When a prayer app becomes a weapon: the psychological cyberwar at the heart of the Iran-US-Israel conflict
On February 28, 2026, the United States and Israel launched massive joint strikes against Iran. Since then, daily life for millions of Iranians has come down to sirens, explosions, power cuts and a near-total internet blackout, against a backdrop…

On February 28, 2026, the United States and Israel launched massive joint strikes against Iran. Since then, daily life for millions of Iranians has come down to sirens, explosions, power cuts and a near-total internet blackout.
Before getting into the technical analysis, one thought is unavoidable: this conflict strikes a people first. Millions of ordinary men and women, heirs to a thousand-year-old civilization, caught in a vise between an authoritarian regime and foreign bombardment. They chose neither one.
But beyond the airstrikes, a less visible front has opened with unprecedented brutality: that of cyberspace and cyberwar. And that is where this article lingers, because what happened that day on the phones of millions of Iranians deserves a closer look.
How was a prayer app turned into a weapon?
On February 28, as the first explosions rang out in Tehran, millions of Iranians simultaneously received an unexpected push notification on their phones.
The app in question is called BadeSaba Calendar. Downloaded more than five million times on Google Play, it is part of daily life for many Iranians: prayer times, the call to prayer (azan), orientation toward the qibla, religious calendar. In the middle of Ramadan, it is consulted several times a day. It is an intimate, familiar tool, tied to faith.
At 9:52 a.m. Tehran local time, the messages began. For nearly thirty minutes, several notifications in Persian followed one another, all under the same title: "Help is coming." Here are two excerpts, confirmed by screenshots analyzed by the Wall Street Journal and WIRED.


"The time for revenge has come. The regime's repressive forces will pay for their cruel acts against the innocent Iranian people. Those who join the defense of the Iranian nation will be granted amnesty and pardon."
"For the freedom of our Iranian brothers and sisters, a call to all oppressive forces: lay down your weapons or join the liberation forces. This is the only path that will let you save your lives. For a free Iran."
No official claim of responsibility followed. But the Israeli daily Maariv, citing a military official, quickly attributed the operation to Israel, and the technical markers leave little doubt: precise synchronization with the first strikes, persistence of the notifications despite filters, absence of any classic malware targeting users. Compromising an app's notification delivery system is not something you improvise on the morning of the strikes; it implies access to its infrastructure prepared weeks, if not months, in advance, through supply chain infiltration or credential theft. The cryptographer Bruce Schneier reads it the same way: for him, an operation triggered that fast is almost certainly of governmental origin, run from access that was already in place. Everything points to an operation planned long in advance, at a state level.
The choice of target is anything but random. As security researcher Hamid Kashfi notes, the users of a prayer app are "particularly religious people, with a higher probability of also being pro-regime and part of the military"; the app also requests access to location, a permission that "can be abused in many ways." Nobody merely hacked an app here: they targeted, with precision, the very population they wanted to make waver.
The message is clear: it is no longer only the servers or the infrastructure that are targeted. The mind is targeted directly, where trust runs deepest.
What did the hybrid war against Iran involve?
This hack did not happen in a vacuum. It was part of a wave of cyber operations synchronized with the airstrikes.
Iranian internet traffic fell to around 4% of its normal level within the first hours, according to NetBlocks data, before collapsing to less than 1% in some regions; the shutdown lasted more than sixty hours, a paralysis that Israeli sources presented as "the largest cyberattack in history." In parallel, targeted disruptions hit the Revolutionary Guards' communication networks, and several official news agency websites, including IRNA, were temporarily hijacked to display messages hostile to the regime. State television itself was not spared: at least two IRIB channels were hacked to broadcast recorded addresses by Donald Trump and Benjamin Netanyahu. In the maritime theater, more than 1,100 ships in the Gulf reported navigation failures within the twenty-four hours following the strikes, according to OCCRP: GPS jamming and disruption of the automatic identification system (AIS) placed their positions at false locations, sometimes over airports, nuclear power plants or points well inland, the classic signature of active GPS spoofing.
The goal is transparent: disorient the adversary on all fronts at once, disrupt the chain of command, and inject doubt directly into the population and the armed forces. This is cognitive warfare in action, synchronized with strikes that, according to several sources including Reuters and the Washington Post, are said to have decapitated part of the Iranian leadership. The American think tank CSIS describes this combination of cyber operations, electronic warfare and propaganda as the defining feature of the conflict.
