Iran’s state broadcaster, Islamic Republic of Iran Broadcasting (IRIB), suffered a brief satellite broadcast hijack that replaced regular programming with footage of anti-regime protests, messages from exiled Crown Prince Reza Pahlavi, and appeals for security forces to defect and support demonstrators. The intrusion reportedly lasted about 10 minutes before authorities restored the feed. Anonymous-linked social media accounts, including @YourAnonTV, claimed responsibility under the #OpIran banner in cooperation with Iranian hackers, but attribution remained unconfirmed.
The disruption reportedly affected satellite transmissions carried via the Badr satellite and quickly spread online through opposition and social media channels. The incident echoed earlier periods of unrest in Iran, where authorities have tightly controlled communications, including a nationwide shutdown that cut access to foreign internet services while leaving domestically hosted sites reachable through Iran’s so-called National Internet. The broadcast hijack adds to a pattern of symbolic attacks on state media infrastructure during politically sensitive moments, though no confirmed link was established to more advanced actors such as Predatory Sparrow.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
After the January 18, 2026 IRIB broadcast intrusion, Anonymous, primarily through the @YourAnonTV account on X, claimed responsibility and said it acted with Iranian hackers under the #OpIran banner. The article notes that this attribution remained unconfirmed.
On January 18, 2026, around 9:30 PM Tehran time, Iran's state broadcaster IRIB suffered a brief satellite broadcast hijack that replaced normal programming with anti-regime protest footage, messages from Reza Pahlavi, and calls for security forces to defect. The intrusion reportedly lasted up to about 10 minutes before authorities reversed it.
During the November 2019 fuel protests, users in Iran lost access to websites and applications hosted outside the country, including Google and WhatsApp, while mobile internet was also unavailable. Domestically hosted Iranian sites remained reachable, effectively confining users to Iran's national intranet.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.