A six-month war whose cyber front is now being reported by aggregators and stale dashboards
No named-victim cyber or influence event in the Middle East or Sahel was wire-reported between 30 August and 2 September. What circulated instead was July material, April material and, in one case, a 2024 breach re-dated to 2026.
The clearest artefact of the window is a story about a British power plant. Cyber Security News published “Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days” on 28 August, and the piece was still surfacing in early-September feeds. Per that account, an incident forced a plant to halt operations for roughly four days in July, caused no customer outages, and left the wider electricity system running normally; it became public on 22 August, when reporting said hackers believed linked to Iran had disrupted a UK energy facility. The plant is not named. The originating report is not identified. The attribution is hedged twice — “reportedly” and “believed linked” — and no operator or UK government statement is quoted. Three handoffs separate the reader from an incident with no measurable effect, and each handoff has firmed up the sponsor.
Two other items show the same mechanism working faster. SOCRadar’s Iran-Israel cyber conflict dashboard is indexed as updated a week ago and is being cited as a live tracker of hacktivist tempo; its own internal stamp reads “Last updated: April 6, 2026,” its threat-actor count is frozen at 47, and its embedded Telegram and X feeds both display zero. Separately, Cyber Security News’s “Top 10 Cyber Attacks of 2026,” indexed one day old, states that “in April 2026, hackers breached National Public Data’s systems, exposing 2.9 billion records” sold for $3.5 million. The National Public Data breach and the 2.9 billion figure are from 2024. The year has been rewritten in place — a checkable instance of content mills re-dating old breaches into the current conflict.
The figures reaching general coverage are not much sturdier. Brig. Gen. (res.) Yossi Karadi, director general of Israel’s National Cyber Directorate, told the Times of Israel on 29 June that Israel recorded 4,800 Iranian attacks in June 2026 against 1,600 in June 2025 — a belligerent government’s own tally, one month, year on year, with the unit “attack” undefined. Wikipedia’s entry on the Iranian blackout carries April estimates of $30–40 million a day in direct shutdown costs, $70–80 million with indirect costs and an 80% fall in online sales, sourced to IranWire and Iran International, but garbles the estimator’s name; the Files has not traced it to either original and does not publish it as fact. The measurement-based exception is Cloudflare Radar, which on 22 July logged an unusually high number of severe and prolonged disruptions in Q1, singling out extended government-directed blackouts in Uganda and Iran.
Assessment: Absence is the finding. Six months into a war, the cyber dimension is being narrated by dashboards with fresh crawl dates and five-month-old payloads, by government self-tallies with no published methodology, and by mills that change a year and republish. The incentives run one way: aggregators need volume, vendors need a threat landscape, governments need an adversary count. Nobody in that chain is paid to report a quiet week. Note also what has not been said. Joe Slowik of Pylos argued on 25 May that Predatory Sparrow’s silence since February is genuinely puzzling given its prior tempo — and that verifying anything inside Iran is near-impossible absent independent Iranian media. That question is still unanswered.