An Eight-Year-Old Pegasus Count Keeps Surfacing With a 2026 Date Stamp
The desk’s own retrieval this weekend returned old spyware and influence-operation research carrying recent date metadata, and the error ran consistently in one direction: forward.
Two cases are unambiguous. Citizen Lab’s “HIDE AND SEEK: Tracking NSO Group’s Pegasus Spyware to Operations in 45 Countries” came back with a page age of 24 July 2026. It is Citizen Lab’s 2018 infrastructure-scanning report, and the “45 countries” figure is an eight-year-old count of scanning results, not a current census of deployments. Separately, Time’s “Meta Takes Down ‘Largest Ever' Chinese Influence Operation” was returned with a page age of 13 April 2026; the story’s URL slug and subject matter place it in 2023, around Meta’s Spamouflage removals, and a syndicated result in the same cluster carried the “close to 8000 Facebook accounts” figure consistent with that 2023 action. In neither case does the document misdate itself. The date is added downstream, by the retrieval layer.
Beneath those two sit a larger haul of material returned under September-2026 queries that is openly older on its face: a Times of Israel report on an Israeli Cyber Directorate phishing warning dated 26 December 2023; a Middle East Eye report on Pegasus victims filing a criminal complaint with the Metropolitan Police, 19 September 2024; Haaretz on an Iranian leak of data concerning Israelis with military ties, 9 July 2025; an Outpost24 write-up of hacktivist activity around the Israel–Iran confrontation, 27 November 2025; and Aerospace Global News counting “already 10 major cyberattacks on airlines, airports in 2025 so far”, dated 10 August 2025. The Files did not open these pages in full this weekend, and cannot yet say whether the forward-dating tracks one crawler, one set of publishers, or the whole index. What can be said is that the pattern is directional.
For the record, the desk logged no independently verifiable incident on this beat between Thursday 24 and Sunday 27 September: no wiper, no hack-and-leak, no confirmed critical-infrastructure disruption, no platform takedown announcement, no new vendor APT publication datable to those four days. Two items plausibly sit inside the window and neither has been read: a Security Boulevard aggregation page, “Daily OT Security News: September 26, 2026”, which is an aggregator rather than primary reporting, and a Citizen Lab post noting that UN reports citing its submissions had been published, returned with a page age of roughly 24 September. Both are leads. Neither is a finding, and the desk is not treating them as one.
Assessment: Numbers are the most portable part of any security report and the first thing to shed its date. “45 countries” survives because it is quotable; the 2018 methodology that produced it does not travel with it. The incentive structure rewards this — vendors, ministries and platforms all want a current threat picture, and a figure with a fresh timestamp attached by a crawler reads as current. The practical test this week is simple: if a brief, a briefing or a ministerial statement cites forty-five countries for Pegasus without saying 2018, whoever wrote it searched rather than read. That is a claim about retrieval, not about NSO.