Most of the Iran cyber material circulating this weekend is weeks or years old
On the fourth anniversary of the Mahsa Amini internet restrictions, 2018 and 2022 documents ranked at the top of current searches, and the public record still says Iranian connectivity was restored — under heavy filtering — at the end of May.
Four date collisions landed in the same seventy-two hours. Citizen Lab’s “Hide and Seek: Tracking NSO Group’s Pegasus Spyware to Operations in 45 Countries” was published on 18 September 2018 and ranked first on a search for NSO activity in September 2026; its “45 countries” figure comes from 2018 infrastructure scanning and is not a current count. Axios’s “Internet restricted in Iran as anti-government protests intensify” is dated 21 September 2022 — exactly four years old — and surfaced on a query about present-day Iranian restrictions. Amnesty International’s Security Lab study of Pegasus, published 17 July 2026, also ranks high on current queries. And CISA’s advisory AA26-097A on Iranian-affiliated actors exploiting programmable logic controllers, updated with the FBI and EPA on 22 July 2026, is an update to an April document. Anyone presenting it as September news is wrong.
The higher-risk composite is the water sector. A Viakoo “Daily OT Security News” digest dated 20 September 2026, syndicated through Security Boulevard, states that a ransomware group has launched a campaign against US water utilities via unpatched operational-technology flaws. It names no group, no utility, no number and no primary source; in that form it is not reportable. Around it sit four older items that a current search returns as though they were one event: SecurityWeek on an Israeli group’s claim — the word in the headline is “claims” — of a Lebanese water hack, 30 September 2024; SecurityWeek on disrupted Israeli irrigation control systems, April 2023; CyberScoop on the Iran-linked intrusion at a Pennsylvania water facility, 29 November 2023; and NPR’s piece of 12 August 2026. Five items spanning three years, none of them in this window.
On Iran’s connectivity, the record is clearer than the commentary. The blackout was documented by Chatham House on 26 January 2026, by Freedom Online Coalition members on 4 February, and by Human Rights Watch on 6 March. Restoration is equally documented: Al Jazeera reported expanded limited access on 20 April, NPR and Euronews reported Iranians back online on 28 May, and Al Jazeera again on 31 May described reinstated access with restrictions still in force for most users. The documented state since the end of May is restored connectivity under heavy filtering with applications blocked — not a blackout. No in-window NetBlocks, IODA or OONI measurement surfaced for Iran or the Gulf in this desk’s searches. That absence is a gap in the record, not evidence that nothing changed.
Assessment: The mechanism here is not deception, it is indexing. Anniversary material, vendor dashboards that update continuously and therefore always read as fresh, and aggregator digests with no original reporting all compete on equal footing with dated journalism in a search return. The same pressure is now shaping numbers: a GRIP analysis has put a twentyfold rise in Middle East ransomware into circulation, tracking a 16 September piece in The National, with no identified baseline year, sample or dataset. If that figure is derived from leak-site postings it measures attacker publicity, which inflates during conflicts because groups post opportunistically. Once a multiple like that is quoted twice it stops being asked for its base.