Strategic Summary
Between Esfand 1404 and Farvardin 1405 (February to April 2026), the “internet shutdown” in Iran was not a simple blackout measure; it was a multi-layered security-technical operation designed to manage the succession at “Pasteur” and control evidence, time, and perception. According to traffic monitoring data and human rights accounts, the structure of the “Stealth Blackout,” by maintaining a superficial presence at the routing layer (especially IPv4) while systematically annihilating public connectivity, facilitated a “selective internet” for government agents and propaganda networks. Simultaneously, the “white SIM/access” mechanism and “Internet Pro” packages transformed global access into a purchasable and trackable privilege. By eliminating the public voice from the evidence-generation cycle, it completed the “media pincer”: the internal jaw applying disconnection and DPI-based filtering alongside whitelisting; the external jaw executing narrative laundering through expatriate intermediaries and injecting it into the mainstream media. This architecture, beyond widespread human rights violations, constitutes a ready case for targeted Magnitsky sanctions against the commanders of digital repression, operator executives, and DPI/LI technology suppliers.[1]
Body: Five Layers of Kinetic Analysis of the “Media Pincer”
The chronological context of this report is the “Pasteur succession crisis” amidst war and communication blackouts: Following the killing of Ali Khamenei[2] in the February 28 attack, a temporary transfer of power was announced with the formation of a three-member council, and subsequently, on March 8, Mojtaba Khamenei[3] was introduced by the Assembly of Experts[4] as the new Supreme Leader.[5] On March 5, reports emerged of heavy strikes near the “Pasteur government complex” alongside the release of images/videos of underground infrastructure attributed to the leadership.[6] During this same period, an “international blackout” was immediately enforced following February 28 and stretched into consecutive weeks until late March; such that reports speak of “narrative building restricted to whitelisted accounts.”[1]
Technical Autopsy of the Repression: The Architecture of Digital Apartheid
Technical documentation indicates that the 2025–2026 (1404-1405) model of “physically disconnecting Iran’s internet from the world” was not done in the 2019 (1398) style (by dropping BGP at the national level), but was rather a “service/user-based disconnection” that maintained the facade of connectivity at the routing layer. Traffic analysis by Kentik[7] specifies that the post-February 28 blackout began in the early hours of the attacks, with “most traffic” drying up around 07:06 UTC, noting the key detail that IPv4 routes in BGP largely remained intact; meaning “the country is still connected in terms of routing, but the people are disconnected from the world.”[1] This is precisely the component that enables the “granting of selective access”: when BGP announcements are preserved, control can be enforced at border bottlenecks/national gateways via gating policies and DPI, rather than through the complete destruction of routes.[1]
In the technical report by Miaan Group[1] (alongside ASL19 and IODA) regarding the 2025 “Stealth Blackout”—which is evaluated as the mature version of this very architecture—the key components of the operation include: DNS poisoning, whitelisting protocols/services to restrict them to domestic platforms, and the aggressive use of DPI to filter and block the traffic of circumvention tools; all without dropping BGP.[4] The same report asserts that such layering creates an “illusion of normal connectivity for the outside observer” while simultaneously collapsing the actual connection of citizens to the global internet.[4]
At the executive level, mobile operators in this model play the role of a “security contractor,” rather than merely a service provider: the government has explicitly stated that the decision to cut off the internet lies with security institutions and the government is incapable of overriding it.[8] This statement, alongside the technical evidence of preserving routing while dropping traffic, leads to an operational conclusion: the operator/regulator must enforce “allow/deny policies” in near real-time at the core network level and at national borders.
