As America approaches the 25th anniversary of the Sept. 11 attacks, FBI Director Kash Patel has offered a timely reminder of what counterterrorism is supposed to do: stop violence before Americans are forced to mourn it. Speaking recently with law-enforcement partners in New York, Patel highlighted the FBI-led Joint Terrorism Task Forces — now more than 200-strong nationwide — as one of the country’s most effective defenses against terrorist threats. The message matters. The JTTFs exist to connect intelligence, pursue leads, investigate threats, gather evidence, make arrests, and act before warning signs become tragedy.
That mission is especially urgent as the confrontation with the Islamic Republic of Iran enters a more dangerous phase. Iran does not need to launch missiles at the United States to threaten Americans at home. It can rely on intelligence operatives, cyber actors, proxy networks, criminal intermediaries, illicit finance, and covert facilitators. These are the tools of an asymmetric campaign: methods designed to blur the line between a conflict overseas and a threat on American soil.
The lesson of 9/11 is not that every warning indicates an imminent attack. It is that warnings must be assessed seriously, intelligence must be shared quickly, and institutions must not wait for certainty when credible signs of operational preparation are already visible. Counterterrorism succeeds not through panic or indiscriminate suspicion, but through disciplined investigation, sound intelligence, and timely disruption.
The FBI has made clear that Iran presents a threat across several fronts: foreign intelligence activity, terrorism, cyber operations, sanctions evasion, illicit procurement, and transnational repression. The bureau states that it is committed to identifying and disrupting Iranian intelligence and military operations that threaten Americans, U.S. national security, or critical infrastructure. Its public record includes investigations into attempted terrorist attacks and kidnappings, espionage and foreign-influence activity, cyberattacks, and alleged plots targeting U.S. officials and Iranian dissidents.
Those facts matter because a military setback for Tehran would not necessarily dismantle its capacity for covert retaliation. Airstrikes can destroy missiles, launchers, radar systems, command facilities, and military infrastructure. They cannot automatically erase the relationships, facilitators, financial channels, intelligence contacts, cyber capabilities, proxy connections, and criminal intermediaries that enable the regime to project coercion beyond its borders.
Iran’s security apparatus has long operated through institutions such as the Revolutionary Guard, the Quds Force, and the Ministry of Intelligence and Security. These bodies do not operate only through conventional military means. They have repeatedly been associated with intelligence operations, terrorism, threats against dissidents, cyber activity, and relationships with foreign partners and networks. The FBI’s own Iran-threat page cites cases ranging from an alleged Guard-linked murder-for-hire plot against a former U.S. national security adviser to past conspiracies linked to Iranian officials, cyber intrusions, and efforts to obtain sensitive American technology.
But analytical discipline is essential. A possible threat is not the same as a credible threat. An identified contact is not necessarily an operational network. A network is not automatically a sleeper cell, and a sleeper cell is not the same as a confirmed terrorist plot. The U.S. should not confuse suspicion with proof, rhetoric with operational preparation, or nationality with criminal intent.
At the same time, responsible caution must not become complacency. The FBI and its JTTFs must focus on the indicators that separate broad concern from an actionable threat: surveillance of potential targets, coordinated communications, suspicious financial transfers, logistical preparation, weapons procurement, acquisition of dual-use technology, recruitment of criminal intermediaries, or attempts to identify vulnerabilities at sensitive sites. The purpose is not to label every Iranian connection as dangerous. It is to recognize when hostile capability, intent, and preparation begin to converge.
Iran’s pattern of transnational repression should receive particular attention. For years, the regime has sought to intimidate, harass, surveil, abduct, or threaten dissidents and critics beyond its borders. Iranian Americans, journalists, activists, former officials, and other people regarded by Tehran as adversaries can become targets of coercion. A government that attempts to export repression into the U.S. is not merely conducting a foreign-policy dispute; it is challenging American sovereignty and the rule of law.
Jewish and Israeli institutions also require sustained attention. The Islamic Republic’s hostility toward Israel and its demonization of Jewish communities are central features of its ideology and messaging. Iranian-linked operations and alleged plots in several countries have involved Israeli diplomatic facilities, Jewish institutions, and individuals associated with Israel. That history does not establish that a specific attack against a synagogue, Jewish school, community center, or Israeli-linked target in the U.S. is imminent. But it does establish a serious threat context that demands vigilance, targeted protection, intelligence sharing, and rapid investigation when credible warning signs emerge.
Cybersecurity is another front where Iran can impose costs without firing a conventional weapon. The FBI, the Cybersecurity and Infrastructure Security Agency, the National Security Agency, and the Department of Defense Cyber Crime Center have warned that Iranian state-sponsored or affiliated cyber actors may target vulnerable U.S. networks and entities of interest. Their joint guidance specifically urges heightened vigilance around critical infrastructure, while noting that U.S. authorities had not observed a coordinated, Iran-attributed malicious cyber campaign at the time of the advisory. Defense-industrial companies with holdings or relationships involving Israeli research and defense firms were identified as being at increased risk.
That warning should not be treated as an abstraction. Hospitals, energy systems, water utilities, transportation networks, communications providers, financial institutions, industrial suppliers, and local governments are all targets for disruption. A successful cyberattack can affect public safety, commerce, trust, and daily life without a single soldier crossing a border. The FBI’s cyber squads, working alongside CISA and private-sector partners, must be prepared to identify malicious activity, attribute it when evidence permits, share threat information quickly, and help prevent isolated intrusions from becoming a broader campaign.
This is precisely why the JTTFs remain indispensable. The FBI describes them as America’s front-line defense against both international and domestic terrorism. They bring together investigators, analysts, linguists, intelligence specialists, and local, state, and federal law-enforcement partners to follow leads, collect evidence, make arrests, protect major events, share intelligence, and respond immediately to threats. The first JTTF was formed in New York in 1980; today, roughly 200 operate around the country, with task forces in every FBI field office area.
The FBI’s task now is clear: it must deepen Iran-focused counterterrorism coordination across its field offices and JTTFs; prioritize investigations involving transnational repression, illicit finance, criminal facilitation, and threats against vulnerable individuals and institutions; strengthen cooperation with CISA when cyber activity carries national security implications; and ensure that credible threat information reaches state and local partners in time to act.
OPINION — FROM 9/11 TO IRAN: TRUMP JUST SPEEDRAN BUSH’S BIGGEST MISTAKE
Effective counterterrorism must follow evidence, behavior, financing, networks, and operational indicators — not ethnicity, religion, nationality, immigration status, or political belief. Iranian Americans, Iranian dissidents, Muslims, immigrants, and other communities must never be treated as objects of collective suspicion. America’s strength lies in its ability to defend itself without abandoning the constitutional principles that distinguish it from authoritarian regimes.
Twenty-five years after 9/11, America should remember that homeland security is not measured by the force of its response after catastrophe. It is measured by whether the FBI recognizes evolving threats, connects the warning signs, and acts before hostile intent becomes operational violence. Iran does not need to win a conventional war to endanger Americans. The FBI and its Joint Terrorism Task Forces must ensure that Tehran’s shadow threat never becomes America’s next tragedy.
Erfan Fard is a counterterrorism analyst and Middle East studies researcher based in Washington, with a particular focus on Iran, Islamic terrorism, and ethnic conflicts in the region.
