Editor's note, 2026-09-27: I have since measured the same site through a second US-Iran escalation with a real baseline, and found no spike. That follow-up, Iran Struck Again. This Time I Had a Baseline., revisits the 251 percent figure below and explains why I am less sure than I was that this site measured the conflict. The April text is unchanged except for one date anchor.
The traffic on jon.rehagen.net jumped 251 percent week-over-week. The site is a personal blog. There is no fintech endpoint, no government domain, no critical infrastructure behind it. The spike is real, the campaign was still in progress when I wrote this at the end of April, and the geographic shape of it lines up with a war I am nowhere near.
Akamai measured a 245 percent rise in malicious traffic against North American, European, and Asia-Pacific institutions in the two weeks after the February 28 strikes on Iran (Akamai, Fortify Your Network Security from Emerging Geopolitical Cyberthreats). That window closed on March 13. The campaign did not. My site is one ten-thousandth of a single Prolexic customer's footprint, and it is still being walked over by the same scanners that walked the banks. The pattern is global, continuous, and indifferent to the importance of the target.
The interesting move is not to reproduce the Akamai number on a personal site. The numbers do not scale that way. The interesting move is to show that the conflict has a recognizable shape at every scale. At Prolexic scale, the story is which sectors absorbed which fraction of the noise. At the scale of a static blog with a Cloudflare edge, the question is not "am I a target" but "what does my edge look like to a campaign that has already decided to look at everything."
What the data shows
Six days of Cloudflare logs, April 22 through April 27 - the maximum window my plan retains. Twenty-two thousand five hundred twenty-five total requests. Nine hundred fifty-one rendered page visits. The ratio of requests to visits is 23.7 to 1. A normal personal site, in my experience, runs at three or four to one. A ratio above twenty means the dominant consumer of the site is not a browser. It is a script.
| Date (UTC) | Requests |
|---|---|
| 2026-04-22 | 2,516 |
| 2026-04-23 | 3,324 |
| 2026-04-24 | 3,626 |
| 2026-04-25 | 4,733 |
| 2026-04-26 | 6,187 |
| 2026-04-27 (partial) | 2,139 |
The spike I noticed first was Apr 23. The campaign actually got bigger after that. Apr 26 is two and a half times the volume of Apr 22, and the single highest hour in the window is 1,517 requests at 09:00 UTC on Apr 26. Five separate hours crossed a thousand requests across four different days, which rules out a single misbehaving cron job.
The geographic distribution is where the story sharpens:
| Country | Requests | Visits | Req/Visit |
|---|---|---|---|
| United States | 8,587 | 309 | 27.8 |
| Canada | 1,666 | 138 | 12.1 |
| Germany | 1,562 | 95 | 16.4 |
| Singapore | 1,513 | 6 | 252 |
| India | 1,178 | 7 | 168 |
| Netherlands | 1,122 | 29 | 38.7 |
| Lithuania | 903 | 11 | 82 |
| Brazil | 529 | 7 | 76 |
| Philippines | 500 | 0 | infinite |
| UAE | 300 | 0 | infinite |
| Georgia | 300 | 0 | infinite |
| Kuwait | 299 | 0 | infinite |
| Palestine | 298 | 0 | infinite |
| Pakistan | 267 | 0 | infinite |
| Oman | 227 | 0 | infinite |
| Morocco | 227 | 0 | infinite |
Hundreds of requests apiece, zero rendered visits, drawn disproportionately from the Gulf, the Levant, North Africa, South Asia, and the Caspian. Iran itself does not appear in the data, which is consistent with the documented internet blackout and only-partial restoration on April 17 (Unit 42, Threat Brief: Escalation of Cyber Risk Related to Iran). It is also consistent with what Akamai's own caveat states clearly: the source IP geography of conflict-driven traffic is the geography of proxy infrastructure, not the geography of the actor. Akamai recorded Russia at 35 percent and China at 28 percent of source IPs not because Russian and Chinese actors were running the campaign, but because Iranian-aligned hacktivists routed through them.
What I cannot tell from this data: which requests Cloudflare's WAF blocked, which got through, what paths they probed, what ASNs they came from. The free-tier dashboard surfaces aggregates and country, not request-level forensics. The 23.7 ratio and the zero-visit country cluster are a strong bot-dominance signal, not a verdict on maliciousness.
The mechanism, in four steps
Akamai's report identifies the composite traffic mix. The question for a personal site is mechanical: how does a kinetic strike on Iran turn into scanner traffic against a static blog?
Hacktivist mobilization. Within hours of the February 28 strikes, more than sixty hacktivist groups activated on Telegram, coordinated through what Unit 42 documents as the Electronic Operations Room. The mobilization speed is in hours, not days (CloudSEK, AI, the Iran-US Conflict, and the Threat to US Critical Infrastructure). Some groups are Iranian state-linked personas like Handala Hack, which the US Department of Justice linked to Iran's MOIS on March 19 (SecurityWeek, March 20, 2026). The named target lists are concentrated on government and finance. The reconnaissance traffic that supports those lists sweeps everything in adjacent IP space.
APT pre-positioning and pivot. Iranian state-aligned APTs were not waiting for February 28 to start. MuddyWater acquired new command-and-control infrastructure in September 2025 and again in January 2026, roughly one month before the strikes (Trellix, The Iranian Cyber Capability 2026). Pre-planted backdoors were already in US banks, airports, and NGOs before the kinetic phase began. The same scanning infrastructure that maintains those footholds is the infrastructure walking my edge.