The blackout did not close with the first strikes. According to NetBlocks, the cut in international connectivity ended up exceeding 1,056 cumulative hours of restrictions and stretched over several weeks, one of the longest blackouts ever imposed on the country. While the population stayed cut off from the world, regime figures and a handful of authorized accounts kept on publishing.
Nor did the digital front stay one-way. In the days and weeks that followed, actors linked to Iran claimed retaliation against American targets, including a major medical device manufacturer, while the US federal agency CISA warned of intrusions targeting the programmable logic controllers of critical infrastructure. The cognitive war opened on phones was compounded by a war of attrition on the networks, in both directions.
What is genuinely new compared with Stuxnet?
Let's be clear: offensive cyber operations are nothing new. Stuxnet, in 2010, showed that a computer worm could physically destroy centrifuges remotely. The "pager" operation in 2024 showed that an entire supply chain could be booby-trapped to set off coordinated explosions. And during the June 2025 confrontation, the pro-Israeli group Predatory Sparrow, reputedly linked to Israeli military intelligence, had already paralyzed Bank Sepah and struck the cryptocurrency exchange Nobitex.
But what happened with BadeSaba is of a different order. It is not physical sabotage, nor an attack on critical infrastructure, nor even a financial raid. It is the transformation of a daily ritual, prayer, into a vector of propaganda. It touches on a rare intimacy: faith, spiritual routine, the bond of trust between an individual and a tool used in a moment of reflection.
The specialist Lukasz Olejnik sums up the stakes: push notifications are "trusted by design," which makes notification infrastructure a very high-value target in wartime. He pushes the comparison further: a notification delivered to a smartphone is, in his view, a distribution channel "more effective than leaflets dropped from a plane." In other words, the weapon is not the code, it is trust itself. This use was in no way unforeseen: as early as 2024, in his book "Propaganda" (CRC Press), Olejnik described precisely this scenario, the hijacking of notification infrastructure as a vector for large-scale influence operations. From hypothetical risk to deployment on a real battlefield, it took less than two years.
For a soldier, a militiaman, or even a civilian already under the bombs, receiving such a message at the very moment of checking prayer times means watching doubt creep in where certainty once stood. This is psychological warfare in its purest form, and its potential effectiveness is formidable: to crack cohesion, amplify fear, destroy digital trust.
Calling a spade a spade
This kind of operation, however "impressive" it may be on a technical level, is by no means morally neutral. Things need to be named.
When a state hijacks a prayer app used by millions of civilians to spread propaganda in the middle of a bombardment, it is not merely a cyber feat. It is the exploitation of the intimate and religious space of civilian populations. It is turning a moment of reflection into a vector of manipulation.
You can analyze the technical sophistication without applauding the use made of it. You can acknowledge the cyber-kinetic integration capability of certain actors without concluding that the end justifies every means. The Iranian population, already caught between a repressive regime and foreign bombardment, did not need its tools of faith turned into a battlefield as well.
The risk is that this kind of operation becomes the norm. And that tomorrow, any state will grant itself the right to hijack any civilian app (health, messaging, education) to inject its propaganda in times of conflict. That an expert described this scenario two years before it happened does not make it any less serious; it only shows that the line was already falling.
How can you protect yourself from hijacked apps?
You might think this episode does not concern us directly. That would be a mistake. What happened in Iran exposes a vulnerability that touches us all: the blind trust we place in the apps of our daily lives.
How many of us actually check who develops the weather app we consult every morning? Who controls the server behind their alarm app, their sleep tracker, their password manager? Every app installed on a smartphone is a potential attack surface. Every push notification is a channel that someone, somewhere, could hijack.
The concrete lessons to draw: limit the number of installed apps to the strict minimum, check the permissions granted (why would a calendar app need access to your contacts or your location?), favor open-source apps when possible, and above all keep a critical mind toward any unexpected notification, even from a "trusted" source.
Cybersecurity is no longer a subject reserved for experts. It is a daily hygiene. And this Iranian episode is a brutal demonstration of it.
Behind the code, human lives
In the midst of these technical analyses, what matters most remains the people. In Tehran, Isfahan, Tabriz, families live under permanent tension. Young people see their digital space, their social ties, their access to information, their spirituality, turned into a minefield.
