A newly reviewed intelligence assessment from the Department of Homeland Security (DHS) warns that Iran and its allied proxy groups could target the United States following the reported killing of Iran’s Supreme Leader, Ayatollah Ali Khamenei, in joint US-Israeli airstrikes.
The February 28 threat assessment, prepared by DHS’s Office of Intelligence and Analysis and reviewed by Reuters, states that while a large-scale physical attack on US soil is considered unlikely, Iran and its proxies “probably” pose a persistent risk of targeted retaliatory attacks, particularly in the short term.
Cyber Threats Seen as Most Immediate Risk
The report highlights cyber activity as the most likely near-term method of retaliation. Iran-aligned “hacktivist” groups are expected to carry out low-level but disruptive cyber operations against American networks, including:
- Website defacements
- Distributed denial-of-service (DDoS) attacks
- Attempts to disrupt public-facing digital infrastructure
While these types of cyberattacks may not cause catastrophic damage, officials warn they can create public alarm and strain emergency response systems.
Regional Escalation Continues
The warning comes amid a rapidly expanding conflict following the air campaign launched by the US and Israel. Iran confirmed Khamenei’s death after the strikes were announced by Israeli officials and US President Donald Trump.
Since then:
- Iranian missile and drone attacks have targeted Gulf states hosting US military bases.
- Hostilities have widened to Lebanon following exchanges involving Hezbollah.
- US and allied forces across the Middle East remain on heightened alert.
The DHS assessment also states that Iran is likely to continue targeting US and allied assets in the Middle East and could blame senior US officials for unrest or protests linked to the conflict.
Domestic Security Concerns
US authorities are also monitoring potential domestic implications. Investigators examining a deadly shooting at a bar in Austin, Texas, said it was too early to determine whether the attack was connected to the Iran conflict. The suspected gunman reportedly wore clothing displaying Iranian symbols, but officials have not established a confirmed motive.
Homeland Security Secretary Kristi Noem said she is coordinating closely with federal intelligence and law enforcement partners to monitor and counter potential threats.
Read More: Three US fighter jets mistakenly shot down over Kuwait
FAQs
Why would Iran target the United States?
The killing of Iran’s Supreme Leader represents a major escalation. Iran may seek retaliation to demonstrate resolve, deter further strikes, and maintain domestic and regional credibility.
Is a major terrorist attack on US soil expected?
According to the DHS assessment, a large-scale physical attack inside the United States is unlikely at this time. However, targeted or symbolic attacks cannot be ruled out.
What are “proxy groups”?
Proxy groups are organizations aligned with or supported by Iran that operate in other countries. These include militias and armed groups in Iraq, Lebanon, Syria, and elsewhere that may act on Iran’s behalf or independently in alignment with its interests.
Why are cyberattacks considered more likely?
Cyber operations allow plausible deniability, require fewer resources than conventional military attacks, and can disrupt systems without triggering immediate military retaliation.
Could protests or unrest increase inside the US?
The assessment suggests Iranian officials may encourage calls for action or attempt to exploit political tensions. US agencies are monitoring for foreign influence operations online.
How are US authorities responding?
Federal agencies are increasing intelligence coordination, strengthening cybersecurity monitoring, and working with state and local partners to identify and prevent potential threats.
Conclusion
The DHS intelligence assessment paints a picture of elevated but measured risk following the reported death of Ayatollah Ali Khamenei. While a catastrophic attack on US soil appears unlikely, targeted strikes, proxy operations, and cyber disruptions remain credible threats.
The evolving conflict underscores the complexity of modern warfare, where retaliation may take digital, indirect, or symbolic forms rather than traditional military confrontation. As tensions persist, US authorities remain on alert, balancing vigilance with efforts to prevent further escalation at home and abroad.
