By
Gigabit Systems
September 24, 2026
•
20 min read

Iran Got Its Hands on an American Underwater Drone. Now It Wants to Copy It.
The drone failed. The intelligence opportunity didn’t.
On September 8, Iran recovered an American autonomous underwater vehicle near the entrance to the Strait of Hormuz.
The U.S. military’s version of events was considerably less dramatic than Iran’s.
According to U.S. Central Command, the underwater drone had malfunctioned more than a day earlier while surveying regional waters. It was essentially “dead in the water” when Iranian forces recovered it. The Pentagon identified it as an older model of Anduril’s Dive-LD and said it neither collected sensitive data nor carried classified sonar or radar equipment.
That might sound like the end of the story.
It wasn’t.
On September 22, Islamic Revolutionary Guard Corps spokesperson Brigadier General Hossein Mohebbi announced that Iran intends to reverse engineer the captured American drone.
That doesn’t mean Iran has successfully copied it.
It doesn’t mean Iran hacked it.
And it certainly doesn’t mean Iran suddenly possesses America’s undersea capabilities.
But it illustrates an uncomfortable reality of autonomous warfare:
Every unmanned system designed to operate where humans shouldn’t go can eventually fail somewhere humans aren’t there to recover it.
And sometimes the enemy gets there first.
What Exactly Did Iran Recover?
Iranian state media identified the vehicle as an Anduril Dive-LD, a large-diameter autonomous underwater vehicle.
Think of it less as a traditional submarine and more as an underwater robot.
Dive-LD is modular and designed to accept different payloads for different missions. Anduril describes the platform as capable of long-distance autonomous operations across defense and commercial missions.
Publicly described applications include seabed mapping, mine countermeasures, intelligence gathering and inspection of underwater infrastructure such as cables and pipelines.
But there’s an important distinction.
Those are capabilities associated with the platform family.
They don’t establish what equipment was installed on the particular vehicle Iran recovered.
CENTCOM specifically says this vehicle did not contain classified sonar or radar and wasn’t collecting sensitive information.
That distinction matters enormously.
Iran Didn’t Necessarily “Capture” a Working Drone
The word captured creates an image of Iranian forces defeating an operational American system.
The available evidence supports something less dramatic.
The U.S. says the Dive-LD malfunctioned while performing a survey mission and had already been disabled for more than a day before Iran obtained it.
Iran obtained the machine.
That doesn’t establish that Iran disabled it.
There’s currently no public evidence that Iran hacked the vehicle, electronically hijacked it or caused its malfunction.
That’s important because those would represent completely different levels of Iranian capability.
Finding a broken drone is not the same as defeating one.
But once you’ve found it, what you can learn from it becomes another question entirely.
“There’s Nothing Classified” Doesn’t Mean “There’s Nothing Useful”
This is where the story gets interesting.
People often hear:
No classified technology onboard.
And translate that into:
Nothing valuable onboard.
Those aren’t equivalent.
Imagine handing a competitor one of your company’s products.
You remove the customer database.
Erase the proprietary documents.
Delete confidential files.
That doesn’t make the physical product meaningless.
They can still take it apart.
Measure it.
Weigh it.
Inspect materials.
Study manufacturing.
Examine propulsion.
Analyze power management.
Look at waterproofing.
Study connectors.
Observe component placement.
Examine communications hardware.
Investigate thermal management.
Determine what commercially available components you’re using.
Study how modules connect.
Compare design decisions against their own engineering.
Reuters reported experts saying Iran could potentially learn useful mechanical details from the captured platform even if software protections limit how much of the complete system can be reproduced.
Reverse engineering doesn’t have to reveal a secret to teach you something.
Iran Doesn’t Need to Build a Perfect Copy
This may be the biggest misconception about reverse engineering.
Imagine Iran eventually displays an underwater drone that looks almost identical to Dive-LD.
That would be visually impressive.
But it wouldn’t tell us much.
A military system isn’t its exterior.
Can it navigate autonomously underwater?
For how long?
At what depth?
How reliably?
How accurately can it determine its position without GPS?
How well does it communicate?
How frequently does it fail?
Can Iran manufacture 10?
100?
Can technicians maintain them?
Can damaged vehicles be repaired?
Can software be updated?
Can sensors and payloads be integrated?
Can operators actually use them effectively?
Can the system perform repeatedly under operational conditions?
Those questions separate possession from capability.
A copy is not a production line.
And a prototype is not a force.
But Iran Has Played This Game Before
There’s a reason the reverse-engineering announcement is being taken seriously enough to examine rather than simply dismissed.
