Half of this week’s Iran cyber feed is dated between April and January
A vendor reference page, a six-month-old CISA advisory and dashboards still describing a blackout that ended in May are circulating as current. The one genuinely live shutdown figure is ten.
Several items ranking as fresh this week are not. FortiGuard’s threat-actor reference page for Handala — the pro-Palestinian, pro-Iran group that emerged in December 2023 — carries a publication stamp of 1 October 2026, but it is a static profile, not an incident report, and will almost certainly be cited as evidence of new Handala activity. The joint CISA/FBI advisory AA26-097A on Iranian-affiliated actors manipulating internet-exposed PLCs, HMIs and SCADA displays across US critical infrastructure is dated 7 April 2026, six months old. Live “Iran Internet Blackout” dashboards continue to describe the 8 January shutdown in the present tense; Wikipedia dates that blackout 8 January to 26 May, and NPR reported on 28 May that Iranians were back online under heavy restriction with traffic at roughly 40% of normal, citing Iranian cybersecurity analyst Amir Rashidi on continuing widespread disruption.
The figures that are actually current are smaller and less dramatic. Internet Society Pulse counted 10 ongoing internet shutdowns worldwide as of 1 October 2026 — the only shutdown number in this window that is genuinely of this window. Access Now’s #KeepItOn report, published 31 March 2026 and covering calendar year 2025, logged 313 shutdown events across 52 countries, with Myanmar highest for a second year at 95, 70 shutdowns coinciding with grave human-rights abuses, and $11.9bn in costs attributed to Russia’s shutdowns. Kaspersky’s GReAT team reported spyware attacks up 11% across the Middle East year-on-year, presented at its META security weekend and reported on 3 August — vendor telemetry, two months old, sample size undisclosed.
A SOCRadar dashboard entry stating that Jordan’s National Cybersecurity Centre confirmed blocking an Iranian attack on the national wheat silo management system is roughly five weeks old and is a vendor product rather than reporting; the NCC statement itself has not been published in any account retrieved here. Reuters' line that Iranian cyberattacks on Israel surged in 2026, attributed to Israel’s national cyber chief, dates to approximately late June and is recycled without a date with some regularity.
Assessment: This is the structural condition of the Iran cyber information space seven months into the war, not a bad week. Vendor landing pages and status dashboards update their timestamps without updating their content, and search ranking rewards the timestamp. The practical rule: any claim that Iran is currently dark requires IODA or Cloudflare Radar readings from this week, and nobody appears to have published them. The gap is being filled by pages that have not been recomputed since May. The same applies to Predatory Sparrow, silent since the campaign began on 28 February — absence of a vendor report is not evidence of absence, and in this environment it is barely evidence of anything.