NEWS

Iran’s Nobitex Hit by $90M Cyberattack

A pro-Israel hacking group claims a $90 million cyberattack on Iran’s largest crypto exchange, Nobitex, destroying the funds in a politically charged act. This escalates the shadow war between the two nations, impacting ordinary citizens.

By
LNGFRM Team
Published June 18, 2025
Stylized illustration of a building under a blue sky, with multiple hockey pucks and white angular streaks floating above. A dark blue road with dashed lines extends upwards from the building.
Illustration by Addison Smith for LNGFRM

The digital battlegrounds of the Middle East have once again flared, witnessing an audacious cyber assault that saw an estimated $90 million vanish from Iran’s largest cryptocurrency exchange, Nobitex.

This was no mere heist for financial gain; it was a strategic, politically charged blow, claimed by the pro-Israel hacking collective known as “Predatory Sparrow,” an entity that increasingly defines the cutting edge of modern, asymmetric warfare.

The cyberattack, executed on Wednesday, struck at a critical financial nerve for Iran, a nation grappling with the stranglehold of international sanctions.

Predatory Sparrow, through a Farsi post on X, declared their intent explicitly: to target Nobitex, which they alleged was a conduit for Iran to circumvent these very sanctions.

But what truly set this operation apart was the hackers’ extraordinary next move.

Rather than pocketing the vast sum, cybersecurity experts suggest the digital loot was effectively incinerated, transferred to digital “wallets” beyond the hackers’ control.

Some of these destination accounts were even reportedly branded with an expletive referencing Iran’s Islamic Revolutionary Guard Corps (IRGC), turning a financial theft into a potent, public act of defiance and psychological warfare.

Nobitex, acknowledging the breach, swiftly moved to suspend access to its platform “as a precaution,” a tacit admission of the severity of the intrusion.

Crypto-tracking firms Elliptic and TRM Labs independently corroborated the theft, confirming the substantial sum had indeed been siphoned off and redirected into these seemingly irretrievable digital black holes.

This unusual tactic suggests a motivation far removed from conventional cybercrime, painting a picture of an operation driven by political objectives rather than avarice.

This crypto-heist was not an isolated incident but part of a coordinated barrage.

Just a day prior, Predatory Sparrow had already claimed responsibility for destroying data at Iran’s state-owned Bank Sepah, justifying the action by asserting that IRGC members utilized the bank’s services.

The ripple effects of these digital incursions were immediate and tangible for ordinary Iranians.

The state-affiliated Fars news agency issued a warning about potential disruptions to banking services at gas stations, a vital infrastructure point.

A source in Tehran described a frustrating odyssey, visiting nearly a dozen ATM machines over two days, only to find them either non-functional or completely depleted of cash.

These are not just abstract cyberattacks; they are economic disruptions that touch the daily lives of citizens.

These twin cyberattacks underscore a significant escalation in the protracted, often clandestine, shadow war between Israel and Iran.

For years, the two arch-enemies, or their proxies, have engaged in a digital arms race, conducting espionage, data destruction, and infrastructure disruption for tactical advantage.

Predatory Sparrow has emerged as a prominent player in this high-stakes game over the past five years, boasting a track record of spectacular interventions, including previously crippling an Iranian steel mill and disrupting payment systems at Iranian gas stations.

Their operations are characterized by precision, audacity, and a flair for dramatic public claims.

The precise identity of Predatory Sparrow remains shrouded in mystery, yet their actions speak volumes.

While they present themselves as anti-government Iranian hacktivists, the consensus among cybersecurity experts leans heavily towards a more direct connection to Israeli intelligence or state-sponsored operations.

This ambiguity itself is a weapon, allowing for deniability while maximizing the psychological impact.

It blurs the lines between independent activism and state-sanctioned aggression, making it difficult to ascertain the true origin and scope of the threat.

However, the collateral damage of such sophisticated cyber warfare rarely respects these blurred lines.

Hamid Kashfi, a Farsi-speaking cybersecurity expert, highlighted a critical, often overlooked aspect of these attacks: despite Predatory Sparrow’s stated aim of targeting IRGC assets, the Nobitex hack could disproportionately affect ordinary Iranians.

In an economy stifled by sanctions and shrinking access to traditional financial resources, many Iranians have increasingly turned to cryptocurrency as a lifeline, a means to preserve wealth and conduct transactions.

This makes them unwitting, and often vulnerable, casualties in a conflict not of their making.

Beyond the direct financial and infrastructural damage, a significant component of the recent cyber activity in the region is aimed squarely at sowing panic and eroding public trust.

As Israel and Iran trade missile strikes, a parallel campaign of psychological warfare unfolds in the digital realm.

Israelis have reported receiving mass text messages impersonating authorities, falsely claiming that bomb shelters are unsafe – a clear attempt to induce fear and chaos.

Conversely, the Iranian government has warned its citizens against using WhatsApp, alleging that Israel was collecting intelligence from these encrypted chats, a claim Meta, WhatsApp’s parent company, has vehemently denied, emphasizing their end-to-end encryption protocols.

This latest chapter in the Israel-Iran cyber conflict illustrates a profound shift in modern warfare.

The battlefield is no longer confined to physical borders or conventional armaments.

It extends into the invisible networks that underpin economies and societies, where a few lines of code can inflict economic paralysis, sow widespread panic, and destabilize a nation more effectively than a conventional strike.

The $90 million “disappearance” from Nobitex is more than just a theft; it is a stark, public declaration of intent, a calculated act designed to send a chilling message that in this new era of digital conflict, even the most seemingly secure financial arteries are vulnerable, and the consequences can echo far beyond the immediate target.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like

Mohit Bansal: On Zero-Headcount Security Scaling

Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.

By Mike Malone
Published June 30, 2026
© 2026 LNGFRM. All rights reserved.