Iran has previously exploited captured American unmanned aircraft.
The most famous example was the RQ-170 Sentinel that Iran obtained in 2011. Iran subsequently displayed aircraft it said were reverse-engineered from the American design, although resemblance alone doesn’t establish equivalence to the original platform’s capabilities. Reuters’ reporting on the Dive-LD incident specifically points to that history when assessing what Tehran may attempt now.
That’s the distinction worth maintaining.
Iran may be very good at extracting some value from recovered technology.
That doesn’t mean it reproduces all of it.
Sometimes the Valuable Intelligence Is Knowing What
Not
to Copy
Reverse engineering isn’t simply photocopying.
Suppose Iranian engineers open the Dive-LD and discover a design decision radically different from their own.
They don’t necessarily need to reproduce it.
They’ve learned something.
Maybe they discover:
The Americans solved this problem differently.
Or:
We overengineered this component.
Or:
They’re using an inexpensive commercial part here.
Or:
Their power architecture prioritizes endurance differently than ours.
Or perhaps they discover nothing particularly surprising.
That’s useful information too.
Engineering involves thousands of decisions.
Access to a competitor’s finished system lets you examine the decisions they actually made rather than guessing.
The prize isn’t necessarily the blueprint. It may be the shortcut.
There Is Another Kind of Intelligence Iran Could Want
Understanding an adversary’s equipment isn’t only useful for copying it.
It can potentially help you counter it.
What does it sound like underwater?
What physical characteristics distinguish it?
What communications equipment does it carry?
What observable signatures might it produce?
What components appear vulnerable?
What operational assumptions influenced its design?
Could future sensors be optimized to detect similar systems?
Could recovered components reveal characteristics useful in identifying related platforms?
Exactly what Iran can learn from this particular vehicle isn’t publicly known, and CENTCOM’s description suggests the sensitive payload risk is limited.
But this illustrates why equipment exploitation matters.
Sometimes you reverse engineer a weapon because you want one.
Sometimes you reverse engineer it because you want to recognize the next one.
Anduril Would Say Loss Is Part of the Design Philosophy
There’s another side to this story.
Anduril described Dive-LD after the incident as an “attritable autonomous system.”
In other words, it is designed for dangerous environments where losing individual vehicles is considered a possibility.
The company told DefenseScoop that the recovered vehicle had already delivered substantial operational value through thousands of hours of operations in CENTCOM.
That’s an important philosophy behind modern autonomous warfare.
If sending a crewed submarine into an environment creates unacceptable danger, perhaps send an autonomous system instead.
If it’s lost, you’ve lost equipment.
Not sailors.
That’s a compelling trade.
But “attritable” creates its own cybersecurity and counterintelligence requirement:
If you’re willing to lose the machine, you’d better be comfortable with somebody eventually finding it.
Attritable Must Also Mean Exploitable-Safely
This is where cybersecurity becomes inseparable from hardware design.
Engineers designing autonomous military systems should assume some percentage will eventually be:
Lost.
Recovered.
Disassembled.
X-rayed.
Imaged.
Probed.
Analyzed.
Connected to laboratory equipment.
Studied for months.
The security model cannot depend on the adversary never obtaining physical access.
That’s the military equivalent of designing a laptop whose security depends on nobody stealing it.
Sensitive systems therefore need protections appropriate to their threat model: strong encryption, protected key storage, secure boot, signed firmware, compartmentalized mission data, credential revocation and architectures that minimize what one captured platform can reveal about the larger fleet.
The objective isn’t to make reverse engineering physically impossible.
That’s unrealistic.
It’s to make losing one machine reveal as little as practical about every other machine.
This Isn’t the First Time Iran Has Tried to Grab an American Drone
There’s useful historical context here.
In August 2022, an Iranian Revolutionary Guard support ship attempted to tow away a U.S. Navy Saildrone Explorer operating in international waters in the Arabian Gulf.
That time, the U.S. noticed.
The patrol ship USS Thunderbolt responded.
So did an MH-60S Sea Hawk helicopter.
After roughly four hours, the Iranian vessel released the drone.
The Navy emphasized then that the Saildrone used commercially available technology and stored no sensitive or classified information.
Sound familiar?
There is, however, an important difference.
That Saildrone was an unmanned surface vessel.
The Dive-LD is an autonomous underwater vehicle.
They’re different platforms operating in very different environments.
But together they illustrate a broader operational problem.
Unmanned Doesn’t Mean Unattended
This may be one of the hidden costs of autonomous warfare.
