Inside Iran’s Internet Censorship Machine: The National Information Network in War

Follow the construction of Iran’s controlled internet from the Green Movement to the 2026 war, then examine how blackouts, whitelisting, surveillance, airstrikes, routing instability, and domestic failures reshaped it.

The morning the outside world disappeared

Evidence cutoff: 14 September 2026. On 28 February 2026, as United States and Israeli strikes began across Iran, traffic visible outside the country collapsed. Cloudflare observed the fall beginning around 10:30 local time; traffic dropped to well under one percent of its previous level. The Kentik traffic analysis saw most traffic disappear at 07:06 UTC and much of the remainder at 11:47 UTC. Yet Iran’s IPv4 routes largely remained announced.

That apparent contradiction opens the story. Iran had not simply unplugged every router. The country could remain present in global routing tables while access for ordinary people was stopped deeper in the network. Small volumes of approved traffic continued. Domestic sites remained reachable for some users. Officials and selected institutions continued posting abroad while families inside Iran struggled to message relatives or learn where strikes had landed.

The blackout was therefore not only absence. It was selection. To understand how authorities could preserve a narrow domestic network while extinguishing most international use, the story must move back two decades—to a project designed to make Iranian digital life function without an open global internet.

Building an internet that could be closed from the inside

Iran announced work on the National Information Network, or NIN, in 2006. After the 2009 Green Movement demonstrated the organizing and evidentiary power of networked communication, the project gained strategic urgency. Legislation in 2011 described an IP-based framework of switches, routers and data centers capable of directing domestic traffic within Iran. The Supreme Council for Cyberspace refined its requirements in 2016 and published a broader architecture in 2020.

The Filterwatch history of the NIN describes three layers. Infrastructure covers wired, wireless and fiber connectivity plus data centers and storage. Services include domestic cloud, search, maps, email, messaging, social networks, certificates and application platforms. Content includes government information, publications, entertainment and media. Locally hosted alternatives operate under Iranian law and infrastructure control.

The NIN has legitimate resilience functions: keeping payments, government portals or local communications available when foreign links fail. The same design also enables coercive control. If daily life depends on domestic substitutes, authorities can restrict foreign connectivity without stopping every service the state and economy require. Resilience for the government and freedom for the user are not the same property.

How the machine controls a connection

There is no single censorship machine. International connectivity is concentrated through state-controlled infrastructure; fixed and mobile operators enforce policy; filtering systems interfere with destinations and protocols; domestic platforms and hosting keep approved services nearby; subscriber identity enables differentiated treatment; and legal and security institutions punish prohibited use. Content blocking, throttling, shutdowns and surveillance are different controls that can be combined.

Measurement makes parts of this system visible. OONI documented blocking of websites, encrypted DNS endpoints, QUIC and IPv6 during earlier protest periods. Its OONI shutdown study combined probe tests with Cloudflare, IODA and Kentik observations. In 2022, for example, HTTP/3 traffic fell nearly to zero, consistent with broad interference against QUIC, while encrypted DNS endpoints experienced DNS and TLS-level interference.

The human layer completes the architecture. Platforms can be compelled to remove content or expose data. Unsanctioned circumvention tools have been prohibited. Surveillance and arrests make users censor themselves. A technically reachable service may therefore remain practically unavailable because it is slow, risky, unaffordable or identifies the person using it.

2019 and 2022: rehearsals in the streets

During nationwide protests in November 2019, authorities cut most Iranians off from the global internet for roughly five continuous days while the national intranet remained available. The event demonstrated that domestic routing and services had matured enough to support an extensive international cutoff. It also reduced the flow of videos and testimony while security forces suppressed protests.

The 2022 “Woman, Life, Freedom” protests produced a more variable pattern. Rather than one uniform national blackout, measurements showed recurring evening outages, regional restrictions, mobile-network disruption and protocol-specific blocking over weeks. This made interference harder to describe with a single on-or-off metric and imposed continuing uncertainty on users.

These episodes were not merely precedents. They trained institutions, operators and citizens. Authorities learned to preserve selected services and narrow circumvention. Users learned to rotate VPNs, share access and anticipate shutdowns. Measurement organizations learned to combine traffic, routing, DNS, protocol and user evidence. By 2025, both control and observation had become more sophisticated.

When Israel began strikes in Iran in June 2025, authorities imposed another near-total shutdown and cited wartime security. Cloudflare measured traffic roughly 97 percent below the corresponding level a week earlier. Researchers found that global routes could remain present while deep inspection, throttling and selective protocol controls isolated users. The episode supplied the immediate wartime rehearsal for 2026: preserve the country’s network presence and selected domestic functions while making global access unusable for most people.