Cyberwar impresses strategists. It terrifies civilians. And that is no doubt where its most fearsome weapon lies.
May the Iranian people, at the heart of this hybrid era, draw from their historic resilience the strength to weather the storm. And may we all remember: behind every line of code, every hijacked notification, every strike, there are human beings who dream of peace.
Sources
- BadeSaba Calendar hack, content of the messages and screenshots analyzed: Wall Street Journal, February 28, 2026.
- Technical analysis, app permissions and expert quotes (Hamid Kashfi, Lukasz Olejnik): WIRED and The Register, March 2, 2026.
- Attribution to Israel (report by the daily Maariv citing a military official): Straight Arrow News.
- Reading of a government-run operation: Bruce Schneier, March 2026.
- Notifications "trusted by design" and scenario described as early as 2024 in "Propaganda" (CRC Press): Lukasz Olejnik.
- Compromise method (pre-existing access, supply chain): GBHackers.
- Hijacking of news agency websites, hacking of IRIB channels and GPS/AIS jamming: "Cyberwarfare during the 2026 Iran war", Wikipedia.
- GPS jamming and false positions of more than 1,100 ships in the Gulf: OCCRP and CNBC.
- Overview of the cyber, electronic and psychological campaign: CSIS.
- Iranian internet blackout (1 to 4% of normal levels, initial collapse of more than 60 hours): NetBlocks, via Wikipedia.
- Extension of the shutdown beyond 1,056 cumulative hours of restrictions according to NetBlocks: IranWire and CNBC.
- Joint strikes and presumed decapitation of the Iranian leadership: Reuters and Washington Post.
- June 2025 precedent, pro-Israeli group Predatory Sparrow against Bank Sepah and Nobitex: TechCrunch and CyberScoop.
- Cyber retaliation attributed to Iran-linked actors against American targets, including a major medical device manufacturer: TIME.
- Alert on intrusions targeting the programmable logic controllers of US critical infrastructure: CISA.
- Context of the hack and call for defection: Jerusalem Post.
Frequently asked questions
What is BadeSaba Calendar and how was it hacked?
It is an Iranian religious calendar app (prayer times, azan, qibla) downloaded more than five million times on Google Play. On February 28, 2026, at 9:52 a.m. Tehran time, it broadcast push notifications in Persian for nearly thirty minutes, calling on the regime's forces to lay down their arms or join the liberation forces. The attackers had compromised its notification delivery system, an access prepared well in advance.
Who is behind the hack of the Iranian prayer app?
No group or state has officially claimed the operation. The Israeli daily Maariv, citing a military official, attributed it to Israel, and both the Wall Street Journal and The Register point to Israeli operators. The cryptographer Bruce Schneier considers that the speed of execution almost certainly betrays a government operation run from access that was already in place.
How is this attack different from Stuxnet or the pager attack?
Stuxnet (2010) and the pager operation (2024) aimed at physical effects: destroying centrifuges or setting off coordinated explosions. The BadeSaba case sabotages no infrastructure: it turns a daily, intimate ritual, prayer, into a vector of psychological propaganda.
How extensive was the internet blackout in Iran?
According to NetBlocks data, Iranian internet traffic fell to around 4% of its normal level within the first hours, before collapsing to less than 1% in some regions. First estimated at more than sixty hours during the wave of strikes, the shutdown in fact went much further, exceeding 1,056 cumulative hours of restrictions according to NetBlocks, one of the longest blackouts in the country's history. It came alongside the hijacking of news agency websites and state television channels.
Can a push notification really be hijacked?
Yes. As researcher Lukasz Olejnik points out, push notifications are "trusted by design": the user opens them without suspicion. Olejnik had already described this hijacking in 2024 in his book "Propaganda": the scenario moved from theoretical risk to operational use in less than two years.
Why does this episode concern us outside Iran?
It exposes the blind trust we place in everyday apps: every installed app is an attack surface and every push notification a channel that can be hijacked. Such a practice could tomorrow extend to any civilian app (health, messaging, education).
How can you protect yourself from hijacked apps?
Limit the number of installed apps to the strict minimum, check the permissions granted (why would a calendar app ask for your contacts or your location?), favor open-source apps when possible, and keep a critical mind toward any unexpected notification, even from a source considered trustworthy.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
