The Iranian cyber file rests on undated vendor pages, group claims and assessed attribution
Trackers refreshed inside the window carry incidents from February. The most-cited capability profiles carry no publication date at all. The distinction between a claim, an assessment and a confirmed event is where this file is weakest.
The CSIS Significant Cyber Incidents tracker was refreshed around 4 September, but the Iran-related entry it surfaces is from February 2026: the hijacking of the Iranian prayer app BadeSaba Calendar to push notifications urging military personnel to defect and lay down their weapons during US and Israeli airstrikes, sent over a roughly 30-minute period. No group claimed the operation. CSIS records that cybersecurity experts assessed it as likely Israeli in origin — assessed, not claimed and not confirmed. A tracker’s update date is not an incident date, and the two are routinely collapsed. The same collapse applies to Symantec’s account of Seedworm, which in December 2025 claimed to have compromised the mobile devices of former Israeli prime minister Naftali Bennett and a senior Netanyahu aide. That is the group’s assertion about itself, not a verified breach.
The capability profiles beneath the headlines are dated unevenly or not at all. Palo Alto Networks' Unit 42 brief, updated 17 April 2026, names Handala Hack as the most prominent Iranian-aligned persona and links it to the Ministry of Intelligence and Security, and describes an “Electronic Operations Room” formed on 28 February 2026. Trellix’s Iranian capability paper carries no publication date and its content runs only to roughly March 2026, profiling MuddyWater and APT34/OilRig. Halcyon, also undated, reads Handala’s markedly reduced blog activity since January 2026 as evidence of high operational tempo rather than dormancy — an inference that cannot be disproved by any observation. Separately, a vendor dashboard last refreshed a fortnight ago lists Al Udeid, the Fifth Fleet, Ali Al Salem and Al Dhafra as in-scope targets, a claim-based aggregation of hacktivist assertions that reads like confirmed targeting.
Assessment: Note the incentive: a vendor that predicts activity from silence wins whether the group resurfaces or stays quiet, and the prediction costs nothing to make. Undated pages compound it, because a reader cannot price the claim without knowing when it was written. The more consequential absence is regional. Saudi Arabia’s National Cybersecurity Authority and the UAE Cyber Security Council said nothing in anything retrieved for this window, while a US-published base list circulates unchallenged. Gulf attribution behaviour — when these bodies speak, and what they decline to name — is the part of this file that Washington desks do not cover and cannot.