VORANT. Threat Intelligence Sign in Get the full feed

Iran internet traffic drops during Israel conflict

medium vulnerability financial-servicesmediainfrastructure

JPCERT observed reduced traffic from Iran during June 2025 Israel-Iran conflict, likely due to government-imposed internet restrictions following cyber attacks on Iranian infrastructure.

JPCERT's TSUBAME sensor network detected significant fluctuations in network traffic originating from Iran between June 13-27, 2025, coinciding with military conflict between Israel and Iran. The number of unique Iranian IP addresses observed daily dropped from a baseline of 170-200 to as low as 20-100 during the peak conflict period. This reduction correlated with reported cyber attacks targeting Iran's state broadcaster, banks, and cryptocurrency exchanges around June 18, followed by Iranian government-imposed internet connectivity restrictions to mitigate attack impact.

The monitoring data showed that Israeli-origin traffic remained stable during the same period, suggesting the disruption was specific to Iranian networks. JPCERT's global sensor deployment revealed that April 2025 recorded the highest packet volumes both domestically in Japan and internationally, with gradual decreases in subsequent months. Across all sensor locations, ports 22/TCP, 23/TCP, 80/TCP, 443/TCP, and 8080/TCP consistently appeared in the top 10 most-scanned services, indicating widespread reconnaissance activity targeting common protocols globally.

This report demonstrates the value of geographically distributed threat monitoring infrastructure for detecting regional network disruptions and correlating them with geopolitical events. While no immediate threat alerts were issued for this quarter, the persistent scanning activity across multiple networks underscores the importance of continuous vigilance against reconnaissance operations.

Source reporting: https://blogs.jpcert.or.jp/en/2025/10/tsubame_overflow_2025-04-06.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free