Nothing new happened in Iranian cyber this weekend, which did not stop it circulating
The corpus of claims about Iranian access to US critical infrastructure is between one and six months old and rests substantially on anonymous officials. It keeps resurfacing without new dates attached.
NBC News reported that Iran attempted cyberattacks on a range of US infrastructure roughly two weeks ago, at the end of August, under a headline ending “sources say” — anonymous US officials, a claim rather than a confirmed event. The National in Abu Dhabi ran an analysis on 2 September. The reporting those pieces sit on is older still: TechCrunch’s account of the alleged Iranian hacks on US water utilities is dated 14 August, and the Center for Strategic and International Studies' mapping of Iranian activity against US water systems is about a month old. Vendor research in circulation is older again. Symantec’s “Seedworm” work on an Iranian group and a US bank, airport and software company has a derivative dated 10 March; Picus published on Iranian threat actors on 8 April; the Canadian Centre for Cyber Security bulletin is from February.
Three gaps matter before any of this is treated as established. No named US utility has confirmed an intrusion on the record in the material reviewed. The word “attempted” is doing heavy work: the coverage collapses scanning, credential stuffing and actual access to operational technology into a single verb, and those are not the same event. And where a CISA warning is invoked, it should be cited to a numbered, dated CISA advisory rather than to secondary write-ups — one page circulating this week, on an SEO-shaped domain with a bracketed year in its title, attributes a warning to CISA with no evident reporting behind it. Separately, Citizen Lab’s 8 May telecom-surveillance report is being re-promoted on social platforms under a sharpened attribution framing it did not originally carry.
The Files found no new, dated Iranian cyber incident inside the 11–14 September window. That is a statement about what surfaced, not a claim that the window was empty — and the same caveat applies with more force to areas this desk did not reach at all, including platform takedowns, AI-generated propaganda, and information operations and shutdowns across Mali, Burkina Faso, Niger and Sudan. The one dated tracker record nearby is Internet Society Pulse’s log of an exam-related internet shutdown in Iraq on 1 September, which sits outside the window but is a primary record rather than a relayed claim.
Assessment: A quiet weekend does not produce a quiet feed. Where no incident occurs, the archive supplies one, and the material with the least friction is the material with no timestamp on its face: vendor research with an operation name, an anonymous-official story, a lab report with someone else’s headline bolted on. The practical defence is mechanical rather than analytical — check the publication date before the argument, and treat a named operation as marketing until a second party corroborates it. The Iraq shutdown log is the shape of what this desk should be built on: dated, methodologically legible, and boring enough that nobody has an incentive to re-cut it.