Menu
Browse

Cyber Incident Victim: Iran

Date:

Sep 2022

Location:

Iran

Summary

A cyberattack targeted Iran's central bank, compromising systems and disrupting financial operations. Authorities confirmed the breach but did not disclose the attackers' identity or specific impacted services. The incident highlighted vulnerabilities in critical financial infrastructure, though officials provided limited details on the extent of damage or recovery measures. While the attack caused temporary operational disturbances, no further public statements elaborated on data compromises or long-term consequences for banking stability.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On September 1, 2022, Iranian authorities confirmed a cyberattack targeting the Central Bank of Iran (CBI), disrupting financial services in Tehran and other regions. The attack impacted online banking platforms and ATM networks, causing widespread transaction failures and service outages for customers. Initial reports indicated unauthorized access to banking infrastructure, though the full technical scope remained under investigation. A hacktivist group calling itself "Adalat Ali" (Justice of Ali) claimed responsibility, alleging it had exfiltrated sensitive customer data, including account details and transaction records. The disruption persisted for multiple days, affecting interbank payment systems and delaying salary disbursements for some government employees. The CBI issued public advisories urging customers to avoid digital transactions until services stabilized, while branch offices experienced increased foot traffic due to the online outages.

Cyber Incident Image

Iran’s National Center for Cyberspace (NCC) acknowledged the incident and initiated a coordinated response with the CBI’s internal cybersecurity team. Forensic analysis revealed compromised servers hosting customer databases, though officials did not confirm the extent of data theft. Emergency patches were deployed to isolate affected systems, and backup servers were activated to restore limited functionality within 72 hours. The NCC attributed the attack to "foreign-based actors" but withheld technical attribution details. Service recovery remained partial for over a week, with lingering ATM cash withdrawal limits and delayed interbank transfers. The incident prompted temporary suspensions of international payment processing via Iranian banks, exacerbating economic strain amid existing sanctions. Public statements emphasized ongoing investigations but disclosed no further specifics regarding attacker methodologies or confirmed data breaches.

Sources
Sources available to members
1 source