Five men have been arrested after vans were seen near RAF Fairford. Investigators are probing an alleged bomb plot that may be linked to Iran, although other possibilities, including Russian sabotage, have not been ruled out. The case underscores Tehran’s multi‑pronged campaign — missiles, proxy attacks, cyber intrusions and hybrid infiltration — that has extended tensions across Europe and prompted security services to disrupt dozens of plots.
RAF Fairford Alleged Bomb Plot — Iran’s Expanding Campaign Of Retaliation Targets Europe

British counter‑terror police are investigating an alleged bomb plot near RAF Fairford in Gloucestershire after three vans were seen heading toward a nearby village and five men were arrested on suspicion of preparing a terrorist act. Investigators are treating the episode as potentially linked to Iran, though they have not ruled out other possibilities, including Russian sabotage.
Why RAF Fairford Matters
RAF Fairford has served as a forward operating base for US air operations launched from Europe. It was reported to have been used by US aircraft following strikes that began on 28 February. If Iran is shown to be behind any plot targeting the base, it would indicate a widening of Tehran’s campaign to retaliate against states perceived to be supporting operations aimed at it, including the UK.
How Tehran Has Projected Power
Western officials and security services say Tehran has used a mix of kinetic, proxy and cyber tools to strike at states and infrastructure linked to US and allied operations. After initial strikes in late February, Iran launched missiles and drones against US forces in the Middle East and expanded attacks to other locations that host US personnel or interests, including densely populated urban areas and energy facilities.
Proxy and Direct Strikes
Iran‑aligned militias in Iraq and the region’s proxy groups — often described as the “axis of resistance” — have attacked US troops and allied assets. The Iran‑backed Houthi rebels in Yemen have intensified strikes on shipping and on Saudi targets, prompting some European countries, including the UK and France, to provide military support to protect trade routes and energy infrastructure.
Cyber Operations and Hybrid Tactics
Cyber activity forms a central part of the campaign. By late March, security firm DigiCert reported tracking roughly 5,800 cyber‑attacks attributed to about 50 Iran‑linked groups, primarily targeting US and Israeli interests but also hitting countries across the Gulf. In the summer months, coordinated intrusions affected water and wastewater utilities in multiple US states, and reports suggested an Iran‑linked operation temporarily disrupted a UK power facility.
Iranian actors have also targeted data centres, hospitals and government systems. One operation reportedly used a false link promising bomb‑shelter locations in Israel to install spyware on victims’ devices. The UK’s National Cyber Security Centre said it handled more than 200 incidents in June, about three‑quarters of which were connected to hostile state actors including Russia, China and Iran.
Operations In Europe
Security services across Europe have linked several foiled and confirmed attacks to Iran‑aligned networks or to groups that appear to operate in support of Tehran’s aims. In March, a shadowy pro‑Iranian group calling itself Harakat Ashab al‑Yamin al‑Islamiya (HAYI) claimed responsibility for attacks on Jewish institutions and other incidents across Europe. Authorities also reported an explosion near the US embassy in Oslo and a foiled bomb plot in Paris involving a suspect allegedly recruited via social platforms.
Implications For The UK
British security officials warn that the UK could remain a target because of its political and military ties with the US and its role in regional security. MI5 director Ken McCallum told Parliament that UK services had disrupted 20 potentially lethal plots backed by Iran since 2022. A 2025 parliamentary intelligence and security committee report described Iran as a “wide‑ranging, persistent and unpredictable threat,” identifying physical attacks on dissidents and opponents as a primary concern.
What To Watch Next
Investigators are continuing to examine automotive tracking, communications data and other evidence in the RAF Fairford case. Officials will look for links to known networks, whether state‑directed or proxy forces, and assess whether this incident represents a broader escalation in Europe. Meanwhile, authorities remain vigilant to threats against energy, data and diaspora communities in the UK and allied countries.
Note: Reporting remains fluid. Authorities have described the Fairford incident as an alleged plot under active investigation; no definitive attribution has been publicly confirmed.
Help us improve.

























