Key Judgments
- [CONFIRMED] – The 2011 Arbabsiar plot – an IRGC Quds Force-directed attempt to assassinate Saudi Arabia’s ambassador to the US by bombing a crowded Washington restaurant, using Los Zetas cartel logistics – remains the single clearest evidentiary case of Iran’s willingness and operational reach to conduct lethal attacks on US soil. It failed only because the cartel contact was a DEA informant.
- [CONFIRMED] – US Northern Command has publicly testified to Congress that a specialized counter-drone “Flyaway Kit” was deployed within hours of Operation Epic Fury’s launch (Feb. 28, 2026) to defeat a drone incursion at an undisclosed strategic base, and that additional incursions occurred at other domestic installations in the weeks that followed.
- [CONFIRMED] – Independent reporting has identified Barksdale Air Force Base (a B-52 installation) and Minot Air Force Base (a nuclear bomber/ICBM installation) as sites where drone activity consistent with the broader incursion pattern has occurred; the identity and origin of the operators remains publicly unattributed in every case reviewed.
- [CommandEleven Intelligence Assessment] – CommandEleven Intelligence’s standing public position – stated on Survival Dispatch broadcasts – is that embedded IRGC-linked assets, many in place over 20 years, were not left waiting for a live signal from Tehran but were issued standing conditions at insertion and are directed to act autonomously once those conditions are met, a model that by design leaves no signal intercept or command trail for US law enforcement to track.
- [ASSESSED] – The overall pattern – a proven historical willingness to attempt mass-casualty attacks inside the U.S., an active homeland drone-incursion problem of undetermined origin, and a decapitation strike against Tehran’s leadership whose effect on any standing attack conditions cannot be observed from outside – should be read together as a multi-vector threat picture rather than three unconnected data points.
The Arbabsiar Precedent: Proof of Intent and Reach
Any assessment of Iran’s homeland threat to the United States has to start with the one case where intent, operational planning, and near-execution are all a matter of public record rather than inference. In 2011, Mansoor Arbabsiar – a naturalized US citizen and failed Texas car salesman – was recruited by his cousin, an IRGC officer, and introduced to senior Quds Force official Gholam Shakuri. The plan: hire a Mexican cartel contact to assassinate Saudi Ambassador Adel al-Jubeir with a bomb at his regular Washington restaurant, accepting the likelihood of mass American civilian casualties among the roughly 200 diners typically present. Arbabsiar’s cartel contact turned out to be a DEA informant, and the plot collapsed before execution – a single point of operational luck, not a failure of Iranian intent or reach. Arbabsiar pleaded guilty in 2012 and was sentenced to 25 years; his contact, Shakuri, remains at large, believed to be in Iran.
This case is examined in full in CommandEleven Intelligence’s analysis, “The Iranian Plot to Bomb a Washington Restaurant: The Arbabsiar Case,” which should be read as this dossier’s companion piece on the precedent question.
The Domestic Drone Problem
Since the outbreak of Operation Epic Fury on February 28, 2026, the domestic drone-incursion picture has shifted from background concern to an active, congressionally-testified problem. US Northern Command’s commander told the Senate Armed Services Committee that a Counter-small Unmanned Aerial System “Flyaway Kit” – validated in an October 2025 exercise at Minot Air Force Base – was deployed within hours of the war’s opening to defeat a drone threat at an undisclosed “strategic” installation. NORTHCOM has since confirmed the kit was used against multiple incursions at that base, and separate reporting has identified drone activity consistent with the same pattern at Barksdale Air Force Base, home to B-52 bomber operations, and echoing earlier, still-unattributed incursions at Langley Air Force Base in December 2023.
- [DATA DEFICIT] – In every case reviewed for this dossier, US officials have explicitly declined to confirm whether the incursions are connected to Iran or Iranian sympathizers operating domestically, whether any platforms were recovered, or whether an investigation into their source is ongoing. CommandEleven Intelligence does not assess direct Iranian state responsibility for these specific incursions; readers should treat the timing correlation with Epic Fury’s launch as noteworthy context, not proof of attribution.
The Sleeper Cell Question, Revisited
CommandEleven Intelligence’s own March 2026 intelligence compilation on IRGC sleeper cell infrastructure in the United States – produced in conjunction with Survival Dispatch News – remains the fullest public treatment of this question, built from Iran’s military structure, its asymmetric capabilities across the Middle East, Latin America, and the U.S., and the Arbabsiar case as the operative test case. That assessment holds up well against the last six months of reporting.
