← Back to Blog
Packets in the Dark: VPNs, Scams and Digital Silence in Iran
Explore Iran’s 2026 internet blackout, where VPN black markets, satellite tunneling, and digital survival shaped a nation cut off from the world.
In early January 2026, Iran experienced one of the most extensive and technically advanced internet shutdowns ever recorded. Unlike earlier disruptions that targeted mobile data or specific regions, this event combined routing withdrawals, protocol interference, satellite jamming, and telecom service suspension into a coordinated, multi-layer blackout. What followed was not a momentary outage but a sustained, engineered isolation of an entire national network. Drawing on measurements from Cloudflare Radar, NetBlocks, IODA, and Filterwatch, this article traces the technical progression of the shutdown from early warning signs to its two-week persistence as of January 22, 2026. Early Warning Signals Before the Blackout The shutdown did not begin without notice. In the first days of January, traffic anomalies appeared across Iran’s network footprint. Cloudflare Radar detected intermittent slowdowns, unstable IPv6 routing behavior, and brief packet loss events. These disruptions coincided with growing protests that had begun in late December 2025. By January 5, overall traffic briefly rebounded and even exceeded baseline levels. These spikes were short-lived and misleading. At the same time, reports emerged of mobile data throttling, widespread VPN failures, and DNS interference. Some encrypted connections failed during Transport Layer Security handshakes, suggesting early protocol-level sabotage rather than simple congestion or filtering. These signs indicated preparation rather than malfunction. January 8: Coordinated Collapse of National Connectivity The full shutdown began on January 8, 2026, through a carefully sequenced technical operation. At 11:50 UTC, observers recorded a 98.5 percent reduction in Iran’s announced IPv6 address space. More than 48 million IPv6 /48 prefixes vanished from global routing tables, leaving only a fraction visible. Because modern mobile networks rely heavily on IPv6, this single action severely degraded mobile connectivity nationwide. Between 16:30 and 17:00 UTC, overall internet traffic dropped by nearly 90 percent. Major providers including MCI, Irancell, and Rightell simultaneously lost international reach. Techniques included cutting international gateways, poisoning DNS responses, and activating deep packet inspection systems to disrupt encrypted traffic. By 18:45 UTC, traffic fell to effectively zero. Unlike earlier shutdowns in 2019 or 2022, this blackout extended beyond mobile data to fixed-line broadband, datacenters, and parts of domestic infrastructure. Outages first appeared in Tehran and western regions before spreading nationwide.( Read More ) Deepening Isolation and Protocol Disruption From January 9 onward, connectivity hovered between one and three percent of normal levels. These traces were likely measurement artifacts or the result of whitelisted access for government and security entities. Domestic platforms such as Eitaa, Snapp, and Divar failed due to DNS hijacking and traffic blocks. Even some state-linked websites became intermittently unavailable, highlighting the breadth of the disruption. Unlike earlier shutdowns that relied on blunt disconnections, this event involved systematic interference with core internet protocols. DNS resolution failed across large portions of the network. TLS handshakes were disrupted mid-exchange. Routing paths were manipulated to allow only approved services. The result resembled a “barracks internet,” where connectivity existed only for selected entities under strict control.( Read More ) Satellite Internet Jamming and Physical Suppression As wire and cellular access collapsed, satellite internet briefly emerged as an alternative. Starlink terminals provided limited connectivity in some areas during the first days of the blackout. Technical reports indicated the deployment of advanced jamming systems targeting Ku-band frequencies used by Starlink. Packet loss ranged from 30 to 80 percent, rendering most connections unstable or unusable.( Read More ) At the same time, security forces carried out physical enforcement. Satellite dishes were confiscated during rooftop inspections and building raids. Possession or use of such equipment resulted in arrests and prosecution. These measures closed remaining communication paths both technically and physically.