Cyberspace Becomes Fourth Battlefield in Modern Warfare

States use cyber operations-espionage, disruption and pre-positioned access-to support kinetic actions in Ukraine, Iran, Venezuela and near Taiwan.

Governments now treat cyberspace as an active military domain. Cyber operations are used to gather intelligence, disrupt adversary networks and maintain long-term access ahead of or alongside kinetic military actions in Ukraine, Iran, Venezuela and near Taiwan.

Nation-state cyber activity commonly aims at espionage, regime change and territorial control. These operations prioritize stealth and long dwell times rather than quick financial gain. Dmitri Alperovitch, co-founder of CrowdStrike, noted, “If you detect nation state actors on your network, chances are they have already been there for weeks or months.” Intelligence partners within the Five Eyes conduct cyber collection for national security; officials say they do not use those capabilities to steal private-sector intellectual property for commercial advantage.

The United States formalized cyber as a military domain over the last decade. Cyber Command was ordered in 2009, placed within Strategic Command in 2010 and designated an independent unified combatant command in 2018. U.S. officials told reporters that Cyber Command was one element used to prepare the January 3, 2026 operation that resulted in the arrest of Nicolás Maduro and his transfer to the United States on narcotics-related charges.

U.S. authorities reported they used influence over Venezuelan oil assets and collected intelligence ahead of the Maduro extraction; the arrest itself involved ground forces. U.S. officials also said the operation increased U.S. influence over Venezuelan oil but did not halt narcotics flows through the region. Venezuela’s acting government continues to assert that Maduro is still the legitimate president.

On February 28, 2026, U.S. and Israeli forces launched joint missions codenamed Epic Fury and Roaring Lion targeting Iran’s nuclear capabilities and senior leaders. Cyber operations were used to degrade Iranian radar and air defenses prior to airstrikes, and network intrusions contributed to locating key figures. Iran’s supreme leader Ayatollah Ali Khamenei and several senior commanders were reported killed in those strikes. Iranian authorities have carried out both kinetic and cyber responses, and on July 22, 2026 U.S. agencies warned that Iranian actors were exploiting programmable logic controllers across U.S. critical infrastructure.

Territorial disputes have been accompanied by sustained cyber campaigns. Russian cyber operations preceded and accompanied the 2014 seizure of Crimea and the 2022 invasion of Ukraine. Russian-linked groups used malware such as Snake and Uroburos against government targets and deployed destructive wipers including WhisperGate, HermeticWiper and IsaacWiper against financial, defense and aviation systems. An attack on a KA-SAT satellite network in early 2022 disabled thousands of modems and degraded Ukrainian communications at the start of the invasion. Despite these cyber effects and continued ground combat, Russia has not achieved its stated strategic objectives in Ukraine.

Security researchers and intelligence agencies have linked a campaign called Volt Typhoon to Chinese operators embedding long-term access in utilities, communications and transportation systems near Taiwan. Taiwan supplies roughly 90% of the world’s most advanced semiconductor chips. U.S. officials have said Chinese cyber activity is intended to prepare for a range of contingencies involving Taiwan.

Analysts and practitioners report that cyber tools typically support and shape kinetic campaigns but seldom produce decisive wins on their own. Cyber operations have been used for pre-positioning, espionage and interference ahead of kinetic actions across multiple theaters.

Articles by this author