Botnet retasking. The infrastructure that runs DDoS-as-a-service for hire is the same infrastructure available to hacktivist crews during a conflict. KrebsOnSecurity documented the March 2026 DOJ-led takedown of the Aisuru, Kimwolf, and JackSkid botnets, with three million-plus compromised IoT devices (KrebsOnSecurity, Feds Disrupt IoT Botnets Behind Huge DDoS Attacks). The takedown did not end the campaign. NSFOCUS observed Mirai-variant traffic against Iran's own state infrastructure in late January, before the strikes - the same toolkits, retasked across sides (NSFOCUS, Evaluating the Role of DDoS Attacks in US-Iran Conflict).
Mass-scan spillover. Akamai's sub-metrics break the 245 percent down: botnet-driven discovery traffic up 70 percent, automated reconnaissance up 65 percent, infrastructure scanning up 52 percent, credential harvesting up 45 percent. Discovery and scanning are the front of the funnel. Their job is to enumerate the population, not to act on it. They do not skip personal sites. They cannot. The cost of skipping is higher than the cost of including, because skipping requires the scanner to know what to skip, and a global scanner does not know.
The last of these is what delivers conflict traffic to a personal site. The other three are why the volume is up.
The pattern is not new
| Conflict | Date | Measured spike | Source |
|---|---|---|---|
| Russia / Ukraine invasion | Feb 24, 2022 | Application-layer mitigations +1,300 percent in Ukraine; DDoS as 12.6 percent of Ukrainian traffic in Q1 (vs 1 percent prior quarter) | Cloudflare Blog, One Year of War in Ukraine |
| Russia / Ukraine spillover | 1H 2022 | DDoS attacks against Russia +275 percent in March; Finland +443 percent vs 2H 2021; Ireland +118 percent | NETSCOUT EMEA Regional DDoS Threat Report |
| Israel / Hamas | Oct 7, 2023 | DDoS at ~50 percent of all traffic to Israeli sites within hours; 1.26 billion HTTP DDoS requests blocked Oct 8 against a single newspaper | Cloudflare Blog, Internet traffic patterns in Israel and Palestine |
| India / Pakistan (Operation Sindoor) | Apr-May 2025 | Attacks on Indian systems +500 percent; on Pakistani systems +700 percent; 40+ hacktivist groups joined within days | Radware, Escalating Hacktivist Attacks Amidst India-Pakistan Tensions |
| Iran (Operation Epic Fury) | Feb 28, 2026 | +245 percent overall malicious traffic across NA / EU / APAC | Akamai blog |
The signature is consistent. Mobilization in hours. Spillover to non-primary-adversary states. Sustained APT activity over weeks and months after the initial wave. The personal-site read of any of these would have looked like the table above with a different column header.
What the data does not say
The CSV that produced this article is Cloudflare's adaptive-groups aggregation. It does not expose IP addresses, ASNs, user-agent strings, paths probed, or rule-firing identifiers. The 23.7 requests-per-visit ratio is suggestive of bot dominance. The zero-visit country list is consistent with conflict-mobilized scan traffic. Both are also consistent with crawler infrastructure that simply does not render JavaScript.
The honest framing is that my data shows a shape consistent with what Akamai measured at a different scale, in a different window, with different instruments. The shape is the contribution. The numerical correlation is unprovable from this dataset.
What changes for a small operator
CISA's most current operational guidance for the Iran 2026 conflict lives in advisory AA26-097A from April 7, focused on Iranian-affiliated exploitation of programmable logic controllers in water, energy, and government services (CISA AA26-097A). None of that is a personal-site concern. The advisory's general guidance, however, lines up with what Akamai, Coalition, and Unit 42 have all recommended in the past two months (Coalition Inc, How Geopolitical Tension Can Spotlight Latent Cyber Risks).
Compressed for a single-operator personal site:
- Geographic IP blocking at the edge where there is no legitimate user base in high-risk geographies. Akamai's customers stopped billions of malicious packets with country-level deny rules; the same control on a free CDN tier costs nothing.
- Aggressive rate limiting on every public endpoint. Discovery traffic and credential harvesting both fail loudly when rate limits are tight.
- WAF rules tuned for credential brute force and path traversal. The 45 percent rise in credential harvesting attempts is the most relevant of the Akamai sub-metrics for a small site.
- Attack-surface reduction. Disable unused ports. Make sure RDP is not exposed to the public internet, which Coalition documents as the primary post-scan exploitation target from Iranian-origin scans.
- ASN-level blocking for the worst-offender hosting providers, available on Cloudflare's free tier at no cost.
- Offline backups of site config and content. The wiper-malware risk is enterprise-scale; the small-operator equivalent is a server running unpatched software, and the recovery posture is the same.
- Honest acknowledgment that a personal site is not a target. It is a sample. The risk is that the sample contains an exploitable instance the scanner happens to find, not that the scanner came looking for it.
The closing read
The personal site is not the target. It is the sample. The sample is now global, continuous, and shaped by a conflict no one near it is fighting. The conflict's actors are not coming for the blog. The conflict's infrastructure is, because that infrastructure is not designed to discriminate. A defender of any size who reads the same Akamai number I did and asks whether their scale makes them safe has the question backwards. Scale does not make a defender safe from a campaign whose front-end is indiscriminate. Scale only changes which of the campaign's stages reach you. The reconnaissance stage reaches everyone.
The Cloudflare-to-BigQuery pipeline I should have built six months ago is now on the calendar. The next read on this is going to be longer than seven days.