Identity Verification and State Surveillance in Iran: Instagram Advertising, Divar and the Power to Identify Users
Requirements to register the identities of online advertisers, alongside Divar’s links between user accounts and identity and financial records, make digital activity easier to attribute to individuals. Combined with access to data and pressure on businesses, these connections can become instruments of control.


On September 28, 2026, Iran’s National Cyberspace Center announced that a framework for regulating online advertising had been approved. The framework provides for identity verification of advertising participants and advertising identifiers. Its monitoring provisions also cover accounts operating on foreign platforms, including Instagram. Separately, a technical report describing a remote code execution pathway in some Android versions of Divar, a major Iranian classifieds platform, has raised questions about the security of users’ data and devices.
These developments have different origins and mechanisms. Examined alongside Divar’s identity verification services, however, they raise a common question: how closely is users’ economic activity linked to their legal identity, financial information and devices—and who can use those connections?
In Iran, that question must be considered against the authorities’ record of targeting social media users and security agencies’ pressure on technology companies. In March 2025, the UN Independent International Fact-Finding Mission on Iran described online surveillance as an important tool of state repression. It reported the shutdown of Instagram accounts and confiscation of SIM cards belonging to human rights defenders, including women. This record matters when assessing identity registration requirements, although it does not establish that the new advertising framework or the Divar vulnerability has been used in such cases.
Registering identities for Instagram advertising
According to reported remarks by Arash Vakilian, the National Cyberspace Center’s director-general for cultural governance coordination, the advertising framework seeks to establish the identities of both those commissioning advertisements and those publishing them. Basic details, including national identification numbers and mobile phone numbers, are to be verified, while advertising content is to carry an identifier. Accounts with more than 10,000 followers will receive priority in monitoring.
At the time of the announcement, the framework was awaiting formal issuance. Approximately three months were envisaged for preliminary measures and two years for the overall programme. Approval should therefore not be confused with full implementation. Nor would an advertising identifier replace an Instagram username: its stated function is to identify advertising content and the parties involved.
The significant consequence is the connection between a public-facing activity and a registered individual. A page operating under a business name or pseudonym may have to register the identity of the person responsible for it in a domestic system to continue advertising. Identifying that person would then depend less on piecing together clues from posts and photographs.
Establishing this link does not necessarily require cooperation from Meta. Registration by the account operator can supply some information that Iranian authorities might otherwise struggle to obtain from a foreign platform. It does not, by itself, provide access to private messages, passwords or the account’s complete records.
Commercial relationships can also become traceable
Linking an identity to a page reveals more than who publishes its content. If an advertising identifier connects the advertiser and publisher, it may also create a record of their commercial relationship.
Depending on what the system collects, retains and makes searchable, those records could reveal which pages work with a particular business, which individuals advertise for the same client and how a person’s advertising activity changes over time. The full architecture needed to assess these capabilities has not been established in the sources examined.
For an account operator, this can have consequences beyond privacy. Their identity, published content and sources of income become connected. If their activity attracts enforcement action, authorities may gain opportunities to pressure both the individual and their commercial partners.
This does not establish that a security database of advertising contracts already exists. It identifies the power that recording these relationships could create—and the importance of rules limiting its use.
Divar connects accounts to identity and financial information
Divar explicitly describes some of these connections in its own documentation. In “Divar’s Measures to Combat Money Laundering,” the company states that posting an advertisement requires matching a mobile phone number to a national identification number through Shahkar, Iran’s telecommunications identity verification system. It also describes matching banking information to a verified identity when refunding money and providing necessary information to “competent authorities” when required.
Shahkar checks whether a mobile number is registered to the holder of a particular national identification number. This can establish consistency between subscriber records and the identity submitted. It does not independently prove that the person using the account at a given moment is the registered subscriber.
The process nevertheless links the account to an identifiable person. Financial verification strengthens the connection between identity and a bank account in the refund process described by Divar. Using Shahkar does not mean that Divar automatically transfers advertisements or conversations to that system.
This distinction matters because identifying users does not require continuous transfer of every record. A platform can retain activity data while another system verifies identity. The records may subsequently be connected through a query or a request for disclosure.
Separate records can produce a more detailed picture
A mobile number, national identification number, bank account and activity history each reveal a different part of someone’s digital life. Connecting them can make that picture more detailed.
An account identifies the advertisements posted through it. Identity verification helps attribute the account to a registered person. Financial information, where available and accessible, may establish particular economic connections. Location data may link an account to a physical place.
This is data linkage: information collected for different purposes is connected through a shared identifier. A mobile number or national identification number can serve that function.
The ability to link records must still be distinguished from evidence that they have been linked. Establishing a connection between databases requires evidence of what information was exchanged, who received it and how the matching occurred. A shared identifier alone does not demonstrate shared access to all records.
Account activity also does not necessarily describe the account holder’s circumstances accurately. Advertising a property does not prove ownership; searching for an item does not prove purchase. Using these records to make decisions against people without accounting for such limitations can produce serious errors.
