Iran imposed a near-total nationwide internet blackout that lasted for weeks, with rights groups and network monitors saying the shutdown was used to suppress information and dissent while preserving tightly controlled access for selected businesses, vetted users, and regime-linked insiders. Reports described a developing two-tier system in which most people were left on a degraded domestic intranet while some users received limited or privileged connectivity through state-approved packages and so-called white SIM cards, even as the blackout inflicted heavy economic damage and became one of the longest nationwide shutdowns in recent years.
Despite the restrictions, Iranians continued communicating through censorship-resistant tools and alternative channels including Psiphon, Lantern, Tor Browser with Snowflake, shortwave radio, landline calls, satellite filecasting via Toosheh, and limited Starlink access. Usage surged during the blackout, with Psiphon reportedly reaching nearly 9.6 million daily users in Iran and up to 26 million daily Conduit connections, while researchers and advocates warned that access remained costly, risky, and subject to surveillance, raids, arrests, and severe penalties as Tehran appeared to move toward a more permanent whitelisted internet model.

See the reporting duties and controls this puts on the clock.
11 events from the most recent confirmed update back to the earliest known activity.
After the May 12 outage, the Islamic Cyber Resistance in Iraq-313 Team claimed responsibility, alleging it had launched a DDoS attack against Spotify's servers. The group said the attack was retaliation for the death of Imam Khamenei.
Spotify experienced a significant outage on May 12, 2026, affecting its app, web player, and support services for several hours. User reports peaked at about 14,000, and Spotify said it was investigating before later confirming service had been restored.
By April 2026, observers described Iran's internet disruption as the longest nationwide shutdown ever recorded in any country. The milestone underscored the scale of the blackout as most users remained confined to a heavily censored intranet with only selective access restored.
By mid-April, Iran had begun restoring tightly controlled connectivity to some businesses and approved users through restricted 'pro internet' packages. Analysts said the move reflected a two-tiered internet model that preserved broad censorship while easing economic pressure.
By mid-March, NetBlocks and other observers reported that Iran's government-imposed blackout had lasted more than 14 days. Iranians continued communicating through landlines, shortwave radio, Psiphon, Lantern, Toosheh, and limited Starlink access despite surveillance and arrest risks.
Following U.S. and Israeli strikes in late February 2026, Iran entered another nationwide internet shutdown that lasted for weeks. Rights groups and monitoring firms said the blackout was used to restrict information flow while most of the population remained offline.
As the shutdown persisted in early 2026, Iranians increasingly turned to censorship-resistant tools including Psiphon, Tor Browser with Snowflake, and Lantern. Psiphon usage reportedly rose to nearly 9.6 million daily users in Iran, with Conduit connections reaching as high as 26 million per day.
Iran imposed a major internet shutdown beginning on January 8, 2026, amid mass anti-government protests. Connectivity was heavily degraded nationwide, marking the start of an extended blackout.
A major protest movement began on December 28, 2025, initially driven by economic hardship and currency collapse before expanding into one of Iran's largest antigovernment uprisings in years. Demonstrations were reported in more than 187 cities, with increasingly explicit calls for regime change preceding the internet blackout.
The Intercept reported that Iran's Communications Regulatory Authority appeared to have access to a system called SIAM that could monitor, track, throttle, and suspend mobile users across Iranian cellular networks. Experts said the capabilities could help identify protesters, expose communications, weaken 2FA by forcing 2G connections, and support repression during the 2022 protest wave.
Iran shut down internet access nationwide in November 2019 amid mass protests, severely restricting communications and outside visibility into the crackdown. The blackout became a defining example of the government's use of connectivity disruptions to conceal repression and limit information flow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
31 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcescworld.com
Open sourcetechradar.com
Open sourcesdxcentral.com
Open sourcekhabaronline.ir
Open sourcetheintercept.com
Open sourceiran-shutdown.amnesty.org
Open sourcearticle19.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.