On day 217 of the Iran war, the cyber record is three months stale and the gap is itself the story
The heaviest Iran–Israel cyber reporting dates from January to March 2026. Since roughly July the public record has produced vendor dashboards and market-sizing, not incidents — and nobody has explained which of the two things stopped.
A running tracker at globalsecurity.org labels 2 October as “Day 217” of the Iran war, placing its start in late February or early March. The documentary record of the cyber dimension is front-loaded almost exactly to that opening. NBC News reported an Iran-linked claim against the medical-device maker Stryker, which said its “Microsoft environment” was disrupted, around mid-March. Axios published its explainer on 11 March. Haaretz reported a hack-and-leak reaching Netanyahu’s inner circle on 7 January, and Shin Bet’s account of hundreds of Iranian operations against Israeli officials on 12 February. The most recent Iranian-themed CISA advisory in our sweep is AA26-097A, on exploitation of programmable logic controllers in US critical infrastructure, roughly 74 days old. Unit 42’s “Screening Serpens” research is about 114 days old. No in-window CISA, NCSC-UK or Israeli INCD advisory surfaced at all.
What has arrived instead is continuously edited commercial inventory. SOCRadar maintains a live Iran–Israel cyber conflict dashboard whose latest edit is stamped roughly 2 October — a page touch, not necessarily an incident, and a format that by design aggregates attacker claims alongside confirmed intrusions. The available statistics come from the same commercial layer: Calcalist reported in mid-September that one in six geopolitical cyberattacks worldwide in H1 2026 targeted Israel, without naming the underlying vendor; Positive Technologies, a Russian firm under US sanctions, is cited for a claim that half of Gulf attacks in H1 targeted the UAE and Saudi Arabia. AGBI published Gulf-datelined analysis this week on protecting corporate data in wartime. Three of these four numbers originate with vendors selling into the Gulf during a war.
Assessment: Two explanations fit a three-month gap, and they point in opposite directions. Either Iranian operational tempo genuinely fell after the spring campaign, or disclosure did — governments and victims stopping their reporting while the activity continued. Nothing in the public record distinguishes them, and a vendor dashboard edited on 2 October cannot, because its refresh rate measures the vendor’s publishing schedule rather than the adversary’s. Our own sweep was English-only and never reached NetBlocks, IODA or Cloudflare Radar, so read the silence on Iranian throttling as a hole in our net, not a fact about Iran. The honest position this weekend is that the desk does not know, and neither does anyone selling a chart.