Imagine deploying 1,000 autonomous vehicles because they’re cheaper and safer than crewed platforms.
Excellent.
Now imagine 30 malfunction.
Do you recover them?
When?
Using what?
How many ships?
How many aircraft?
How many personnel?
How much risk?
And how close to hostile forces?
Suddenly an inexpensive unmanned platform can create a very expensive decision.
In the 2022 incident, protecting one commercially available Saildrone involved a U.S. patrol ship and helicopter.
That doesn’t mean deploying the drone was a mistake.
It means:
The cost of an autonomous system isn’t necessarily the price printed on the invoice.
Recovery, protection, maintenance, communications, logistics and the intelligence consequences of loss belong somewhere in the calculation.
The Strait of Hormuz Makes Everything More Significant
This didn’t happen in a random patch of ocean.
Iran says the vehicle was recovered near the entrance to the Strait of Hormuz.
Few waterways matter more to global energy markets.
During the second quarter of 2026, oil flows through Hormuz averaged only about 4.9 million barrels per day, down dramatically from roughly 21.6 million barrels per day in the fourth quarter of 2025 amid regional disruptions.
The U.S. Energy Information Administration reported that disruptions through the strait contributed to higher and more volatile crude-oil prices during much of the second quarter.
That does not mean losing this drone affected oil prices.
There is no evidence that it did.
It means the location where autonomous systems are operating is strategically consequential.
Underwater surveillance.
Mine detection.
Seabed infrastructure.
Shipping.
Energy.
Military movements.
All converge in a narrow maritime environment.
There Is Also a Propaganda Victory
Iran doesn’t have to successfully reproduce Dive-LD to get value from it.
It has the American machine.
It can photograph it.
Display it.
Disassemble it.
Talk about reverse engineering it.
Present possession as evidence of technological or military success.
That value exists immediately.
Technical exploitation takes longer.
And those two things shouldn’t be confused.
Iran possessing an American underwater drone is established.
Iran announcing reverse engineering is established.
Iran successfully reproducing Dive-LD’s capabilities is not established.
Iran hacking the vehicle is not established.
Iran causing its malfunction is not established.
Iran obtaining classified U.S. technology from it is not established—and U.S. officials specifically say it carried no classified sonar or radar and no sensitive data.
Those distinctions matter.
The Real Test Comes Later
Eventually Iran may display something.
That isn’t the test.
The test is:
Can it operate?
Can Iran manufacture it repeatedly?
Can it maintain it?
Can it integrate useful payloads?
Can it perform missions reliably?
Can it survive?
Can it meaningfully change Iranian undersea operations?
Capability is measured by sustained performance, not resemblance.
The same standard should apply to the United States.
One failed Dive-LD doesn’t establish that autonomous underwater warfare doesn’t work.
But neither should impressive demonstrations be enough to establish that autonomy is ready to replace crewed capability.
The real measure is sustained mission performance—including what happens when systems fail.
The Cybersecurity Lesson Is Bigger Than This Drone
We’ve spent decades protecting computers from remote attackers.
Autonomous warfare creates another assumption:
Eventually, your computer may physically belong to the attacker.
That’s an extraordinarily hostile security environment.
Imagine designing an enterprise server while assuming that someday your most capable adversary will:
Steal it.
Open it.
Image every storage device.
Inspect every chip.
Analyze the firmware.
Probe the interfaces.
Study it for years.
Then use what they learn to attack the rest of your network.
That’s effectively the problem facing designers of attritable autonomous military systems.
And it’s why this incident matters even if CENTCOM is completely correct that there was nothing exquisite or classified onboard.
The goal isn’t simply:
Don’t lose the drone.
The more scalable requirement is:
Design the drone assuming eventually you will.
Iran has an American underwater vehicle.
Now it wants to learn everything the machine is capable of teaching.
Whether that produces a genuine Iranian capability remains to be seen.
But there’s already a lesson for every organization deploying autonomous systems:
If a machine is expendable, its secrets need to be expendable too.
70% of all cyber attacks target small businesses, I can help protect yours.
#Cybersecurity #AutonomousSystems #DefenseTechnology #ArtificialIntelligence #DataProtection
Iran now has an American underwater drone—and says it’s going to reverse engineer it. The Pentagon says the Anduril Dive-LD was an older, malfunctioning model with no classified sonar, radar or sensitive data. But “nothing classified” doesn’t necessarily mean “nothing useful.” Iran doesn’t have to perfectly copy the drone to benefit from taking it apart.