/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A cyberattack claimed by pro-Israel hacktivist group Predatory Sparrow has reportedly disrupted services at Iran's state-owned Bank Sepah, including its website

The attack introduces a clear cyber element with immediate consequences for the country's critical infrastructure amid a growing conflict between Israel and Iran.

CyberScoop Matt Kapko

Context & Ripple Effects

Predatory Sparrow has previously been associated with unusually aggressive attacks on Iranian civilian targets, while an earlier claimed attack disrupted service at roughly 70% of Iran’s gas stations. The Bank Sepah incident extends that pattern from a public-facing service into a state-owned financial institution.

The episode sits in the increasingly public Iran-Israel cyber conflict, where cyber operations have repeatedly imposed visible disruptions on civilian life and critical services rather than remaining confined to intelligence collection.

First-order effects

  • Bank Sepah users and staff face an immediate service disruption, including loss of access to the bank’s website, while the bank must prioritize restoration and incident response.
  • The claimed operation gives Predatory Sparrow another high-visibility target following its prior attacks on Iranian civilian targets, increasing pressure on Iranian state-service operators to treat public-facing systems as active conflict exposure.

Second-order effects

  • Iranian financial and critical-infrastructure operators are likely to reassess external-facing defenses and continuity procedures, particularly after the nationwide gas-station disruption demonstrated how cyber incidents can rapidly become public-service failures.
  • The attack raises the incentive for retaliatory or disruptive activity by Iran-aligned operators, consistent with coverage of Iran’s cyber apparatus expanding targeting and influence tactics; attribution claims, however, remain a central source of escalation risk.

Third-order effects

  • If attacks on civilian-facing state services continue, cyber operations will become a more routine means of imposing domestic economic and political costs during regional conflict, blurring the boundary between military pressure and everyday infrastructure disruption.
  • The durable challenge is ecosystem cyber defense: governments and state-linked operators will need resilience across banks, utilities, transport, and public communications, not only perimeter protection for individual institutions.

The trend: The incident is one data point in the normalization of public, reciprocal cyber disruption against civilian-facing infrastructure in the Iran-Israel conflict.

