28 August 2026

Iran Is Using Foreign Criminals to Attack Its Critics Overseas

The New Yorker | Cora Engelbrecht

Iranian intelligence agencies and the Islamic Revolutionary Guard Corps have escalated a targeted external assassination campaign by hiring transnational organized crime networks to attack exiles and dissidents abroad. In March 2024, Iranian dissident journalist Pouria Zeraati was stabbed outside his London home by Romanian operatives, exemplifying Tehran’s shift toward outsourced violence to maintain plausible deniability.

This tactical pivot reflects systemic pressures on Iran following domestic civil unrest and regional military setbacks, prompting reliance on criminal proxies. Over the past five years, analysts documented more than 200 Iranian-backed plots overseas, nearly doubling the total recorded between 1979 and 2021. Operational coordination by IRGC Unit 840 allows Tehran to bypass direct state-level retaliation while imposing psychological coercion on diaspora media. Despite targeted Western sanctions, European law enforcement agencies face compounding operational friction as low-cost criminal cutouts exploit open borders to conduct lethal reconnaissance and targeted strikes.

Comment

The adoption of third-party criminal proxies by IRGC Unit 840 introduces structural vulnerabilities into intelligence collection and executive action chains. Unprofessional cutouts lack the operational security and tradecraft discipline of institutional cadres, increasing the probability of premature compromise during pre-assassination surveillance phases. The failure of hired Romanian operatives in London demonstrates how reliance on commercial encrypted messaging and ad-hoc financial transfers creates distinct forensic signatures for Western counter-intelligence agencies.

This tradecraft degradation ultimately reduces the probability of operational success, transforming targeted kinetic strikes into counter-productive intelligence exposure. When local law enforcement intercepts unvetted criminal proxies, seized communications technology typically exposes broader handler networks spanning from Tehran to European transit hubs. Consequently, the reliance on disposable cutouts trades long-term network security for immediate deniability, exposing IRGC Unit 840 command nodes to systematic intelligence penetration.

Strategic Question for Discussion
If IRGC Unit 840 continues to trade operational tradecraft for deniability through criminal cutouts, does the resulting forensic exposure ultimately compromise state-level intelligence architecture more than it advances foreign counter-dissident objectives?
The pattern suggests that relying on low-cost criminal surrogates creates severe counter-intelligence vulnerabilities that outweigh the short-term benefit of political deniability. While these outsourced operations insulate Tehran from direct diplomatic attribution, the forensic trail left by unvetted proxies consistently exposes IRGC Unit 840 handlers to Western security agencies. The trajectory indicates that this operational compromise will progressively dismantle Iran's covert infrastructure across Europe.
Share your assessment in the comments below.

No comments: