The Week’s Iranian Cyber File Is a Claim, a Press Release and a January Blackout
Most of what circulated on this beat between Monday and Thursday was an unconfirmed assertion, a vendor distribution or months old. The one non-commercial dataset published this week remains unopened here.
MEMRI’s CJLab reported on or about 7 August that a pro-Iran cyber group claims to have hacked an Israeli organisation. Two layers apply: MEMRI is a partisan outlet with a stated editorial mission, and what it carries is the group’s own claim, not a confirmed breach. On 12 August the Israeli outlet JFeed published a piece on an Iranian AI deepfake video of Donald Trump said to be circulating widely online; this desk found no second outlet carrying it, no named forensic analyst and no stated provenance for the file, and does not treat the Iranian attribution as established. Kaspersky’s 3 August finding that cyberespionage is a growing threat across the Middle East, Türkiye and Africa was distributed as a press release, without a telemetry period or sample size in the material retrieved. SOCRadar’s Iran-Israel dashboard, last updated around 8 August, aggregates claimed attacks; it is a marketing asset and evidence of nothing.
The recirculation is heavier than the news. Amnesty International’s Security Lab research on Pegasus is July 2026 and is still being carried as fresh. The Iranian national blackout cluster — The Conversation on 16 January, Euronews on 14 January, TechPolicy.Press on 5 February, and the argument over the Starlink workaround — is seven months old, and nothing found this week indicates a new shutdown event. The Israeli cyber chief’s surge figures date to 29 June; the Haaretz hack-and-leak investigations to January and May. Against all that, the Internet Society’s Pulse project published within the past week a shutdown tracker and report covering 2019 to 2025, the only non-commercial seven-year series on this beat. This desk has not read its figures and will not print one it has not opened. Also unswept: the Israeli National Cyber Directorate’s statements, Persian and Arabic regional press, Gulf CERT advisories, NetBlocks and IODA telemetry, Citizen Lab and Access Now.
Assessment: The supply problem is structural. When no government will attribute the water-sector wave, the demand for narrative is met by parties with a commercial or political interest in supplying it: security vendors selling detection, threat-intel firms selling dashboards, monitoring groups selling a thesis about Tehran. Each produces material that is publishable and unfalsifiable in the same gesture. The test to apply this week is not whether a claim is plausible but who bears the cost if it is wrong — and for a dashboard entry or a partisan translation, nobody does. The one dataset with no product attached to it is the one that went uncovered.