The center of gravity of “Digital Apartheid” in this case is the transformation of global access into a “privilege”: reports speak of “white SIM cards” offering VPN-free access to filtered platforms as a component of the “class-based internet.”[7] Simultaneously, field reports regarding the rollout of “Simcard Pro/Internet Pro” indicate that “international” access is being sold with an activation fee of over 2 million Tomans and multi-fold tariffs per gigabyte, even claiming to feature an “international IP” and stability during widespread blackouts—meaning the existence of a reliable access channel reserved for specific groups.[3] A report by Radio Free Europe/Radio Liberty[9] also characterizes the “white SIM” as “unrestricted” access within the framework of a class-based internet.[7]
Regarding the technical mechanism of “prioritization” and “bypassing filtering,” one must be precise: claims of “premium QoS” or “DPI bypass” cannot be conclusively proven without access to the operators’ internal configurations. However, from a network engineering perspective, the necessary tools to create such a divide exist within standard architecture: under the PCC framework, “policy control” can include QoS control and gating control, with QCI defined as the reference for forwarding behavior—meaning the operator can apply policy-driven, differentiated routing paths and service qualities for specific subscribers/groups.[9] Therefore, the existence of “stable access for a specific group” in the midst of a general blackout is consistent with known patterns of gating and QoS control; especially when BGP IPv4 is maintained and control is executed at the national gateway/operator core.[1]
The actionable focal point for future prosecution is the “digital footprint.” Contrary to popular parlance, the main issue in mobile networks is not the “MAC Address”; forensic-technical identifiers at this layer include IMSI/IMEI, Call Detail Records (CDR), time/location of connection (Cell-ID/TA), and service-level logs. A report by The Citizen Lab[4] shows that the Communications Regulatory Authority (CRA)[10], using “Legal Intercept” provisions, has sought direct access to retrieve user data and alter services, monitor historical voice/SMS/data usage, and uniformly enforce “allow/block/downgrade/deny service” policies; it also points to integration with billing systems and CDR extraction.[11] This level of control generates sufficient data for attribution and reconstructing the chain of decision-making and execution—provided that in the future, the preservation of evidence and the chain of custody are guaranteed by independent/judicial bodies.[11]
The Golden 72-Hour Doctrine: The Weaponization of Time and Cognitive Gaslighting
This case must be read with a guiding premise: the regime’s goal is not the “permanent concealment of truth”; the goal is the “capture of the initial time window”—the window during which the initial narrative is formed and the cost of international response is determined. Cognitive science supports this proposition: the “continued influence effect of misinformation” demonstrates that even after correction, false information can persist in reasoning.[12] Furthermore, the “illusory truth effect from repetition” shows that prior exposure to a statement—even if fabricated—can increase the perception of its accuracy.[13]
During the March 2026 succession crisis, the regime combined this knowledge with network engineering: the international blackout disrupts the citizen evidence generation and dissemination cycle at a critical moment; whereas “whitelisted traffic” and “white access” allow only selected actors to produce messages and imagery.[1] This mechanism creates a “deliberate delay” in the discovery of reality: when the domestic society is deprived of the widespread and simultaneous transmission of evidence, the capacity to detect patterns of killings/arrests/mass violations, as well as the capacity for swift reaction by international bodies, becomes paralyzed. Reports by Human Rights Watch[1] and Amnesty International[1] regarding the 2026 blackouts explicitly point to their function of “concealing abuses and escalating risks for civilians.”[14]
This “72-Hour Doctrine” in the Pasteur arena had another component: the “artificial production of political continuity.” A report by The Wall Street Journal[15] states that following the appointment of the new Supreme Leader, the lack of public presence and the absence of a verifiable voice were replaced with generated/manipulated imagery and voice-overs in state media.[15] In a disconnected environment, this artificial substitution—especially in the first 72 hours—is not “information dissemination,” but rather a “damage control operation”: managing uncertainty by generating fabricated signals of stability.
To this apparatus, one must add the “criminalization of connection attempts.” Technical and media reports have spoken of the dispatch of warning SMS messages (under sender names such as POLICE), threatening line blockages and legal prosecution for “repeated attempts to connect to the international internet.”[16] This measure serves a dual function simultaneously: (1) increasing the cost of communicative action and (2) generating judicial/security data out of the “behavior of attempting connection” for subsequent case-building.
The News Laundering Ecosystem: From Domestic Production to Transnational Packaging
The “media pincer” is completed when the second jaw operates beyond the borders. Specialized literature describes this phenomenon as “Information Laundering”: a process through which content from a problematic origin, via intermediaries, appears as “legitimate information” in mainstream media.[17] In this process, the added value of the intermediary is not “verification”; it is rendering the narrative “consumable” for policymakers and editors—using pseudo-academic language, untraceable sources, and fabricated modeling.
