The bombs that fell on Tehran on February 28, 2026, did not arrive without warning, at least, not for the people who planned them. By the time the first US and Israeli strikes hit their targets, Israeli intelligence services had spent years building a granular, AI-processed picture of the Iranian capital so detailed that, as one official told the Financial Times, they knew Tehran the way they know Jerusalem.
That picture was assembled not only through satellites, but through something far more intimate: the city’s own surveillance infrastructure, turned against it. Traffic cameras on every major street. Mobile phone networks threading through government compounds. And on the morning of the strikes, a prayer app trusted by five million Iranians was turned into a psychological warfare delivery system, pushing military surrender messages to lock screens across the country as the first explosions shook the city.
This is the story mainstream news is not telling. The casualty counts are being covered everywhere. What is not being covered is how the information war was won long before the kinetic war began, and what that tells us about the nature of
AI-assisted conflict going forward.
The Cameras: Years of Access, Streaming to Tel Aviv
A Financial Times investigation, confirmed across multiple outlets citing current and former Israeli intelligence officials, reveals the full scope of what may be the most ambitious peacetime intelligence penetration of an adversary’s civilian infrastructure ever reported.
Israeli services, primarily Unit 8200, the signals intelligence arm of the Israel Defence Forces, and Mossad, Israel’s foreign intelligence service, obtained long-term remote access to Tehran’s municipal traffic camera network. Not a handful of cameras. Not a targeted installation. According to sources familiar with the operation, nearly all traffic cameras in Tehran were compromised, with encrypted footage streamed continuously to servers in Israel for years before the February 2026 strikes.
“Nearly all traffic cameras in Tehran were compromised for years, with encrypted footage streamed to servers in Tel Aviv. We knew Tehran like we know Jerusalem.”
The Camera That Changed Everything
Among the thousands of feeds streaming to Israeli servers, one proved decisive. A camera positioned near the Pasteur Street compound, the complex in central Tehran that houses the offices of the Supreme Leader, the presidency, and the national security apparatus, gave analysts something no satellite pass could provide: consistent, ground-level visibility of who came and went, and where they parked.
From vehicle identification alone, Israeli analysts mapped the home addresses of Khamenei’s personal security team, their daily schedules, their protection assignments, and the internal layout of the compound’s security perimeter. Combined with penetrated mobile phone infrastructure, which gave access to call metadata, movement patterns, and communication timing, the intelligence picture of Iran’s leadership became, in the words of officials, comprehensive.
📍 The Pasteur Street Operation — Key Intelligence Gathered
- Physical layout of the Supreme Leader’s compound security perimeter
- Home addresses of Khamenei’s personal protection detail
- Daily routines, shift patterns and vehicle assignments of the security team
- Patterns of life for senior officials when they arrived, departed, and who they met.
- Real-time confirmation on strike morning that Khamenei was physically present
- Cell tower disruption: ~12 towers near the compound were deliberately disabled to prevent security coordination
On the Morning of the Strike
The camera and mobile network intelligence were not just historical. On the morning of February 28, Israeli and US intelligence services used the live feeds to confirm in real time that Khamenei and key senior officials were present at the Pasteur compound before the strike order was given. Simultaneously, cellular service from approximately twelve towers near the compound was deliberately disrupted, making phones appear busy and preventing the security detail from receiving or coordinating any response to the incoming operation.
The disruption of mobile infrastructure was not collateral. It was a precision operation designed to create a window of communication blindness at the exact moment it was needed most.
The AI Layer: Turning a Flood of Data Into a Target
City-wide camera surveillance at scale generates volumes of video data that no human analyst team can process in a useful time. This is where artificial intelligence transformed the operation from a passive collection effort into an active targeting system.
Israeli services reportedly deployed AI tools and machine learning algorithms to process what sources describe as billions of data points collected from cameras and penetrated mobile networks. The analytical approach combined two well-established AI capabilities:
- Pattern-of-life analysis: Deep learning models trained to recognise vehicles, track movement trajectories, and flag deviations from established routines, the same class of technology used in commercial traffic management systems, repurposed for intelligence targeting
- Social network analysis: Graph-based AI models that map relationships between individuals based on co-location, communication timing and movement correlation, enabling analysts to identify decision-making nodes and predict where key figures would be at specific times
The result was not just a list of targets. It was a living, continuously updated model of how Iran’s leadership moved through its own capital city, a model that could be queried in near-real time to answer the single most operationally critical question: Is the target there right now?