CommandEleven Intelligence Assessment – stated publicly on Survival Dispatch broadcasts

CommandEleven Intelligence’s operating model for these cells departs from the “wait for a signal from Tehran” framing that dominates most open-source commentary. Our assessment is that many of these assets have been embedded in the United States for over 20 years and were not left waiting for a live activation order – they were issued a standing set of conditions at the time of insertion, and are directed to act autonomously once those conditions are met. This is a materially different threat model than a centrally-triggered network, and it is precisely what makes the cells difficult for US law enforcement to track and disrupt: there is no signal intercept to catch, no command-and-control communication to monitor in the run-up to an attack, and two decades of ordinary life to build cover that gives investigators nothing anomalous to flag.

The question resurfaced with new intensity following the killing of Iran’s Supreme Leader Ali Khamenei and other senior regime figures in a coordinated US-Israeli operation in late February 2026. Counterterrorism analysts described the sleeper-cell threat as “very grave” in the operation’s aftermath. Separately, earlier in the year, federal officials circulated a warning to law enforcement following an encrypted broadcast tied to the regime that intelligence agencies assessed could function as an activation signal for covert operatives abroad. CommandEleven Intelligence’s own model treats that signal-based theory as, at most, a supplementary or contingency channel rather than the primary triggering mechanism – the conditions-based design means a signal intercept, even a real one, would not by itself indicate whether any cell’s conditions have already been independently met. Independent fact-checking of the broader claim throughout the year has consistently landed in the same place: the threat is treated as credible and elevated by intelligence agencies and informed commentators, but public reporting has not surfaced a confirmed, large-scale operational network inside the United States – consistent with a model built specifically to avoid producing that kind of confirmable signature.
- [ASSESSED] – Under CommandEleven Intelligence’s conditions-based model, the relevant question after the Khamenei strike is not whether Tehran will “give the order,” but whether the strike itself satisfies one or more standing conditions already held by embedded assets – a threshold that, by design, would not be visible to US law enforcement or open-source reporting until after the fact. This is a materially higher-confidence framing than “raised incentive to authorize an attack,” and it is the basis for CommandEleven Intelligence’s standing public position that the domestic threat window did not open or close with any single event in the war, but has been live since insertion.
Synthesis: A Multi-Vector Threat Picture
Read individually, each of these threads has an honest evidentiary gap: the Arbabsiar case is 15 years old; the drone incursions are unattributed; the sleeper-cell concern is assessed rather than confirmed. Read together, against the backdrop of an active shooting war and the most significant blow to Iran’s senior leadership since the conflict began, they describe a homeland threat environment that is qualitatively different from the pre-February 2026 baseline – proven historical intent, an active and unexplained aerial intrusion problem at nuclear-adjacent installations, and a decapitation strike against Tehran’s senior leadership whose downstream effect on any pre-set attack conditions cannot be observed from the outside.
CommandEleven Intelligence’s standing assessment, consistent with our sleeper-cell compilation from March and reiterated publicly on Survival Dispatch broadcasts, is that the greatest domestic vulnerability lies not in a large centrally-directed network waiting on a live order, but in a small number of long-embedded assets – many in place for 20-plus years – operating against standing conditions set at insertion, using cut-outs (including criminal-network logistics, per the Arbabsiar precedent) that leave no signal intercept or command trail for law enforcement to catch before the fact. This is the central analytical distinction of this dossier: the absence of confirmed activity is not evidence of an inert network. It is what the conditions-based model predicts.
Sourcing Base (Confidence-Tiered, with Links)
[CONFIRMED] – Primary/Official Record & CommandEleven Intelligence Prior Work:
- CommandEleven Intelligence, “The Iranian Plot to Bomb a Washington DC Restaurant: The Arbabsiar Case”
- CommandEleven Intelligence, “IRGC Sleeper Cells in the United States: Intelligence Compilation” (March 2026)
- DefenseScoop, “US Northern Command says it thwarted a drone threat over a ‘strategic’ installation hours into the Iran war” (Congressional testimony)
- DefenseScoop, “US military reveals more details about drone incursions at strategic base“
- Washington Post, “Man in Iran-backed plot to kill Saudi ambassador gets 25 years“
- ABC News, “Man in Alleged Iran-Backed D.C. Assassination Plot Pleads Guilty“
[ASSESSED] – Credible Secondary Reporting:
- The War Zone (TWZ), “US Battled Drone Incursions Over Key Bases At Home After Launch Of Epic Fury“
- JNS, “‘Very grave’ threat of Iranian sleeper cells in US, experts warn“
- Washington Times, “How real is the threat of Iranian sleeper cells in the US?“
- Fox News, “Enemy within: Counterterrorism experts fear sleeper cells could be poised inside US” –
- Factually.co fact-check compilation on Iranian sleeper cell claims (methodology note: aggregates 14 sources, flags partisan/alarmist framing in some outlets)
Excluded from this dossier: Specific, granular target-list or attack-scenario claims circulating in some commentary/preparedness sources. These cross into operational speculation rather than strategic assessment and are not reproduced here, consistent with CommandEleven’s standing editorial policy.