Overview
- Network data from NetBlocks, Cloudflare and Kentik show national traffic collapsing early Saturday and stabilizing at near-zero levels, with limited allowlisted routes preserving some official access.
- Coordinated hacks hit multiple Iranian news sites and the BadeSaba prayer app, which pushed messages urging security forces to surrender; no group has claimed responsibility and analysts say attribution remains unclear.
- Kentik’s Doug Madory reported sharp drops at 07:06 and 11:47 GMT on February 28, consistent with previous regime-enforced shutdowns used to control information flows and impede coordination.
- Cybersecurity firms including CrowdStrike, Sophos and Flashpoint report rising activity from Iranian-aligned actors and hacktivists, warning of reconnaissance, DDoS and possible wiper operations against regional and international targets.
- The prolonged blackout and cyber disruptions have created an information vacuum for civilians, raised operational risks for businesses and infrastructure, and are expected to fuel decentralized cyber retaliation.