In the Iran case of March 2026, the blackout and whitelisting render “raw data” scarce, thereby creating a market for “alternative narratives”: only those with white access or those generating traffic on whitelisted networks can deliver high-volume output.[10] This scarcity elevates the likelihood of forming a classic laundering cycle: coordinated domestic outputs → republication by expatriate figures under the guise of “experts/analysts” → quotation by think tanks and packaging in the form of policy memos → consumption by mainstream media as “independent analysis.”[18]
For the Western policymaker, the issue is not merely an “analytical error”; it is a “legal risk.” In the United States, the Department of Justice[10] explains that the FARA law requires the registration and disclosure of agency/lobbying activities on behalf of a “foreign principal.”[19] There is also a precedent for criminal enforcement: the DOJ indicted a writer/political scientist in one case for “acting as an unregistered agent of the Government of Iran.”[20] This report, without naming specific individuals or institutions, provides a legal benchmark: any expatriate actor/organization that consciously and coordinately produces/distributes “informational materials” for political influence on behalf of a foreign government, while concealing a financial/command relationship, faces the risk of disclosure regulations and prosecution—especially when the product effectively acts as a “cover for repression” and a “distorter of human rights responses.”[21]
The Political Economy of Darkness: Monopoly, Rent, and Supply Chain Complicity
A multi-week blackout is not merely a “security cost”; it is a “political business model.” Evidence indicates that amidst the blackout, global access was offered as a “privilege with discriminatory pricing”: both Filterwatch’s technical report and an IranWire report discuss “Internet Pro/Simcard Pro,” featuring an activation fee of over 2 million Tomans, official identity verification, and multi-fold tariffs per gigabyte for access to filtered platforms.[16] This mechanism simultaneously achieves two objectives: (1) monetizing the “denial of access” and (2) guaranteeing traceability for users “authorized” to access the global internet.[16]
On the other side of the market, chronic filtering creates a “structural demand” for VPNs, and this market can reach the billion-dollar level. Reports speak of claims by parliament members regarding a “VPN mafia” and the massive financial turnover of circumvention tool sellers, pointing to accusations that segments of the ruling establishment profit from the continuation of filtering.[22] The existence of “national/governmental VPNs” also has a precedent and has been described as a mechanism for granting controlled and monitorable access.[23] In this framework, blackouts and filtering are not an exception, but rather a “rent-generating tool”: the socialization of restriction, the privatization of privilege.
The forgotten yet decisive dimension is the supply chain. Human rights reports regarding the role of Chinese technology in Iran’s internet control infrastructure—including references to DPI and surveillance equipment—have raised the names of companies like Huawei and ZTE as suppliers or actors (despite claims of their exit from the Iranian market).[24] An ARTICLE 19 report also documents the institutional and policy framework for strengthening internet control through the Supreme Council of Cyberspace[11] and the expansive powers granted to the “Cyberspace Security/Filtering Command.”[25]
More importantly: Citizen Lab shows that within Iran’s “Legal Intercept” architecture, negotiations and the involvement of foreign companies (based on internal documents and correspondence) have taken place, even naming vendors based in Russia/the UK/Canada for components related to surveillance, DPI, accounting, and integration with the lawful interception system.[11] This means that the “tool of digital repression” is not purely a domestic product; it is a supply-chain product.
From a sanctions law perspective, this point is actionable. The Office of Foreign Assets Control[4], under the “Global Magnitsky” framework and based on Executive Order 13818[4], provides the capability to sanction individuals involved in “serious human rights abuse” or those providing “material/technological support” for it.[26] Human rights sanction regimes also exist at the European and British levels: the European Union[4] through Regulation (EU) 2020/1998 and the Government of the United Kingdom[5] via its Global Human Rights Sanctions guidance.[27] The legal message is clear: “Selling DPI/LI to a regime demonstrably committing repression” transfers the risk of targeted sanctions from the political level to the transactional level—and rightly so.
“Traitor” as a Kill-Switch: The Engineering of Hate and Disenfranchisement
The systematic use of the label “traitor” (and related labels such as “enemy agent/terrorist”) is not merely a linguistic political dispute; it is a legal-security mechanism for activating violence. In official post-crackdown narratives, protesters are introduced as “enemy agents,” and this rhetoric paves the way for severe punishments—including execution—through broad and elastic charges. In reports related to the 2026 crackdown, even under the shadow of the blackout, threats of lethal punishment and attributing protesters to “foreign enemies” have been prominently featured.[28]
At this level, the link between “word” and “action” is critical. International law prohibits “incitement to hatred” when it constitutes incitement to discrimination/hostility/violence (ICCPR, Article 20).[29] ARTICLE 19’s interpretation and policy standards also demonstrate that “incitement” is not just bad speech; when speech plays a practical role in producing violence or legitimizing it, it enters the realm of obligations and liabilities.[30]
International judicial precedent has also clarified the significance of “media” as an instrument of crime: in the ICTR “Media Case,” criminal responsibility for direct and public incitement to commit genocide/crimes was examined and penalized.[2] This report does not claim a mechanical analogy between Iran and Rwanda; however, it establishes a legal principle: “media/propaganda” can serve as the actus reus (material element) of a crime, rather than just a political fringe.