Israeli analysts used social network analysis on billions of data points to identify decision-making nodes and new targets within Iran’s leadership network. AI turned years of surveillance into
a precision strike map.“
How Tehran’s Own AI Systems Enabled the Hack
There is a deep irony in the technical architecture of this operation. Iran had invested heavily in its own AI-enhanced surveillance infrastructure, installing tens of thousands of cameras across Tehran equipped with license plate recognition systems, facial detection capabilities, and centralised data processing, primarily for domestic political surveillance, including enforcement of hijab laws and monitoring of dissidents.
Those centralised back-end servers, the very systems that made Iran’s surveillance apparatus powerful, also created a single point of compromise. An adversary who gained access to the central infrastructure could access every camera feed it connected to, rather than needing to compromise individual devices. Iran’s investment in surveillance technology became the vulnerability that enabled a foreign power to watch the city through Iranian eyes.
|
Capability
|
Iran’s Intended Use
|
How Israel Exploited It
|
| Traffic cameras (city-wide) |
Traffic management + political surveillance |
Real-time leadership movement tracking |
| License plate recognition AI |
Tracking dissidents and protesters |
Identifying security team vehicles, mapping home addresses |
| Centralized server architecture |
Unified data management |
Single point of compromise — all feeds accessible from one breach |
| Mobile network infrastructure |
Domestic communications |
Call metadata, location data, movement pattern extraction |
| Facial detection systems |
Public order enforcement |
Potential confirmation of individual identities at compound |
The Technical Vector: What We Know and Don’t Know
Public reporting does not confirm the exact method used to gain initial access to Tehran’s camera network. Three vectors are technically plausible based on the profile of the operation:
- Supply chain compromise: Camera hardware or firmware from a vendor with access to both civilian and government networks, similar in concept to the Stuxnet approach against industrial controllers
- Network credential theft: Exploitation of Iran’s municipal IT systems or ISP infrastructure to obtain administrative access to camera management platforms
- Long-term persistent access: Initial breach followed by years of quiet, low-signature access maintenance consistent with the multi-year timeline described by sources
No forensic report from a neutral cybersecurity firm has been publicly released. The technical implementation must therefore be treated as expert inference rather than confirmed fact, but the operational outcome is well-corroborated across multiple independent outlets.
The Prayer App: BadeSaba and the Psychological Strike
The traffic camera operation gave Israel the intelligence to target Khamenei with precision. BadeSaba gave an unknown actor, likely Israeli or US-coordinated, the ability to reach every phone in Iran at the exact moment the bombs fell.
What BadeSaba Is
BadeSaba is an Islamic calendar and prayer-time application, one of the most trusted apps in Iran, with over five million downloads on Google Play alone and additional installs through sideloading. It displays the Hijri calendar, reminds users of the five daily prayers, and pushes the adhan, the call to prayer, as a notification to the phone’s lock screen.
For millions of Iranian users, a notification from BadeSaba is as familiar and trusted as an alarm clock. It is not an app that users scrutinise. It is an app they rely on.
📱 BadeSaba — Profile
Type: Islamic calendar, prayer times and adhan notification app
Install base: 5 million+ Google Play downloads + sideloaded installs nationwide
Trust level: Embedded in daily religious routine, lock-screen notification access
Why targeted: Maximum reach + maximum trust + pre-existing notification permissions
Technical access needed: Server-side backend compromise, not device-level malware
What Happened at 9:52 a.m. Tehran Time
As the first explosions were being reported across Tehran on the morning of February 28, 2026, BadeSaba users began receiving push notifications. The first message arrived at approximately 9:52 a.m. Tehran time concurrent with or minutes after the initial strikes. Over the following thirty minutes,
a sequence of Persian-language messages arrived:
- Message 1: “Help has arrived” / “Help is on the way”
- Messages 2–4: Urged Iranian military personnel and IRGC members to surrender their weapons and stand down
- Amnesty offer: Promised protection and amnesty to anyone joining “the forces of liberation”
- Call to action: Invited citizens to help form a “People’s Army” to defend “Iranian brothers”
- IRGC-specific: Provided apparent surrender procedures for rank-and-file Revolutionary Guard members
- Coordination: Designated apparent safe gathering areas for protesters and defectors
CBS News, citing the Wall Street Journal, reported that the messages closely echoed President Trump’s televised address in the hours before the strikes, in which he urged Iranian security forces to lay down their arms. The alignment between the broadcast messaging and the in-app content suggests a single coordinated information operation running across multiple channels simultaneously.
