Gen. partnerAlgotech

Iran offline: widespread internet blackout and cyber incidents during the crisis

Large-scale outages are not new in the Iranian context. Since 8 January 2026 there have been prolonged connectivity restrictions during protests, when monitoring organizations recorded a dramatic drop in traffic across multiple providers.

|
March 1, 2026
Iran offline: widespread internet blackout and cyber incidents during the crisis

In recent days Iran experienced one of the most dramatic restrictions of internet access that independent monitoring services have ever recorded. According to data NetBlocks, nationwide internet connectivity on 28 February 2026 fell to approximately 4 % of normal levels, corresponding to an almost complete blackout of the entire country.

Monitoring platform Cloudflare Radar registered a similar development: a sharp drop in announced IPv6 addresses and then virtually zero network traffic from Iranian networks. This pattern corresponds to an intervention at the level of the internet's backbone routing – the level controlled by major operators and the state.

Blackout as a recurring tool for controlling the internet

Large-scale outages are not new in the Iranian context. Since 8 January 2026 there have been prolonged connectivity restrictions during protests, when monitoring organizations recorded a dramatic drop in traffic across multiple providers.

At times traffic was practically zero, suggesting an intervention in the routing itself rather than just blocking individual applications or social networks.

At the same time, Iran has long been building its own infrastructure known as the National Information Network (NIN), a partially isolated domestic network intended to enable selected services to operate even when disconnected from the global internet. The current restrictions, however, affected a broader range of services including mobile networks and some government portals, raising questions about the true resilience of this architecture.

Cyber incidents beyond the blackout itself

The blackout was not the only digital event. During the same period a specific cyber incident was also recorded at the application layer.

Security media reported a compromise of the popular application BadeSaba Calendar, which is used to determine prayer times and has millions of downloads. Users received push notifications calling for "surrender" and promising amnesty to military personnel.

According to experts cited by the media, the timing of these messages appeared to be a targeted information operation. The attacker's identity, however, has not been confirmed and official attribution is still lacking.

The incident shows that digital pressure during crises does not have to occur only at the infrastructure level, but can also target end users directly through mobile applications.

What the blackout means from a technological perspective

A massive reduction in connectivity to single-digit percentages of normal traffic usually means:

  • withdrawal or restriction of BGP routes,
  • a significant reduction in announced IP ranges,
  • interruption of international transit links,
  • or the implementation of a "whitelisting" model, where only selected internal services are allowed.

Such measures greatly limit the ability to circumvent blocks using VPNs and also complicate independent verification of information from the country.

The digital space as part of crisis management

Available data indicate that the blackout in Iran matches the technical pattern of a state-directed restriction of connectivity. The outage itself cannot, without detailed analysis, be conclusively labeled as an external cyber attack.

The parallel compromise of the mobile application, however, shows that during crises there are also targeted operations at the application layer with potential psychological impact.

The current situation thus illustrates a broader trend: modern digital conflicts are not limited to infrastructure. They include a combination of network restrictions, control of information flows, and targeted interventions into services that have direct reach to millions of users.

Why this is relevant beyond Iran

A massive nationwide blackout shows how quickly digital infrastructure can be paralyzed. For states and companies outside the region, it serves as a reminder of the need to build network resilience, crisis communication scenarios, and protection for endpoint applications.

The digital space today is not just a technical layer above the conflict – it is a full-fledged part of it.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.