Two unaudited numbers and a Telegram boast: how the cyber war is being counted
Tehran says it absorbs up to 180,000 external cyber incidents a day. Israel says it logged 4,800 in a month. A channel calling itself APT IRAN says it darkened AT&T in Texas. None of the three has been independently verified.
Behzad Akbari, Iran’s deputy communications minister, has put the country’s incoming external cyber incidents at 150,000 to 180,000 a day and said a “major cyberattack” two weeks earlier was repelled, according to GlobalSecurity.org’s 16 September digest. The figure is unaudited, “incident” is undefined, and at that volume the count almost certainly includes automated internet-wide scanning that reaches every connected network on earth. It should be read as a political number. Its natural pair is equally self-reported: Brig. Gen. (res.) Yossi Karadi, director general of the Israel National Cyber Directorate, told Die Welt that Israel registered around 1,600 hostile incidents in June 2025 and some 4,800 in June 2026, and that his directorate handled more than 26,000 attacks in 2025, a 55 percent rise on 2024, per the Times of Israel’s 29 June account of the interview. Both states count themselves. Neither is audited.
The counting problem has a cruder cousin. On Tuesday 8 September a Telegram channel branded APT IRAN claimed it had caused an AT&T outage across major Texas cities on Labor Day and breached an unnamed Texas water utility; the claim was denied the following day, and the channel replied that those rebuffing it “don’t even know what we tampered with” or “have access to”, as reported by Bridget Johnson for Threat Beat on 10 September. The Houston Chronicle, cited in that write-up, recorded Downdetector reports beginning Sunday and surging after noon on Labor Day, clustered in Houston, then Spring, Dallas, Fort Worth, Cypress and Austin. The outage is an event with third-party measurement. The attribution is a claim by an actor with every incentive to adopt any coincident failure — and a Houston-weighted report pattern is what an ordinary AT&T fault looks like, because that is where the customers are.
Assessment: The asymmetry to watch is that events are measurable and attributions are not. Downdetector, NetBlocks and forensic labs produce numbers somebody else can check; ministries and Telegram channels produce numbers designed to be repeated. Iran’s 180,000-a-day figure does work at home — it frames the state as besieged — and abroad, where it seeds the idea that any future Iranian action is reciprocal. Israel’s 4,800 does the mirror job for budget lines through 2030. Neither tells you whether anything broke. When a claim arrives this weekend, ask only who measured the effect, not who claimed the cause.