Also available in Persian — نسخه فارسی EN فا
❓ Unknown

What Was the Internet Disruption Incident in Iran?

Jan 26, 2026 January 26, 2026 3 min read 📰 Radio Farda
📋 Key Takeaway

On April 6, 2018, the hacker group JHT attacked Iran's internet infrastructure, causing significant disruptions. The attack was preventable through timely software updates from Cisco, which were ignored by many users. This incident highlights the critical importance of maintaining updated software to prevent cyber vulnerabilities.

🔍 Quick Context Guide
💡 Bottom Line: The JHT cyber attack serves as a reminder of the critical importance of timely software updates to protect against cyber threats.

👥 Key Players

JHT MENTIONED
Hacker group
"JHT is significant as they represent a growing trend of cyber activism and hacking against state-sponsored cyber operations."
Iran's Minister of Communications and Information Technology MENTIONED
Government official
"This official's response to the attack reflects the Iranian government's stance on cybersecurity and its implications for national security."
Cisco MENTIONED
Technology company
"Cisco's software vulnerabilities were exploited in the attack, highlighting the importance of cybersecurity in technology infrastructure."

📰 What Happened

On April 6, 2018, the hacker group JHT launched a cyber attack that disrupted internet access in Iran and Russia by exploiting a known vulnerability in Cisco software. The attack was preventable, as the vulnerability had been publicly reported just days prior.

  • The attack was executed by resetting router settings to default and displaying a message to network administrators.
  • JHT claimed their motivation was to retaliate against state-sponsored hacking activities.

💡 Why It Matters

🇮🇷 For Iran: This incident underscores vulnerabilities in Iran's internet infrastructure and raises questions about the government's cybersecurity preparedness.
🌍 Regional: The attack highlights the ongoing cyber conflict in the region, particularly between state and non-state actors.
🌐 International: It demonstrates the potential for cyber attacks to disrupt national infrastructure and the need for international cooperation on cybersecurity.

📚 Background

Cybersecurity is a growing concern globally, with state-sponsored and independent hacking becoming increasingly common. This incident illustrates the vulnerabilities inherent in internet infrastructure.

Cybersecurity State-sponsored hacking
📡 Source: NEUTRAL
📊 Confidence: 70%
The article presents factual information about the cyber attack without evident bias, making it a reliable source for understanding the incident.

On April 6, 2018, a hacker group named JHT launched a cyber attack on the internet infrastructure in Iran and Russia, causing disruptions in internet access in both countries. In a message tweeted by Iran's Minister of Communications and Information Technology, the hackers mentioned their non-interference in their country's elections alongside the American flag. This attack, which could have been easily prevented by updating two Cisco software programs, attracted significant attention from various media outlets, both Persian and non-Persian, sparking discussions about its nature. This article addresses three important questions regarding this cyber attack. What was the cause of this attack? As mentioned above, Iran and other countries could have easily prevented this cyber attack by updating the Smart Install feature in two Cisco IOS Software and Cisco IOS XE programs. On March 27, 2018, Cisco, one of the largest producers and providers of hardware and software for internet infrastructure, reported a severe security vulnerability in its two software programs and urged all users to update them promptly. However, officials and various individuals in Iran and other countries using these two software programs did not take this warning seriously until the day of the cyber attack, which was April 7. How did this attack work? This security vulnerability essentially allowed the attacker to reset the router settings to default and display a desired message to the victim. In the attack carried out by the JHT group, the router's configuration file named startup-config was rewritten, and then the router was restarted. With this change, the hackers disrupted the network, which in this case was Iran's internet network, and displayed the message shown in the image above to the network administrators of the attacked networks. What was the hackers' motivation? Answering this question is quite difficult, but according to an interview conducted by the Motherboard website with the JHT hacking group, the hackers cited their main reason as being 'tired' of state-sponsored hackers attacking the U.S. and other countries. Additionally, JHT claimed that before launching the attack, they had examined and resolved the Cisco software issue in other countries such as the U.S., the U.K., and Canada, and then began their attack to ensure that only a few countries like Iran and Russia experienced disruptions in internet connectivity. What lessons can be learned from this attack? Only one important and fundamental lesson can be drawn from this attack: the continuous updating of various software and tools; so that whenever a new version of software is released, it should be updated without delay. To start, check all the software you are using right now to ensure they are up to date.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →