As America approaches the 25th anniversary of the September 11 attacks, FBI Director Kash Patel has offered a timely reminder of what counterterrorism is supposed to do: stop violence before Americans are forced to mourn it. 

Speaking recently with law-enforcement partners in New York, Patel highlighted the FBI-led Joint Terrorism Task Forces – now more than 200 strong nationwide – as one of the country’s most effective defenses against terrorist threats.

The JTTFs connect intelligence, pursue leads, investigate threats, gather evidence, make arrests, and act before warning signs become a tragedy.

That mission is especially urgent as the confrontation with the Islamic Republic of Iran enters a more dangerous phase. 
Iran does not need to launch missiles at the United States to threaten Americans at home. It can rely on intelligence operatives, cyber actors, proxy networks, criminal intermediaries, illicit finance, and covert facilitators – tools of an asymmetric campaign designed to blur the line between a conflict overseas and a threat on American soil.

The lesson of 9/11 is not that every warning indicates an imminent attack. It is that warnings must be assessed seriously, intelligence shared quickly, and institutions must not wait for certainty when credible signs of operational preparation are visible.

SMOKE BILLOWS from the World Trade Center towers after planes were crashed into them by al-Qaeda terrorists, on September 11, 2001.
SMOKE BILLOWS from the World Trade Center towers after planes were crashed into them by al-Qaeda terrorists, on September 11, 2001. (credit: REUTERS)

Counterterrorism succeeds not through panic or indiscriminate suspicion, but through disciplined investigation, sound intelligence, and timely disruption.

The FBI has made clear that Iran presents a threat across several fronts: foreign intelligence activity, terrorism, cyber operations, sanctions evasion, illicit procurement, and transnational repression. The Bureau is committed to identifying and disrupting Iranian intelligence and military operations that threaten Americans, US national security, or critical infrastructure.

Its public record includes investigations into attempted attacks and kidnappings, espionage, foreign influence, cyberattacks, and alleged plots targeting US officials and Iranian dissidents.

A military setback for Tehran would not necessarily dismantle its capacity for covert retaliation. Airstrikes can destroy military infrastructure, but not automatically erase the relationships, financial channels, intelligence contacts, cyber capabilities, proxy connections, and criminal intermediaries that enable the regime to project coercion beyond its borders.

Iran’s security apparatus – including the Islamic Revolutionary Guard Corps, the Quds Force, and the Intelligence and Security Ministry – does not operate only through conventional military means. These bodies have repeatedly been associated with intelligence operations, terrorism, threats against dissidents, cyber activity, and relationships with foreign networks.

The FBI’s Iran-threat page cites cases ranging from an alleged IRGC-linked murder-for-hire plot against a former US national-security adviser to conspiracies linked to Iranian officials, cyber intrusions, and efforts to obtain sensitive American technology.

But analytical discipline is essential. A possible threat is not the same as a credible threat. An identified contact is not necessarily an operational network; a network is not automatically a sleeper cell; and a sleeper cell is not the same as a confirmed terrorist plot.

The United States should not confuse suspicion with proof, rhetoric with operational preparation, or nationality with criminal intent.

At the same time, responsible caution must not become complacency.

The FBI and its JTTFs must focus on indicators that separate broad concern from an actionable threat: surveillance of potential targets, coordinated communications, suspicious financial transfers, logistical preparation, weapons procurement, recruitment of criminal intermediaries, or attempts to identify vulnerabilities at sensitive sites.

The purpose is not to label every Iranian connection as dangerous, but to recognize when hostile capability, intent, and preparation converge.

Iran’s pattern of transnational repression deserves particular attention. For years, the regime has sought to intimidate, harass, surveil, abduct, or threaten dissidents and critics beyond its borders. Iranian Americans, journalists, activists, former officials, and other people regarded by Tehran as adversaries can become targets of coercion.

A government that exports repression into the United States is challenging American sovereignty and the rule of law.
Jewish and Israeli institutions also require sustained attention. The Islamic Republic’s hostility toward Israel and demonization of Jewish communities are central features of its ideology and official messaging. 

Iranian-linked operations and alleged plots in several countries have involved Israeli diplomatic facilities, Jewish institutions, and individuals associated with Israel. That history does not establish that a specific attack against a synagogue, Jewish school, community center, or Israeli-linked target in the United States is imminent.

But it does establish a serious threat context demanding vigilance, targeted protection, intelligence sharing, and rapid investigation when credible warning signs emerge.

Cybersecurity is another front where Iran can impose costs without firing a conventional weapon. The FBI, CISA, NSA, and the Defense Cyber Crime Center have warned that Iranian state-sponsored or affiliated cyber actors may target vulnerable US networks and entities of interest.

Their joint guidance urges heightened vigilance around critical infrastructure, while noting that authorities had not observed a coordinated, Iran-attributed malicious cyber campaign at the time of the advisory.

Hospitals, energy systems, water utilities, transportation networks, communications providers, financial institutions, industrial suppliers, and local governments are all potential targets for disruption. A successful cyberattack can affect public safety, commerce, trust, and daily life without a single soldier crossing a border.

The FBI’s cyber squads, working with CISA and private-sector partners, must identify malicious activity, share threat information quickly, and prevent isolated intrusions from becoming a broader campaign.

This is why the JTTFs remain indispensable. The FBI describes them as America’s front-line defense against international and domestic terrorism. They bring together investigators, analysts, linguists, intelligence specialists, and local, state, and federal partners to follow leads, protect major events, share intelligence, and respond immediately to threats.

The first JTTF was formed in New York in 1980; today, roughly 200 operate nationwide.

FBI's Iran-focused counterterrorism

The FBI’s task is clear: it must deepen Iran-focused counterterrorism coordination across its field offices and JTTFs; prioritize investigations involving transnational repression, illicit finance, criminal facilitation, and threats against vulnerable people and institutions; strengthen cooperation with CISA when cyber activity carries national-security implications; and ensure that credible threat information reaches state and local partners in time to act.

Effective counterterrorism must follow evidence, behavior, financing, networks, and operational indicators – not ethnicity, religion, nationality, immigration status, or political belief. Iranian Americans, Iranian dissidents, Muslims, immigrants, and other communities must never be treated as objects of collective suspicion.

America’s strength lies in defending itself without abandoning the constitutional principles that distinguish it from authoritarian regimes.

Twenty-five years after 9/11, America should remember that homeland security is not measured by the force of its response after a catastrophe. It is measured by whether the FBI recognizes evolving threats, connects warning signs, and acts before hostile intent becomes operational violence.

Iran does not need to win a conventional war to endanger Americans. The FBI and its Joint Terrorism Task Forces must ensure that Tehran’s shadow threat never becomes America’s next tragedy. 

The writer is a Middle East political analyst. His latest book, Tehran’s Dictator, examines the theocratic era of Ali Khamenei (1989-2026). @EQFard