Location verification adds a physical connection
In its official description of on-site verification for property advertisements, Divar explains that an advertiser activates their phone’s location at the property and takes fresh photographs. The system assesses whether the location and images match the listing. The company stresses that this process does not establish property ownership or constitute in-person identity verification.
The feature illustrates how an account can be connected to presence at a particular place and photographs of that place. If retained and made accessible, those records could help assess the account’s relationship to the location.
Collecting location during this process should not be confused with continuous phone tracking. The documentation describes location collection for listing verification; it does not establish ongoing monitoring of a user’s movements.
Keeping information out of the public advertisement also does not resolve the privacy question. Data that other users cannot see may still be processed or retained internally. Retention periods, access permissions and disclosure conditions determine the risks.
The Divar vulnerability extends the question to users’ devices
A technical report by security researcher Ramin Farajpour describes a separate concern. According to the analysis, a specially structured push notification can activate a pathway in certain examined versions that connects to an external address and allows commands to execute with the application’s privileges.
The researcher reports that the older and newer files share the same signing certificate and that the pathway was removed in version 11.15.0. A matching certificate provides information about the applications’ signing relationship. It does not identify who introduced the code or how it entered the production process.
In its official September 28 security notice, Divar acknowledged a significant vulnerability and instructed users to update to version 11.15.0 or later. It also warned that disabling affected versions did not remove the vulnerability from copies already installed on devices.
This differs from ordinary access to account records. If the reported pathway is activated, the issue extends beyond information stored on company servers to command execution within the application’s environment on the device.
The extent of that access depends on application permissions, the Android version and operating system restrictions. Execution with an application’s privileges is not equivalent to root access or complete control of a phone. The technical report alone does not establish which users, if any, were targeted or what information was extracted.
Linking identity to a device can enable selective targeting
The connection to identity verification lies in the possibility of selecting a particular target. If an actor can associate a person’s identity with their account and device, and can also deliver the required activation message, those capabilities could be combined to target that individual.
Identity records would establish who the target is; the technical pathway, if successfully activated, would provide a means of executing commands.
That scenario requires access to both capabilities, or cooperation between those who hold them. Possessing identity information alone does not enable activation of the code. Access to push notification infrastructure does not necessarily reveal a device owner’s legal identity.
Determining whether the pathway was used would require examination of push delivery logs, received commands, targeted devices and the history of the code’s introduction into the build process. The available evidence does not establish attribution to the Islamic Revolutionary Guard Corps (IRGC) or use for state surveillance.
Pressure on a company is another source of control
State influence over a platform does not depend exclusively on ownership. Pressure on executives and business decisions can also affect how a company operates.
Hessam Armandehi, Divar’s founder and board chair, publicly stated that the IRGC Intelligence Organization had disqualified him from involvement in his own company. He consequently opposed Divar’s proposed stock exchange listing. His statement documents security-agency intervention in the company’s future. It does not establish IRGC ownership or access to all user information.
Separately, Divar’s stated provision of information to competent authorities identifies a declared route for disclosure. Its scope and conditions require closer examination: which authorities can request information, what they receive and whether the affected user is notified.
Direct database access, disclosure in response to a request and informal pressure on a company are different mechanisms. Distinguishing them makes the actual points of exposure easier to identify.
Identification can become pressure on a livelihood
For someone earning through Instagram or an online marketplace, an account is part of their economic life. Threats to halt activity, remove content or disrupt commercial relationships can carry immediate costs.
Identity registration makes content easier to attribute to a person. Recording advertising relationships may also make clients and business partners identifiable. If those records are used to exert pressure, the consequences can extend beyond the individual to their commercial network.
Iran’s documented record of action against Instagram accounts shows that control of online activity can lead to action against people. Greater identifiability may also affect those who have not been directly targeted. Someone who understands that their page, identity and income can be connected may avoid sensitive expression to protect their business.
The effect will vary with economic dependence, published content and previous enforcement. Identity verification alone does not establish a repressive purpose in every instance. The concern is how the resulting information can be used within a system with a documented record of targeting citizens’ expression and activity.
What remains undisclosed
Explaining that verification combats fraud or money laundering identifies the stated purpose of collection. Assessing its consequences also requires knowing what happens to the information afterwards.
For the advertising framework, the relevant questions concern the registration system, collected fields, links between identifiers and pages, and institutional access. For Divar, they concern retention of identity and location information, disclosure conditions and notification of users. For the Android vulnerability, they concern the code’s origin, affected releases and evidence of any exploitation.
These details determine how far identity verification remains tied to a specific service and where it can facilitate broader identification and action against an individual.
The advertising framework and Divar’s services reveal components of a connection between identity and economic activity. The technical report raises a separate pathway for access within an application on a user’s device. The evidence does not establish a coordinated operation behind these developments. It does show why privacy risk cannot be assessed by examining the collection of a national identification number alone: the risk grows when identity, activity, commercial relationships and location become linkable, particularly when users cannot see who can access those connections or what limits govern their use.