Iran’s internet blackout ended in May, and this week’s search results still read as current
The Iran and Israel cyber material surfacing with recent-looking framing this week is five to nine months old. The recycling matters because it sets the baseline readers carry into whatever happens next.
Iran’s near-total shutdown of internet and communications services began on 8 January 2026, according to the Freedom Online Coalition’s joint statement of 4 February, issued on the twelfth day of the 2025–2026 protests, with blackouts in Tehran and disruptions in Isfahan, Lordegan, Abdanan and parts of Shiraz. Open-source timelines put its end on 26 May — four months and eighteen days. Human Rights Watch documented a further significant drop in traffic on 28 February indicating a nationwide blackout following US strikes; the publication date is itself unresolved, with the URL dated 6 March and the search index returning 26 March. Chatham House’s analysis is from 26 January. The Starlink jamming and account-blocking coverage is from January and March. A 2019 TechCrunch piece on the fuel-protest shutdown, carrying NetBlocks percentages from that year, ranks alongside all of it. We have checked no connectivity data for 20–23 September and are therefore saying nothing about Iran’s network state now.
The breach file runs the same way. The two-petabyte Israeli data-breach figure attributed to the INCD is from 20 February; the Iran-linked claim on Israel’s largest healthcare network is from 25 February; the leaked documents attributed to a former Israeli army chief are from 10 April — and with the partial exception of the INCD number, these are claims by the attacking side rather than confirmed incidents. The CSIS incident tracker records that in March 2026 Handala, an Iranian-linked group, claimed an attack on medical-device maker Stryker triggering simultaneous factor resets on over 200,000 corporate devices across 79 countries, framed as retaliation for a US strike on a girls' school in Minab; that figure originates with the group, not with Stryker. NBC News reported on 2 September that Iran attempted cyberattacks on US infrastructure, sourced to unnamed officials in its own headline. Middle East Eye’s report on suspected spyware against Turkish ministers' phones is from around 9 September and still says suspected.
Two YouTube videos are ranking on these queries — one claiming Russian hackers wiped Israeli military data in May, one claiming 50,000 leaked Israeli intelligence emails in March. Neither is citable and neither should be characterised, even to debunk. They are noted here only because any researcher working these search terms will hit them inside the first page of results, and because they sit in the same result set as Human Rights Watch and the Freedom Online Coalition with nothing visually distinguishing them.
Assessment: The incentive structure explains most of this. Attacking groups inflate because the claim is the payload, and a 200,000-device figure costs nothing to assert and months to disprove. Search ranking rewards recency signals over publication dates, so a nine-month-old shutdown reads as live. And desks with an empty in-window queue — ours included this week — are precisely the ones that reach for circulating material. The operational rules are unglamorous: date-stamp every NetBlocks percentage before it goes near a draft, name the anonymity when a story rests on unnamed sources, and never let a claimed breach become a reported one in the transition from source to summary. The live thread from today’s lead is whether that Check Point management-server flaw produces a regional incident. If it does, expect the claim to arrive before the confirmation.