The foiling of suspected terror plot near RAF's Fairford airbase in the UK, which is used by the US to attack Iran, has revived an old question about Iran’s ability to retaliate far beyond the Middle East.
There is still no evidence that the five British men arrested, and now being bailed out, near the US-used airbase were linked to Iran, and British police say several lines of inquiry remain open. Iran has denied any connection to the incident. But the possibility of Iran-linked attacks in America and Europe has been repeatedly flagged by Western security officials and counterterrorism experts, particularly after direct US strikes on Iranian territory.
ALSO READ | Trump says UK terror suspects were looking to do ‘big damage’ near US air base
Fairford is a warning sign, not proof of an Iranian operation
British police arrested five British nationals near RAF Fairford on Sunday after reports of three suspicious vans travelling towards the airbase. The men were arrested on suspicion of preparing a terrorist act and have since been released on bail while remaining under investigation.
The Iran angle, though speculative, is understandable. RAF Fairford has been used by the US Air Force for operations against Iran and the Islamic Revolutionary Guard Corps warned in July that bases used for attacks on Iranian territory would be legitimate targets. Reuters reported that investigators were considering an Iranian-linked motive, alongside other possibilities including Russian sabotage and Islamist extremism.
ALSO READ | Police declare major incident at UK's Fairford air base, used by US air forces
None of that establishes an Iranian connection to the Fairford suspects. The episode nevertheless illustrates the problem for Western governments that retaliation can potentially be conducted without an obvious Iranian military signature.
Iran has spent years developing overseas options
Matthew Levitt, a former FBI and Treasury Department counterterrorism official, told USA Today in March this year that Iran had spent years developing the capability to conduct attacks abroad, including inside the US. His assessment was that the current conflict could provide Tehran with a strong incentive to use that capability.
The concern is not theoretical. US authorities had reportedly disrupted at least 17 Iranian-linked plots in America since the 2020 killing of Qassem Soleimani. Some involved alleged murder-for-hire schemes against former American officials.
John Bolton, the former US national security adviser, had told USA Today that the entire American counterterrorism apparatus should be on high alert. Bolton had previously received FBI "duty to warn" alerts over confirmed Iranian threats against him following the Soleimani killing. He said Iran's regime would try to use every mechanism available to retaliate. Iranian state has pursued targets on Western soil even outside periods of open war.
Proxies are only one part of the threat
Chris Swecker, a former assistant FBI director, had told Fox News Digital in March that Hezbollah and Hamas networks or sympathisers inside the US could become relevant during a direct US-Iran confrontation. His assessment was that an American military campaign alongside Israel could change the domestic threat environment quickly.
Jason Pack, a retired FBI supervisory special agent, made a different but related point in comments to the Daily Mail at that time. He said the immediate danger might come from someone already living in America who independently decides to act rather than from an IRGC team entering the country. Pack also highlighted the legal problem facing investigators. A person can attract counterterrorism attention without having crossed the line into a prosecutable conspiracy. That makes self-radicalised violence particularly difficult to prevent.
A centrally directed Iranian operation and an individual motivated by Iranian propaganda may produce very different evidence. The second can give Tehran considerable deniability.
Sleeper cells remain a concern
Barak Seener, a senior fellow at the Henry Jackson Society, told Fox News Digital in June last year after US strikes on Iran that Iran could turn to sleeper cells in the US, Britain and Europe as its conventional military options and proxy networks came under pressure. He said such networks could conduct surveillance before targeting community centres or officials.
Jonathan Gilliam, a former FBI special agent who worked on terrorism task forces, warned that Iranian sleeper cells could be difficult to identify because they might already be living openly in American communities. Gilliam also suggested that rural areas and lightly protected public venues could be attractive targets. His comments should be treated as a threat assessment rather than evidence that such cells have been found. The DHS advisory issued after the June 2025 US strikes likewise warned that violent extremists could independently mobilise if Iran's leadership issued a religious ruling calling for retaliation.
The lone-wolf problem may be harder to detect
Charles Marino, a former DHS senior adviser and Secret Service supervisor, told the Daily Mail in March that the US faced a convergence of possible threats ranging from Iran-aligned lone attackers to organised sleeper cells. He said small groups could potentially conduct simultaneous or near-simultaneous attacks against crowded public venues. That scenario does not require Iran to insert a team of operatives immediately before an attack. Individuals already in the country could potentially provide the access and local knowledge.
This was also the point behind Pack's warning. Iranian state propaganda can identify enemies and create an ideological incentive to act without necessarily issuing an operational order. For investigators, proving the difference between inspiration and direction can be difficult.
Cyberattacks give Iran another route
Iran's reach is not confined to physical terrorism. James Knight, a cybersecurity specialist, told the Daily Mail last year that Iranian hackers could target US banks, hospitals, power systems and oil infrastructure. He said the objective would more likely be disruption and public pain than the permanent destruction of American infrastructure.
Knight also warned that malware could potentially be placed inside networks before an open conflict and activated later. The claim that specific American systems already contain such malware is an expert warning, not evidence that this has happened in any particular network.
Cyber operations are attractive because attribution is harder. A disruptive attack can be conducted by state-linked hackers, proxy groups or hacktivists operating with varying degrees of direction from Tehran.
Europe is already part of Iran’s security equation
Britain faces a particularly complicated exposure because it is both a close US military ally and a country hosting American forces. Seener specifically identified Britain and Europe alongside the US as possible targets for Iranian sleeper-cell activity.
The concern predates Fairford. British intelligence has repeatedly warned about Iranian intelligence operations on British territory. The country's security services have previously described Iranian plots against dissidents and other targets as a serious threat.
The Fairford incident therefore matters even if investigators ultimately establish no Iranian connection. A US base being used for attacks on Iran gives it obvious strategic significance, while the arrest of British nationals would also illustrate how a foreign conflict can create a domestic security problem without foreign operatives necessarily crossing a border.
What happens if Iran itself fragments?
Stefano Ritondale, chief intelligence officer at geopolitical risk consultancy Artorias, had told the Daily Mail a few months ago that the removal or collapse of Iran's leadership could produce an unpredictable security environment. He warned that splinter factions could emerge with transnational ambitions rather than the threat simply disappearing.
That is a scenario rather than an established development as nothing of this sort happened in the US after hits on top Iranian leadership. But it highlights the difference between Iran's government and the wider network of organisations, operatives and ideology associated with the Islamic Republic.
The central question is attribution
The Fairford case shows why attribution will be crucial in the months ahead. Iran has a documented history of pursuing targets overseas and Western officials have repeatedly warned about its ability to use proxies, covert networks, sympathetic individuals and cyber operations. But those capabilities cannot by themselves establish responsibility for a particular attack.
The five men arrested near Fairford may ultimately be shown to have had no connection to Iran. The investigation could also reveal a foreign-state connection, including one that does not involve direct orders from Iran.
Until investigators establish that link, the responsible assessment is to treat the Iranian angle as a live possibility rather than a conclusion. But for the US and Europe, the general risk is clear enough without making that leap. Iran has demonstrated an ability and willingness to pursue adversaries outside its borders. What remains uncertain is when, where and through which mechanism that capability might be used if Iran is forced into a corner and decides to hit beyond the battlefield.