Recent cyber attacks attributed to Iran underscore that digital infrastructure is now a strategic asset in modern conflicts. In an era where cyber capabilities, communications networks, and critical data infrastructure serve as instruments of geopolitical competition, Iraq’s telecom sector is not only an administrative bureaucracy but also an Iranian asymmetric warfare asset. Facing degraded domestic network resilience and strict internal communications restrictions amid ongoing regional conflicts, Iranian state-sponsored syndicates require contiguous, external networks for resilient command-and-control. Iraq’s compromised infrastructure offers precisely that—a contiguous, deniable, and externally hosted network that Tehran can leverage for regional cyber operations.
Tehran’s cyber strategy partially relies on externalized digital logistics bases. Iran shields its activities behind Iraqi sovereignty by engineering the capture of its telecommunications and regulatory frameworks.
Iran shields its activities behind Iraqi sovereignty by engineering the capture of its telecommunications and regulatory frameworks.
In Baghdad, Iran-backed factions have executed a top-down takeover of the civilian communications apparatus. Over the past decade, successive appointments to the Ministry of Communications—including Hassan Al-Rashid, Hayam Al-Yasiri, and Mustafa Sanad—bypass professional competency to install figures bound by ideological loyalty to Tehran and its clerical rule.
Iraq’s Communications and Media Commission also mirrors this capture. Commissioners such as Amtar Al-Mayahi—wife of senior Badr Organization figure and former minister Hassan Al-Rashid—control frequency allocations and internet service provider licensing. By subverting these administrative gates, pro-Iranian networks ensure that national data routing and digital oversight bypass sovereign Iraqi interests to directly accommodate Iran’s security and intelligence requirements.
This institutional capture dictates the framework and topology of Iraq’s national data grid. For nearly two decades, the Iraqi government and its Western partners discounted reports concerning Iraqi internet bandwidth smuggling as isolated illicit finance schemes or low-level bureaucratic corruption involving unnamed actors. Unauthorized control demonstrates the existence of parallel networks that leverage digital infrastructure outside normal state accountability.
These operations constituted the formative phase of a systematic state-capture blueprint. In 2023, Iran and Iraq signed a bilateral agreement to cooperate in telecommunications infrastructure, the exchange of expertise in cybersecurity and artificial intelligence, and coordination in international forums on these technologies. This has provided Iran a mechanism to deepen its technical presence inside Iraq’s infrastructure. Most visibly, Iraq’s Ministry of Communications has awarded critical fiber-optic contracts to the Muhandis General Company, the U.S.-designated economic wing of the Popular Mobilization Forces operating under the direct supervision of U.S.-designated Kata’ib Hezbollah leadership and embedded Islamic Revolutionary Guard Corps advisers. This, in turn, enables Tehran to use, intercept, monitor, and route bulk data traffic outside effective Iraqi state oversight to exploit Iraqi communication for intelligence collection, information operations, and broader hybrid warfare.
Should Baghdad fail to reform, the U.S. Treasury should expand its secondary sanctions to force technical measures designed to disrupt Iran’s architecture.
Simultaneously, the state’s internal security apparatus institutionalizes the human capital required for advanced cyber operations. The Ministry of Interior, dominated by the Badr Organization and Iranian-backed militias, has organized cybersecurity initiatives under the oversight of former Minister Abdul Amir Al-Shammari under the guise of national law enforcement capacity-building. Militias recruit these trained cadres to staff internal wiretapping cells and external proxy cyber units. State-funded training consequently strengthens cyber capabilities available to Iran-backed armed groups, further blurring the distinction between official security institutions and proxy organizations, ultimately merging official law enforcement with Iran-backed digital aggression. These developments indicate that Iranian proxies in Iraq are now multi-domain actors that integrate cyber operations and information warfare into traditional military capabilities. In effect, Iraqi militias now mirror the Lebanese Hezbollah’s development of capabilities beyond bombs and bullets.
Whether Iraq’s telecommunications infrastructure has been operationally employed in the recent cyber campaigns against the United States remains shielded by classification, but the capability is just a matter of time.
Should Baghdad fail to reform, the U.S. Treasury should expand its secondary sanctions to force technical measures designed to disrupt Iran’s architecture. Washington should condition assistance on the removal of officials aligned with Iran from Iraq’s ministries and commissions, while requiring the exclusion of Muhandis General Company and other Iran-affiliated entities from the country’s telecommunications sector. There are alternatives, such as Supercell, whose core brand is secure communication absent Chinese components or cooperation with militia-infiltrated companies like Muhandis or Earthlink, whose Iraqi iteration is unrelated to the U.S.-based company.