CSIDB logo
Incident

Bank of Israel

Incident posture

Attack window
Apr 2022
Location
Israel
Status
Historical
CIA posture
Available to members
Updated
2026-01-19 02:10

Linked entities

Victim
Bank of Israel
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Apr 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A financial institution faced claims by Iranian-linked hackers who asserted unauthorized access to its interbank transfer network and customer accounts. The country’s National Cyber Directorate and the bank itself refuted these allegations, stating no evidence of compromise was found in their systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 25, 2022, a hacker group allegedly linked to Iran publicly claimed to have compromised the Bank of Israel's interbank money transfer network. The attackers asserted they had infiltrated the central banking system responsible for processing transactions between Israeli financial institutions and subsequently gained unauthorized access to individual customer accounts. This announcement surfaced through undisclosed channels frequented by cybercriminal entities, though the group provided no verifiable evidence to substantiate their intrusion claims. The targeted system facilitates critical financial operations across Israel's banking sector, handling sensitive transactional data and personal account information.

Israel's National Cyber Directorate and the Bank of Israel immediately issued coordinated statements refuting the hackers' assertions. Both entities conducted forensic examinations of the interbank network infrastructure, transaction logs, and account access records. Their investigations found no technical evidence of unauthorized system penetration, data exfiltration, or anomalous account activity consistent with the claimed breach. The Bank of Israel confirmed the operational integrity of its financial transfer systems remained uncompromised throughout the alleged incident period. No disruptions to banking services, fraudulent transactions, or customer data leaks were reported or detected by monitoring mechanisms. The authorities maintained standard cybersecurity protocols without implementing emergency containment measures, as their analysis concluded no actionable threat materialized from the unsubstantiated claims.

Sources

Sources available to members: 1 source.

CSIDB