December 2025 to January 2026: protest, blackout, and mass killing

The immediate road to the wartime blackout began in Tehran’s bazaars on 28 December 2025. A collapse in the rial, rising prices and worsening living conditions brought traders and workers into the streets. Protests spread across provinces and broadened from economic grievances into rejection of the political order. The state initially used familiar methods—arrests, tear gas, beatings and localized lethal force. Amnesty International and Human Rights Watch documented at least 28 protesters and bystanders, including children, killed across 13 cities in eight provinces between 31 December and 3 January.

On 3 January, Supreme Leader Ali Khamenei publicly characterized demonstrators as rioters who should be put in their place. On the evening of 8 January, the response changed scale. The internet blackout began as crowds gathered across the country. Evidence reviewed by Amnesty showed security forces positioned in streets and on rooftops firing rifles and shotguns loaded with metal pellets. The organization reported repeated fire toward largely peaceful protesters and bystanders, including shots striking heads and torsos. Its Amnesty investigation of the January killings describes January as the deadliest period of repression in decades of its Iran research. Human Rights Watch evidence of mass killings similarly concluded that coordinated security-force action after 8 January produced large-scale killings across the country.

Identified forces in the verified record include the IRGC, Basij battalions, police units known as FARAJA and plain-clothes agents. Witness and video evidence described firing from elevated positions, pursuit into residential areas and pressure on medical care. The United Nations special rapporteur told Reuters that protesters were reportedly detained in hospitals and that some families were asked for payments of $5,000 to $7,000 to retrieve relatives’ bodies. Tens of thousands were reported detained. Later proceedings and executions extended the repression beyond the nights of street violence.

The death toll cannot responsibly be expressed as one certain number. Iran’s first public accounting said 3,117 people died and grouped 2,427 civilians and security personnel together while attributing many deaths to “terrorists.” An Iranian official separately told Reuters that at least 5,000 people, including roughly 500 security personnel, had died. By early February, the U.S.-based Human Rights Activists News Agency reported at least 6,221 deaths: 5,858 protesters, 100 children, 49 non-protesting civilians and 214 government-affiliated personnel. The Associated Press casualty account reported that breakdown while stressing the continuing blackout. Still higher estimates circulated, but restricted access, missing people, duplicate reports and differing definitions prevented verification. The defensible conclusion is that thousands were killed and that the final total remained unresolved.

The blackout was not background scenery. It interrupted coordination between cities, slowed the transfer of videos, isolated hospitals and families, and made casualty enumeration dependent on fragments carried out by telephone, satellite access, witnesses and diaspora networks. It also gave the authorities room to frame those killed as violent foreign-backed actors while independent investigators could not enter freely. Communication began returning in phases after 18 January, reaching only a partial and unstable baseline by 27 January. Iran entered the February war with the protest blackout—and the killings it concealed—still shaping public fear and state security decisions.

The foreign-fighter reports: what the evidence does and does not establish

As the killing intensified, reports emerged that the IRGC had called on forces from Iran-aligned Iraqi organizations. Iran International first reported approximately 800 arrivals connected to Kataib Hezbollah, Harakat al-Nujaba, Kataib Sayyid al-Shuhada and the Badr Organization. On 16 January, CNN cited an unnamed Iraqi security source who put the figure near 5,000 crossing through al-Sheeb and Zurbatiya, while an unnamed European military source described hundreds entering under the cover of religious pilgrimage. CNN reported an assessment placing some fighters in sensitive areas including Hamedan. The CNN report on Iraqi militia deployments is the strongest mainstream account located, but its decisive sources were anonymous.

Those reports are plausible in organizational context. The IRGC Quds Force has long relationships with Iraqi armed factions, Lebanon’s Hezbollah, the Afghan Fatemiyoun and Pakistani Zainabiyoun. Moving aligned personnel across the Iraqi border is physically possible, and foreign units can offer loyalty when a government doubts whether domestic personnel will fire on neighbors. Plausibility, however, is not confirmation of a specific deployment or act.

The independently verified human-rights investigations reviewed for this resource identify IRGC, Basij, FARAJA and plain-clothes Iranian security personnel as perpetrators. They do not independently establish that thousands of foreign fighters entered Iran, nor do they assign a verified killing to a named Iraqi, Afghan, Pakistani or Lebanese unit. A contemporaneous Iranian outlet denied the allegation; Iranian authorities did not provide transparent deployment records. The large difference between estimates—roughly 800 and nearly 5,000—also signals uncertainty rather than precision.

