A live tracker says Iran is dark; Iran came back online in May
The dashboard refreshes daily, so it reads as breaking. The shutdown it describes ended on 26 May 2026. The same mechanism is quietly ageing most of the Middle East cyber material circulating this week.
A tracker at state-of-iranblackout.whisper.security surfaces in a 72-hour sweep timestamped zero days old. It describes a near-total shutdown imposed on 8 January 2026 in response to protests driven by economic crisis, and says it aggregates IODA, Cloudflare Radar and RIPE RIS. It refreshes daily. The blackout it documents ran from 8 January to 26 May 2026. NPR reported on 28 May that Iranians were back online under heavy restrictions, with traffic at roughly 40 percent of normal and, per Iranian cybersecurity analyst Amir Rashidi, continuing widespread disruption. The Conversation established the comparative scale in January: longer than the 48.5-hour shutdown of June 2025, longer than the near-seven-day cut of November 2019, and more complete than the nightly mobile cuts of September–October 2022 because fixed-line was closed as well. All of that is real. None of it is new.
The same dynamic runs through the vendor layer. SOCRadar’s Iran–Israel/US cyber war dashboard carries undated entries under a continuously updated banner, including an assertion that Jordan’s National Cybersecurity Centre confirmed blocking an Iranian attack on the national wheat silo management system — with no date and no NCC statement linked. The same vendor’s April 2026 blog supplies the 4-percent-connectivity, IRNA-offline, Tasnim-defaced set that still circulates without its date. Positive Technologies' Gulf figures for H1 2026 — UAE 35 percent, Iran 17 percent, Saudi Arabia 15 percent of regional attacks — were published around 19–22 September and are being rewritten this week; they are vendor telemetry, not an incident count. The National, reporting CloudSek ransomware data on 16 September, said plainly that its figures were threat-intelligence indicators rather than confirmed successful attacks. That caveat is the exception.
Meta’s removal of an Iran-based network using generative AI to pose as ordinary Americans, reported by Axios on 27 August, involved 23 Facebook accounts and 11 Instagram accounts. Five weeks later, low-grade aggregators are still presenting it as a current takedown. The honest framing of 34 accounts is not that the operation was trivial but that persona networks are cheap to stand up and cheap to lose, which is precisely why headcount is a poor measure of anything.
Assessment: A dashboard converts a standing condition into an apparent event, and a daily refresh does the rest. The incentives are aligned and unremarkable: vendors need recency to sell detection, aggregators need volume, and regional desks need a chart. The state-level benefit is the one worth watching. Recycled alarm devalues real alarm, and an audience that has read four versions of the same blackout will not react to the fifth, actual one. The remedy is mechanical, not editorial judgement: put the date of the measurement on the tile, not the date of the page, and name whose telemetry it is.