BadeSaba Calendar App Hack (Iranian Prayer-App Compromise)

Mobile App Compromise Push Notification Abuse Information Operations Crisis-Time Targeting
Overview
The BadeSaba Calendar app, a widely used Iranian prayer-timing application with reportedly more than five million downloads, was reportedly compromised to send unauthorized push notifications to users. Messages in Persian urged members of Iranian security forces to defect or lay down weapons during an active military period and major domestic internet disruptions.
Based on open-source reporting, the incident appears to involve compromise of push-notification infrastructure rather than a user-device exploit chain. Responsibility remains unverified in independent public reporting.
Technical Specifications
| Attribute | Details |
|---|---|
| Incident Type | Mobile app backend compromise / unauthorized push broadcast |
| Target Platform | BadeSaba Calendar app ecosystem |
| Primary Mechanism | Abuse of push notification backend/control plane |
| Access Path (Likely) | Unauthorized access to cloud APIs, keys, or developer notification consoles |
| User Interaction Required | None (push notifications delivered passively) |
| Observed Message Theme | Persian-language defection/surrender prompts during conflict period |
| Attribution Status | No official confirmed claim; external attribution remains unverified |
| Campaign Timing | Coincided with reported airstrikes and broad internet disruptions |
Affected Products
- BadeSaba Calendar mobile application users
- Push notification delivery infrastructure and related cloud control systems
- Users receiving emergency/prayer reminder notifications via the app ecosystem
- Status: Reported compromise event with trust and platform-integrity impact
Technical Details
Attack Vector
- Attackers reportedly compromised infrastructure used to manage or transmit app push notifications.
- This allowed large-scale message broadcast without requiring end-user interaction.
Likely Abuse Points
- Cloud-based push APIs and service credentials
- Developer/admin control panels for notification campaigns
- Keys/tokens used to authorize mass notification delivery
Operational Characteristics
- Messages were delivered in Persian and aligned with conflict-era narrative content.
- Delivery timing reportedly coincided with physical operations and major internet outages.
- Synchronization with broader disruption increased information-environment impact.
Attribution Caveat
- Public reporting frequently suggests state-linked motivation based on timing and message theme.
- No independently verified, official attribution is confirmed in provided sources.
Attack Scenario
-
Pre-Positioning:
- Threat actor obtains unauthorized access to the BadeSaba push-notification backend ecosystem.
-
Trigger Timing:
- During active military operations, actor initiates mass push campaigns.
-
Payload Delivery:
- Users expecting routine prayer/calendar reminders receive political-military messages instead.
-
Amplified Effect:
- Concurrent internet disruption reduces alternate verification channels.
-
Trust Degradation:
- Users and operators lose confidence in app integrity and notification authenticity.
Impact Assessment
- Millions of users potentially received unsolicited crisis-time messaging
- Reduced trust in app notifications and digital public-information channels
- Increased uncertainty around legitimacy of urgent mobile alerts
- Messaging may influence morale perceptions among civilians and security communities
- Narrative injection during conflict can amplify confusion and pressure
- App ecosystem becomes a vector for strategic psychological effects
- Demonstrates weaponization potential of push-notification control planes
- Highlights weak points in app backend/API credential governance
- Reveals hybrid-warfare value of compromising high-reach mobile platforms
Mitigation Strategies
For Users and Platforms
- Cross-check high-impact push messages with official channels before acting
- Keep mobile apps updated from trusted stores only
- Treat crisis-time notifications as potentially manipulated until verified
For Developers and Operators
- Harden push backend APIs, admin consoles, and cloud IAM controls
- Enforce MFA, least privilege, audit logging, and routine key/secret rotation
- Implement segmented authorization for high-volume broadcast actions
Monitoring and Response
- Monitor for abnormal push volume/content/timing patterns
- Define automated thresholds and alerting for anomalous notification campaigns
Resources and References
Open-Source Reporting
- Iran-Israel conflict: Iranian prayer app 'BadeSaba' with five million users hacked by Israel, report - Technology News | The Financial Express
- Hackers Hit Iranian Apps and Websites: Iranians receives 'Defend your brothers, Time for ...' and other notifications from BadeSaba as Iranian apps and websites hit by hackers | - The Times of India
- Iran Israel Live Updates Tehran Ayatollah Khamenei Mossad Trump: Israel Hacked Iranian Prayer App, Urged IRGC To Betray The Regime: Report
- 'Patriots, keep protesting': Iranian prayer app with five million users hacked by Israel, says report | World News - The Times of India
- Digital Warfare at 30,000 Feet: How Israel Hijacked an Iranian Prayer App to Broadcast Surrender Messages During Airstrikes
- Israel hacks prayer app to push propaganda to Iran: report • The Register
- Popular Iranian App BadeSaba was Hacked to Send “Help Is on the Way” Alerts
- How the BadeSaba Prayer App Was Hacked in Iran and How to Protect Yourself
- Hacked Prayer App Weaponized in Cyber Operations Amid US–Israel Strikes on Iran
Last Updated: March 3, 2026