as they are trying to capture the journalists that write negatively about them. They do this not just to impose costs on the United States,

but also to put pressure on US partners. Whether you love or hate this new Iranian war, and I always say cyber security is agnostic to politics, but we're not immune from it, we have to expect that everything I just talked about is what Iran is going to do and they're going to do at a larger scale. But I also think we need to prepare for actual terror attacks on US soil from Iranian terror cells and their allies, their cutouts, all these kinds of things. This is coming and there's been a lot of reports and heightened alerts from intelligence agencies whether the reports are published or not saying we have to prepare for this so we should. This is now a whole new world. And please like share a follow me here on Facebook and Twitter and make a ESP and please subscribe to me at YouTube and all of the other places I'm totally losing my train of thought today and as always stay safe, stay online and please please please there's a private informed insecure take care take care

More episodes

More from The Deep Dive Radio Show and Nick's Nerd News

View all episodes →