In the context of Iran in March 2026, the term “traitor” acts as a “Kill-Switch” because it intertwines with the digital blackout and the architecture of interception/service control: when the state can simultaneously enforce “allowing/denying communication,” “logging micro-communicative behavior,” and “prosecuting connection attempts,” labeling turns into a tool for case-building, mass arrests, and elimination.[11] Moreover, the pattern of airing “forced confessions” on state media as a tool to justify prosecution and execution—a practice with a documented history—completes the function of this very switch: obliterating the right to a fair trial by substituting it with a media spectacle.[31]
Accountability Outlook: An Operational Map for Responsibility and Targeted Sanctions
This section is not a political recommendation, but an “evidence-based executive demand.” The controlled blackout of February-April 2026 is an attributable technical crime because (a) it is executed at the bottleneck level, (b) it is observable through independent traffic data, and (c) it generates an operational digital footprint.[1]
- Targeted Magnitsky Sanctions against the Architects of the Blackout and Class-Based Internet: Focus on senior executives of operators and regulatory/security bodies who (1) issued or communicated the disconnection orders, (2) designed or operationalized the whitelist/Internet Pro policies, or (3) played a role in the “deliberate deprivation of communication” during the crackdown and conflict. The legal basis for sanctions concerning “material/technological support” for serious human rights abuse is explicitly outlined in EO 13818.[26]
- Sanctioning and Restricting the DPI/LI Supply Chain and Surveillance Infrastructure: Any foreign company that, either directly or through intermediaries, has provided DPI, interception/service control systems, or border equipment usable for repression must be subjected to US/EU/UK sanctions packages. The data from ARTICLE 19 and Citizen Lab regarding the role of foreign technology and vendors serve as the starting point for financial-contractual investigations.[24]
- Action against the Rentier Economy of Filtering and the Official/Unofficial VPN Market: The “Internet Pro” and “Whitelist” models must be documented as “structural discrimination in access to information” and the “monetization of repression,” and should be incorporated into sanction dossiers.[3]
- Severing Resources and Legitimacy from Expatriate Information Laundering Networks: The standard must be “financial transparency and the disclosure of relationships with foreign principals.” If expatriate actors participate in the narrative laundering cycle, legal instruments such as FARA disclosure requirements and oversight models for think-tank funding become applicable.[19]
- Preservation and Standardization of Evidence for Future Judicial Avenues: International bodies must officially retain independent traffic data (IODA/Cloudflare/Kentik/NetBlocks) as “corroborating evidence” alongside testimonies and medical/arrest records, and they must extend and reinforce fact-finding missions and special rapporteurs to collect and safeguard evidence.[32]

List of References
- [1] Kentik: Internet and Airstrikes – Tracking Iran’s Extended Communication Blackout
- [2] ICRC Casebook: ICTR Media Case
- [3] IranWire: Filtered for Millions, Open for a Few – Iran’s Simcard Pro Goes on Sale
- [4] Miaan Group: Iran’s Stealth Blackout Report (PDF)
- [5] Reuters: Iran names Khamenei’s son Mojtaba new supreme leader
- [6] Iran International: News 202603095883
- [7] RFE/RL: Iran Internet Censorship, X, Twitter, VPN
- [8] Iran International: News 202601275988
- [9] ETSI: Deliverable TS 123 203 (PDF)
- [10] 8am Media: NetBlocks – Internet Disruption in Iran Enters its 25th Day
- [11] Citizen Lab: Uncovering Iran’s Mobile Legal Intercept System
- [12] PubMed: Study on Misinformation 26173286
- [13] PMC: Study on Truth Effect PMC6279465
- [14] Human Rights Watch: Iran Internet Shutdown Violates Rights
- [15] The Wall Street Journal: Where is Mojtaba Khamenei? AI and Voice-overs
- [16] Filter.Watch: Investigative Report – Iran’s Strategic Internet Shutdown
- [17] CIMA: Information Laundering and Globalized Media
- [18] CSIS: Exploring Information Laundering Ecosystem
- [19] US Department of Justice: FARA
- [20] US Department of Justice: Political Scientist Charged – Unregistered Agent
- [21] EveryCRSReport: IF11439
- [22] Iran International: News 202402192348
- [23] Center for Human Rights in Iran: National VPNs
- [24] The Guardian: China, Iran Technology and Internet Control
- [25] ARTICLE 19: Supreme Council of Cyberspace (PDF)
- [26] The American Presidency Project: Executive Order 13818
- [27] EUR-Lex: Regulation (EU) 2020/1998
- [28] Le Monde: Iran’s Bloody and Concealed Crackdown
- [29] OHCHR: International Covenant on Civil and Political Rights
- [30] ARTICLE 19: Policy on Prohibition to Incitement (PDF)
- [31] Iran International: News 202302247578
- [32] Human Rights Watch: Unprecedented Mass Killings in Iran
This page is also available in: فارسی
Georgian (Georgia)
עברית
العربية