“A prayer app trusted by five million Iranians was turned into a psychological warfare delivery system. The call to prayer became a call to surrender.”
The Technical Operation
Security researchers at Flashpoint and analysts quoted by Wired and TechCrunch confirmed that the attack targeted BadeSaba’s backend notification infrastructure, not individual user devices. This distinction matters. No malware was installed on phones. No individual device was compromised. The attack was on the server that sends notifications to all users, a single point of control for five million simultaneous messages.
Security researcher Lukasz Olejnik assessed the operation as requiring weeks or months of pre-positioned backend access, characterising it as a state-level psychological operation executed with a precision and timing that rules out opportunistic cybercrime. The payload was almost certainly staged well in advance, triggered at a pre-set moment aligned with the kinetic operation.
Iran’s Response: Internet Blackout
Iranian authorities responded to the combined kinetic and cyber strikes with a near-total internet shutdown. Network monitoring firms recorded two sharp drops in Iranian internet connectivity on February 28, the first around 07:06 GMT and the second around 11:47 GMT, leaving traffic at approximately 4% of normal levels. Calls, SMS and VPN services were disrupted.
The blackout was the Iranian government’s most immediate tool for limiting panic, controlling the narrative, and disrupting further cyber operations. It also confirms that authorities understood they were facing a coordinated information operation, not merely a kinetic strike.
The Lineage: From Stuxnet to AI-Assisted Warfare
The Tehran camera operation and the BadeSaba hack do not exist in isolation. They are the latest chapter in a long-running Israeli and allied campaign of cyber and intelligence operations against Iranian infrastructure, a campaign that has been escalating in sophistication for over fifteen years.
|
Operation
|
Year
|
Target
|
Method
|
AI Role
|
| Stuxnet |
~2010 |
Natanz uranium centrifuges |
Industrial control system malware via supply chain |
None — pre-AI era |
| Port/fuel attacks |
2020–2021 |
Iranian ports and fuel distribution |
Network intrusion, system disruption |
Limited — automated triggers |
| Assassination operations |
2020–2022 |
IRGC scientists and commanders |
Human intelligence + electronic surveillance |
Emerging — location tracking |
| Tehran camera hack |
2022–2026 |
Leadership compound and city-wide movement |
Long-term network access, AI video analytics |
Central — pattern-of-life AI |
| BadeSaba PSYOP |
2026 |
Iranian civilian population and IRGC members |
Backend notification server compromise |
Adjacent — mass targeting via app infrastructure |
The through-line is clear: each operation has expanded the attack surface, increased the degree of civilian infrastructure involvement, and incorporated more sophisticated data processing. The Tehran camera hack represents the point at which AI moves from supporting tool to central enabling technology without the machine learning analysis of billions of data points, years of camera footage would have been an unprocessable archive rather than a precision targeting system.
What This Changes About Modern Conflict
Every City’s Infrastructure Is a Potential Intelligence Asset
Tehran’s traffic cameras were built to manage congestion and enforce domestic political control. They became the most valuable intelligence source in the operation against Iran’s own leadership. This is not a story about a unique Iranian vulnerability; it is a story about the dual-use nature of all urban surveillance infrastructure. Every city that builds a centralised camera network with AI processing creates, by definition, a potential foreign intelligence asset if that infrastructure can be compromised.
AI Turned Years of Data Into Real-Time Targeting
Without AI, years of camera footage are an archive. With AI pattern-of-life analysis and social network modelling, it becomes a continuously updated, queryable targeting system. The technology required for object detection, trajectory analysis, and graph analytics is commercially available. What Israel demonstrated is the application of that technology to an adversary’s own surveillance infrastructure at national scale.
Civilian Apps Are Now Dual-Use Weapons
The BadeSaba operation establishes a precedent that extends well beyond Iran. Any widely installed application with notification permissions and a trusted relationship with its users represents a potential psychological operations delivery mechanism in a future conflict. The attack surface of modern warfare now includes app stores, developer credentials, and cloud notification infrastructure, none of which were designed with military threat modelling in mind.
The Information War Was Won Before the Kinetic War Began
By the time missiles struck on February 28, Israeli intelligence had already achieved three critical objectives: they knew where Khamenei was in real time, they had disabled his security team’s ability to communicate, and they had begun pushing defection messaging to millions of Iranians simultaneously. The kinetic operation executed against a target that had already been stripped of its intelligence, communication and psychological defences. That is what AI-assisted warfare looks like at full operational maturity.