☰Series Navigation (13 parts)
Everything in this series so far has been about code. A worm, a cyberweapon, a swarm of software agents. This one is about explosives in people’s pockets, and I want to be clear at the top about why it belongs here anyway.
The victims did the same thing Iran did at Natanz and the same thing every organization in this series did. They looked at their risk, decided the safe move was to get off the compromised channel, and moved to something they believed the enemy could not reach. Iran built an air gap. Hezbollah bought pagers. Both times, the thing they trusted to keep them safe was already owned by the people they were hiding from, and the trust itself was the weapon. The blast is different. The lesson underneath it is identical.
What happened in the Hezbollah pager attack?
On the afternoon of September 17, 2024, at around half past three local time, pagers carried by Hezbollah members across Lebanon began to buzz with an incoming message. As people lifted the devices to read them, the pagers exploded. Not one or two. Thousands, at nearly the same moment, in homes, cars, shops, and streets.
The next day, September 18, it happened again with a different device. Two-way radios, the walkie-talkies Hezbollah used for its communications, detonated across the country. Some went off at funerals being held for the people killed the day before, where members had gathered to mourn. The second wave killed more people than the first.
Across the two days, at least 42 people died, including a reported dozen or so civilians and several children. Between 3,500 and 4,000 were wounded. The injuries were concentrated where a person holds a device: the hands, the face, the eyes. Ten months later, survivors were still going through surgeries and learning to live with what the blasts took. Among the wounded on the first day was Iran’s ambassador to Lebanon.
Israel did not claim the attack at first. Prime Minister Benjamin Netanyahu publicly confirmed Israeli responsibility in November 2024, describing it as an operation carried out over the objections of some senior officials. He has since presented it as a demonstration of Israeli technical and intelligence skill.
Why was Hezbollah using pagers in the first place?
The reason it belongs in this series sits here, so it’s worth slowing down on.
Hezbollah knew its phones were a liability. A modern smartphone is a tracking device that also makes calls. It reports its location, it can be turned into a microphone, and an intelligence service with the right access can intercept its communications. For a militant group whose members are targets, carrying a smartphone is carrying a homing beacon, and Israel had a long record of using exactly that kind of access to find and kill people.
So in early 2024, Hezbollah made what looked like the smart, security-conscious decision. It moved off smartphones and onto pagers. A pager is about as dumb as an electronic device gets. It receives short messages and nothing else. It has no GPS, no microphone, no camera, no apps, no internet connection. It cannot be tracked the way a phone can, because there is almost nothing in it to track. On paper, moving to pagers closed the exact hole Hezbollah was worried about.
That decision was their air gap. It was a deliberate step to a simpler, more isolated technology precisely because the sophisticated one was compromised. And like the air gap at Natanz, it protected against the threat they were looking at while leaving them wide open to the one they weren’t.
How did Israel get bombs into the devices?
Not by intercepting a shipment and rigging it in a warehouse, though that has been done in other operations. This was deeper. Israel reportedly became the supplier.
The pagers carried the brand of Gold Apollo, a real Taiwanese company. But Gold Apollo didn’t make the deadly batch. It had licensed its name to a company in Budapest called BAC Consulting.
According to reporting in the New York Times, BAC and at least two other shell companies were Israeli intelligence fronts, created to manufacture and sell rigged hardware while hiding any link to Israel. Hezbollah reportedly ordered around 5,000 pagers through an intermediary and handed them out to its people. The explosives were built into the devices during manufacture, hidden in a way that survived ordinary handling and inspection.
The devices were attractive for exactly the reasons a careful buyer would want: long battery life, rugged, reliable, able to carry encrypted messages. They were good products. That was the point. A front that sells junk gets found out. A front that sells a genuinely good pager builds a reputation, wins the order, and delivers the weapon inside a device the customer is glad to have.
The radios followed the same logic through a murkier path. The walkie-talkies bore the markings of ICOM, a Japanese manufacturer, and matched a model, the IC-V82, that ICOM said it had discontinued around a decade earlier and no longer supplied. Whether those were counterfeits built to look like ICOM units or genuine units diverted and rigged, the structure was the same: a trusted-looking device, sold into Hezbollah’s supply chain, carrying a bomb the buyer never suspected.
I am not going to walk through how the explosive charges were built or triggered. That detail is available elsewhere for anyone who wants it, and it adds nothing to what I care about here. The trust is the weapon, not the chemistry.
Was the pager attack legal?
This is contested, and I’m going to give you both sides plainly, because it’s a genuine dispute among serious people and not a question I can settle.
A group of United Nations human rights experts called the explosions a terrifying violation of international law. Their core argument is about discrimination. At the moment thousands of devices detonated, there was no way to know who was holding each one or who was standing next to them. A pager could be in a fighter’s pocket, or on a kitchen table next to a child, or in the hand of a medic.
International humanitarian law requires an attacker to distinguish between combatants and civilians and to weigh whether harm to civilians is proportional to the military gain. Critics argue that a weapon detonating in thousands of unknown locations at once cannot meet that standard by design. Human Rights Watch and several legal scholars raised a second problem. A body of law prohibits booby-traps built into ordinary, harmless-looking portable objects. That is close to a literal description of what these devices were.
The other side has serious advocates too. They argue the devices went to Hezbollah’s members, that Hezbollah is a party to an armed conflict with Israel, and the operation hit the group’s fighters while sparing the wider population a bomb on a building would have caught.
On this view the attack was a more discriminating use of force than the alternatives, and defensible under the laws of war. Some also note that Israel has not ratified the booby-trap protocol critics cite, a gap that complicates the legal claim even if it doesn’t settle the moral one.
I’m a technology person, not a lawyer, and I won’t pretend the legal question resolves cleanly. I can say the disagreement is real and that both sides are arguing in good faith about how centuries-old rules apply to a genuinely new kind of weapon. That difficulty, old rules meeting a new method, is itself part of what this attack represents.
Why does the pager attack belong in a series about isolation?
Because the pager attack is the physical, brutal proof of the thing every other article here argues in software.
Hezbollah did the security-conscious thing. It identified that its communications were compromised, and it withdrew to a simpler, more isolated technology to protect itself. That is textbook defensive thinking, the same instinct that builds an air gap around a nuclear plant. And it failed for the same reason the air gap at Natanz failed: the isolation was defeated upstream, before the device ever reached the user, by an attacker who had made themselves part of the supply the victim trusted.
There is no patch for this, no setting to change, no scanner that catches it. Hezbollah could have inspected those pagers and found nothing wrong, because there was nothing wrong with them as pagers. They worked. They just also belonged to the enemy from the moment they were built. When the thing you buy to protect yourself is made by the people you’re protecting yourself from, no amount of care with the device saves you.
The next article stays with the pagers and takes apart the supply-chain lesson in full: why going low-tech didn’t help, and what it means for anyone, in any field, who buys hardware through layers of resellers they’ll never meet. For the wider view of security, the cybersecurity hub collects the rest of my work.
Frequently Asked Questions
Continue the Series
1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI
