On February 28, 2026, Iran suffered one of the most severe cyberattacks in its recent history, occurring simultaneously with military operations conducted by Israel and the United States. The episode concretely demonstrates how, in modern geopolitical crises, operations in cyberspace and those on the battlefield are now closely intertwined. Understanding what happened helps shed light on the direction conflicts of our time are taking.
What Happened
On the same day that Israel and the United States launched military operations against Iran — referred to as “Operation Roar of the Lion” or “Epic Fury” according to some sources — Iran’s digital infrastructure was struck by a large-scale, coordinated attack. According to data collected by the monitoring organization NetBlocks, the country’s internet connectivity collapsed to just 4% of normal levels, effectively causing an almost total blackout of the network.
The attack combined several techniques. Among the most well-known to the general public are so-called DDoS attacks, which consist of overwhelming a system with requests until it becomes inaccessible. However, deeper intrusions into critical infrastructure were also reported, including those linked to the communications of the Islamic Revolutionary Guard Corps (IRGC), official news sites such as IRNA and Tasnim, and the energy and aviation sectors. In some cases, compromised websites reportedly displayed subversive messages visible to the Iranian public. The use of electronic warfare to disrupt communications was also reported.
Why It Matters
The impact of this attack goes beyond mere technological disruption. A communications blackout during military operations can severely undermine a country’s ability to coordinate its response, both in terms of security and public information management. The blocking of official news sites, for example, makes it difficult for the population to receive reliable institutional communications during a moment of crisis. It is not yet precisely clear what long-term damage the targeted infrastructure sustained, and many operational details remain classified or not yet verified.
What Organizations and Users Can Do
Although this attack concerns a specific geopolitical context, it offers useful lessons for anyone who manages IT systems or depends on digital continuity. It is important to keep systems up to date, have business continuity plans in place in the event of network outages, and avoid relying on a single communication channel. Organizations should also regularly assess their exposure to external disruptions, regardless of their size.
Final Takeaways
Large-scale cyberattacks can accompany or precede military operations, making cyberspace a genuine theater of conflict.
Near-total disconnection from the internet can have serious consequences for a country’s security, information flow, and capacity to respond.
Many details of these events remain uncertain or not publicly verified: it is essential to rely on trustworthy sources and avoid speculation.
Sources:
https://www.cbsnews.com/live-updates/israel-us-attack-iran-trump-says-major-combat-operations/
https://www.jpost.com/israel-news/defense-news/article-888271
https://theaviationist.com/2026/02/28/israel-us-attack-iran/
Source: DataBreaches