( Read More ) Partial Rollbacks and Intranet Expansion After January 12, limited changes appeared. Outgoing international calls were partially restored on January 13, allowing restricted contact with the diaspora. On January 17, SMS services returned nationwide after eight days offline. Mobile data and global internet access remained blocked. During this phase, Iran’s National Information Network was partially reactivated. Banking, health, and education services resumed on approved platforms. VPN services remained ineffective. Protocol-level blocking continued to defeat circumvention tools. Status at the Two-Week Mark By January 22, Cloudflare Radar confirmed that national traffic had remained near zero for fourteen consecutive days. Limited fixed-line access returned in parts of Tehran, mainly for institutional users. Mobile networks remained largely offline nationwide. Whitelisted IP ranges continued to function for officials and essential services. Satellite jamming persisted. Many Iranian websites were deindexed by global search engines due to prolonged inaccessibility. Government statements suggested unrestricted access might not return until March 2026. Black Markets for Temporary Access: Scammers, Exploits Telegram Channels As the blackout continued, an auction access market grew around the few points still online. Starlink-based VPN configurations began circulating on informal markets, priced anywhere from 1$ to 50$ per gigabyte of usage. These configurations typically relied on shared satellite backhaul, aggressive traffic compression, and strict bandwidth caps, making them expensive and unreliable but briefly functional. On the Wired and Cellular network, limited protocol leaks appeared. For short windows, DNS tunneling enabled partial access to Telegram on some networks. Although an estimated 98% of users remained offline, certain VPN tools such as Psiphon worked occasionally on limited parts of the network, most notably on MCI. These openings were inconsistent, short-lived, and often closed within hours as filtering rules were updated. Unexpectedly, access to Google services and ChatGPT briefly reappeared through specific ISPs, including Irancell. This allowed technically skilled users to identify reachable Cloudflare IP ranges and restore VPN configurations by proxying traffic through Cloudflare infrastructure. By leveraging Cloudflare’s proxy and TLS termination behavior, some activists were able to move traffic through domains that had not yet been blocked. However, these same conditions enabled widespread abuse. Scammers rapidly exploited Cloudflare-based tunneling setups, advertising paid access and reselling traffic routed through their own Cloudflare accounts. Users were charged between 1$ and 5$ per gigabyte for tunneled data, often without transparency or reliability. In many cases, services stopped functioning after payment or within hours, reflecting the absence of trust, verification, or enforcement in this improvised access market. As filtering tightened and Cloudflare ranges were progressively restricted, most of these methods ceased to function, reinforcing the overall effectiveness of the blackout. Datacenter Isolation and System Vulnerabilities Alongside user-level disruption, Iran-based datacenters were forced to operate in a constrained intranet environment. National traffic was limited to whitelisted IP ranges and internal DNS resolvers, effectively severing connections to external repositories, update servers, and cloud services. Virtual servers and hosts were unable to fetch critical updates, patches, or security packages, leaving the country-scale network exposed to newly discovered vulnerabilities and CVEs. Users reported that datacenters with servers located outside Iran either shut down those machines or removed them entirely to prevent internal access. Support channels from these providers often gave vague, unhelpful responses or avoided engagement entirely. The result was a critical operational gap: enterprises and individuals could not maintain system security or continuity, creating a persistent risk of exploitation while the blackout remained in effect. This phase highlights a secondary, cascading consequence of large-scale network isolation: beyond connectivity loss, national IT infrastructure becomes brittle and susceptible to attack. Even domestic services hosted within Iran faced operational instability, as their dependencies on external updates and cloud-hosted components were disrupted. The combination of whitelisting, DNS isolation, and inaccessible repositories transformed Iran’s datacenter ecosystem into a partially functional but high-risk environment. Closing Thought What this blackout ultimately reveals is not just how a network can be shut down, but what happens when a society is forced to operate in the dark. Connectivity became rare, fragile, and expensive. Trust broke down. Technical skill turned into survival currency. Infrastructure designed for resilience quietly decayed as updates stopped, patches failed, and isolation compounded risk. For a brief moment, packets slipped through cracks. DNS tunnels whispered. Proxies blinked alive. Then they disappeared. What remained was a reminder that the internet is no longer just a utility. It is a dependency. When it is removed by design, the effects ripple far beyond access, reaching security, economics, and human behavior. This was not a broken network. It was a controlled one. And that distinction should unsettle anyone who builds, studies, or relies on global connectivity.