World March 1, 2026

Cyber Operations Target Iranian Apps and Websites During U.S.-Israeli Strikes

Religious calendar app BadeSaba defaced as internet connectivity in Iran falls and cybersecurity firms report rising hostile activity

By Derek Hwang
Cyber Operations Target Iranian Apps and Websites During U.S.-Israeli Strikes

Early on Saturday, coordinated cyber-enabled operations coincided with joint U.S.-Israeli strikes on targets across Iran. Multiple news sites were defaced and the widely used religious calendar app BadeSaba, with more than 5 million downloads, was hacked to display messages urging a reckoning and calling for members of the armed forces to lay down arms. Internet connectivity within Iran experienced sharp drops at two intervals, and several cybersecurity firms reported increased reconnaissance, DDoS attacks, and destructive "wiper" activity attributed to Iranian-aligned actors.

Key Points

  • Cyber operations coincided with joint U.S.-Israeli strikes on targets in Iran, including defacements of news websites and the hacking of BadeSaba, a religious calendar app with over 5 million downloads.
  • Iran's internet connectivity fell sharply at 0706 GMT and again at 1147 GMT, leaving only minimal connectivity, according to Doug Madory of Kentik.
  • Cybersecurity firms reported increased reconnaissance, DDoS attacks, and state-backed "wiper" activity against Israeli targets; sectors impacted include government services, military networks, and internet-exposed industrial systems.

Early Saturday morning, a series of cyber-enabled operations unfolded alongside joint U.S.-Israeli strikes targeting locations in Iran, according to cybersecurity observers and analysts. The digital activity included the defacement of a number of news websites and the compromise of BadeSaba, a religious calendar application that has been downloaded more than 5 million times.

Users of the BadeSaba app were presented with messages telling them "It's time for reckoning" and urging members of the armed forces to give up weapons and "join the people." Attempts to reach BadeSaba's chief executive for comment were unsuccessful. A spokesperson for U.S. Cyber Command did not immediately respond to requests for comment.


Network monitoring data showed abrupt reductions in Iran's internet connectivity at two distinct times on the same day. "Internet connectivity in Iran dropped precipitously at 0706 GMT, and then again at 1147 GMT, with only minimal connectivity remaining," Doug Madory, director of internet analysis at Kentik, said in a post on X.

Security researchers described the hack of BadeSaba as tactically significant. Hamid Kashfi, a security researcher and founder of cybersecurity firm DarkCell, said the compromise was a smart move because the app is used by government supporters who tend to be more religious.

In addition to the app and media defacements, there were reports that cyber operations hit a range of Iranian government services and military targets with the stated aim of limiting a coordinated Iranian response. Those claims were reported by the Jerusalem Post; independent verification of those specific assertions was not available at the time this report was filed.


Cybersecurity experts warned that the immediate activity could presage further online actions. "As Iran considers its options, the likelihood increases that proxy groups and hacktivists may take action, including cyberattacks, against Israeli and U.S.-affiliated military, commercial, or civilian targets," said Rafe Pilling, director of threat intelligence at cybersecurity firm Sophos. Pilling added that such attacks could include "the amplification of old data breaches presented as new, unsophisticated attempts to compromise internet-exposed industrial systems, and potentially direct offensive cyber operations."

Observers at anti-ransomware and security firms reported rising activity in the region. Cynthia Kaiser, a former senior FBI cyber official and now senior vice president at Halcyon, said activity in the Middle East had increased. Kaiser noted that her firm had seen calls to action from known pro-Iranian cyber personas that have previously carried out hack-and-leak operations, ransomware attacks and distributed denial-of-service attacks, commonly known as DDoS, which flood internet services and render them inaccessible.

Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, said the current cyber activity could be a precursor to more forceful operations. "CrowdStrike is already seeing activity consistent with Iranian-aligned threat actors and hacktivist groups conducting reconnaissance and initiating DDoS attacks," he said.

Cybersecurity firm Anomali reported in analysis shared with this outlet that state-backed Iranian hacking groups were carrying out "wiper" attacks that erase data on Israeli targets ahead of the strikes.


Though U.S. cyber officials often cite Iran alongside Russia and China as a threat to American networks, Tehran's past responses to attacks on its soil have sometimes been limited in their digital impact. For example, after U.S. strikes on Iranian nuclear targets in June, there was little evidence of broad disruptive cyberattacks beyond a short-lived interruption of services in Tirana, the capital of Albania, according to media reports at the time.

At present, cybersecurity firms and analysts continue to monitor for additional waves of activity, including hack-and-leak operations, ransomware, DDoS campaigns, and potential attempts to disrupt internet-exposed industrial systems. The evolving situation underscores how kinetic strikes and cyber operations can unfold in parallel and create complex risk dynamics for governments, critical infrastructure and commercial networks.

Risks

  • Escalation of cyberattacks by proxy groups and hacktivists against Israeli and U.S.-affiliated military, commercial, or civilian targets, which could affect defense contractors and international commerce.
  • Potential spread of disruptive activity such as DDoS and "wiper" attacks that can impair critical infrastructure and industrial systems accessible via the internet.
  • Uncertainty around claims of strikes on Iranian government and military digital assets - independent verification was not available, creating ambiguity about the full scope and attribution of operations.

More from World

Trump says U.S. forces are sinking Iran's navy as strikes intensify Mar 1, 2026 Merz Urges Partners to Prepare 'Day After' in Iran as Region Faces Uncertainty Mar 1, 2026 Trump Says Iran’s New Leadership Seeks Talks; Details and Timing Unclear Mar 1, 2026 EU Officials See Chance for Change in Iran After Khamenei's Death, Warn of Instability Mar 1, 2026 North Korea Condemns Israeli Strikes and U.S. Military Action as 'Illegal Aggression' Mar 1, 2026