“Mercenary” should not be used as a synonym for foreign militia member. It has a narrow and contested legal definition involving recruitment, motivation, nationality, residence, membership and compensation. The public record does not establish those elements for each alleged fighter. The accurate formulation is: security sources reported that Iran-aligned Iraqi militia fighters entered Iran to assist the crackdown; the scale, command arrangements and participation in particular killings remain unverified in the public evidence reviewed. Claims about Fatemiyoun, Zainabiyoun or Hezbollah participation require additional corroboration.

A tiered wartime internet emerges

During the war, state-affiliated outlets published lists of services available through the NIN: domestic news, search, maps, messaging, government portals, entertainment and practical services. Filterwatch documented both service-level whitelisting and user-level whitelisting. Selected officials, journalists, professions and institutions retained broader access through “white SIM cards” or approved locations while most people could not reach the same network.

The result was an information hierarchy. Authorities and aligned voices could speak outward while citizens had limited ability to verify, answer or document. Internet Society reporting based on interviews described connectivity as layered, unstable and sometimes monetized through scarce gateways. This was not universal, equal restoration; location, operator, profession, institutional status and payment could shape access.

The censorship machine therefore became part of information warfare. It reduced potential leakage useful for cyber-enabled targeting, but also limited warnings, family contact, independent casualty documentation and economic activity. Security purpose and population-wide harm existed together; acknowledging one does not prove the necessity or proportionality of the other.

How the system itself began to fail

By mid-March, the remaining network suffered additional collapses. Kentik measured drops inside the already tiny residual traffic on 2, 5 and 15 March. Routes belonging to Islamic Republic of Iran Broadcasting disappeared for part of 1–2 March. On 12 March, routing instability at the Telecommunication Infrastructure Company coincided with a brief restoration, suggesting that a failure or change may temporarily have removed a block. On 15 March, AP reported that a deeper collapse interrupted even semiofficial media accounts.

Filterwatch reported outages involving domestic providers and data centers, followed by cascading failures in the NIN that affected fiber and VDSL users and services such as ride-hailing and state news. Accounts of cause conflicted: reports mentioned power or shrapnel damage, domestic technical failure, defensive disconnection and infrastructure changes. No single explanation is established for every outage.

This is how the censorship machine was disrupted: not by a verified strike on one master building, but through the collision of deliberate restriction, concentrated control, unstable infrastructure, power and data-center failures, operator disconnection and wartime damage. The architecture could isolate the population, yet the same concentration and interdependence reduced graceful failure when its domestic components came under stress.

Eighty-seven days later: reconnection without a return

On 26 May, 87 days after the wartime shutdown began, Cloudflare saw a marked increase in traffic and DNS queries. At the peak, traffic reached only about 40 percent of the highest level observed earlier in 2026, and 91.6 percent of measured HTTP requests originated in Tehran. AP reported connectivity estimates around 86 percent while Kentik measured traffic around 40 percent—different metrics describing different parts of recovery, not a contradiction.

People returned to slow, filtered and uneven service. The Associated Press restoration report recorded lost online livelihoods, continued platform restrictions and fear that access could vanish again. The Cloudflare measurement record shows why “internet restored” was too simple: volume, geography, DNS activity and usable services recovered at different rates.

The Human Rights Watch wartime assessment emphasizes risks to people seeking safety information, medical assistance and family contact. In the Iran–United States cyber conflict, connectivity was simultaneously a defensive concern, intelligence surface, instrument of domestic control and civilian lifeline. The lesson is not that censorship failed or succeeded. It is that a system built to control information could impose extraordinary isolation, then expose its own society and state services to cascading failure. Any assessment must include civilian harm and reverberating effects alongside military claims.

Frequently asked questions

What is Iran’s National Information Network?

It is a domestically managed IP network containing Iranian connectivity, data centers, platforms, government services, messaging, search, media, and approved content. It can keep selected domestic services available while authorities restrict access to the global internet.

Does Iran control the internet through one kill-switch building?

No. Control is distributed across international gateways, the state-controlled Telecommunication Infrastructure Company, mobile and fixed operators, filtering systems, domestic hosting, identity and subscriber controls, platform rules, and security institutions.

Was Iran’s censorship system destroyed in the 2026 war?

No reliable evidence shows that one attack destroyed it. Authorities successfully imposed a prolonged international blackout. Later outages also affected domestic networks and data centers, revealing fragility, but reporting did not establish one cause for every failure.

How long did the February 2026 shutdown last?

Cloudflare observed traffic fall below one percent on 28 February. A marked partial restoration began on 26 May, 87 days later, but traffic and access remained well below pre-shutdown conditions and unevenly distributed.