Discussion

  • @ericjgeller.com Eric Geller on bluesky
    Pro-Israel hacktivists have taken credit for disrupting the systems of Iran's Bank Sepah, claiming it helped Tehran circumvent sanctions and finance terrorist groups. techcrunch.com/2025/06/17/p...
  • @ericjgeller.com Eric Geller on bluesky
    👀 “We thank the brave Iranians whose help made this operation possible.” x.com/GonjeshkeDar...  [image]
  • @cyberscoop @cyberscoop on bluesky
    Iran's Bank Sepah disrupted by cyberattack claimed by pro-Israel hacktivist group.  The attack introduces a clear cyber element with immediate consequences for the country's critical infrastructure amid a growing conflict between Israel and Iran. via @mattkapko.com cyberscoop.com…
  • @nobitexmarket Nobitex on x
    [Translated] Announcement Regarding Security Incident This morning, June 18, our technical team identified signs of unauthorized access to a portion of our notification infrastructure and hot wallet.  Immediately upon detection, all access was halted, and our internal security te…
  • @gonjeshkedarand @gonjeshkedarand on x
    Destruction of the infrastructure of the Islamic Revolutionary Guard Corps “Bank Sepah” We, “Gonjeshke Darande”, conducted cyberattacks which destroyed the data of the Islamic Revolutionary Guard Corps' “Bank Sepah”. “Bank Sepah” was an institution that circumvented [image]
  • @zachxbt @zachxbt on x
    The crime supercycle is indeed very real. While it's true the industry has historically been ripe for abuse it has noticeably increased since politicians launched meme coins and numerous court cases were dropped further enabling the behavior. Laundering groups and small OTC [imag…
  • @rgb_lights Rob Joyce on x
    Predatory Sparrow's past cyber attacks on Iranian steel plants and gas stations have demonstrated tangible effects in Iran. Disrupting the availability of this bank's funds, or triggering a broader collapse of trust in Iranian banks, could have major impacts there.
  • @johnhultquist John Hultquist on x
    Predatory Sparrow, or Gonjeshke Darande, is taking credit for cyberattacks on Iranian banks. Despite appearances this actor is not all bluster. [image]
  • @nobitexmarket @nobitexmarket on x
    Official Statement Nobitex Security Incident — June 18, 2025 Earlier today, June 18, Nobitex identified unauthorized access to parts of its infrastructure, specifically affecting our internal communication systems and a portion of our hot wallet. Immediately upon detection, all
  • @gonjeshkedarand @gonjeshkedarand on x
    Caution: Associating with the regime's instruments for evading sanctions and financing its ballistic missiles and nuclear program is bad for your long-term financial health. Who's next? https://x.com/...
  • @rgb_lights Rob Joyce on x
    Predatory Sparrow strikes again. This time they drained funds from an Iran-based crypto exchange. Beyond theft, they targeted trust, undermining a key tool Iran uses to evade sanctions. Nobody with options will keep crypto assets there now.
  • @ryangrim Ryan Grim on x
    The Israeli-linked hacker group Predatory Sparrow has claimed credit for hacking two major Iranian banks with links to the military, but which are also used heavily by civilians. They claim to have wiped out their data which would be catastrophic for Iranian society if true.
  • @hkashfi Hamid Kashfi on x
    Following Sepah Bank hit, Sparrows hit a large Iranian exchange and sucked up $47M. They're not exactly wrong about the mentioned affiliation though. Multiple cases and sources exist that highlights them being the favorite upstream money shop of “places of interest”.
  • @nobitexmarket @nobitexmarket on x
    Follow-up on Nobitex Security Incident — June 18, 2025 As previously announced, on the morning of Wednesday, June 18, Nobitex detected unauthorized access to part of its infrastructure — specifically affecting internal communication systems and a segment of the hot wallet
  • @0xprotonkid @0xprotonkid on x
    Update: The hacker group known as Gonjeshke Darande (Predatory Sparrow) takes credit for the attack on Nobitex. Source: Zachxbt [image]
  • @gonjeshkedarand @gonjeshkedarand on x
    [video]
  • @talbeerysec Tal Be'ery on x
    The Predatory Sparrow group just burned $47M of cryptocurrency taken from Iran Nobitex exchange into the BURNER address TKFuckiRGCTerroristsNoBiTEXy2r7mNX Why is it a burner 👇
  • @thegrugq Thaddeus E. Grugq on x
    What is the air speed of an unladen Predatory Sparrow?
  • @jewishwarrior13 Raylan Givens on x
    🚨 BREAKING🚨The hacker group “The Predatory Sparrow,” which is affiliated with the Israeli security establishment and is behind some of the major cyber attacks against Iran in recent years, said in a statement: “In a cyber operation, we destroyed all the data infrastructure of a
  • @vodkapundit Stephen Green on x
    If Predatory Sparrow made a copy of IRGC's financials before crashing the bank, maybe they could turn it over to @DataRepublican so everybody might see where the money went.
  • @mayazi Maya Zehavi on x
    The hacker group “predatory Sparrow” claims responsibility for hacking Iran's bank Sepa is now publishing documents that reveal how the banks' AML helped the IRGC & Kids force access banking.
  • @nobitexmarket @nobitexmarket on x
    Follow-up on Nobitex Security Incident — June 18, 2025 As part of our ongoing response to the recent security incident, we would like to provide the latest update: Nobitex's technical and security teams continue to investigate the root cause of the incident and are actively
  • @mayazi Maya Zehavi on x
    Predatory Sparrow hits again. $82m stolen hacked from Nobited, the Iranian exchange, but the real leverage is the source code & client list. How many ppl from inside he regime hold crypto funds to bypass sanctions & hide their funds from the regime! [image]
  • @craiu Costin Raiu on x
    The Predatory Sparrow group just burned $47M of cryptocurrency taken from Iran Nobitex exchange into the “vanity” address TKFuckiRGCTerroristsNoBiTEXy2r7mNX. 108375 transactions in a couple of minutes - https://usdt.tokenview.io/...
  • @osint613 @osint613 on x
    BREAKING 🔴🔴🔴 Israeli-linked hacker group “Predatory Sparrow” wiped out 95% of assets on Iran's Nobitex crypto exchange. Nobitex was reportedly used by Tehran to evade sanctions through crypto. Wallet balances plunged from $1.8 billion to just $100 million. [image]
  • @netblocks @netblocks on x
    ⚠️ Confirmed: Analysis of telemetry shows a significant reduction in internet traffic in #Iran; the incident comes amid an escalating conflict with Israel and is likely to limit the public's ability to access information at a critical time 📉 [image]
  • @netblocks @netblocks on x
    ⚠ Confirmed: Metrics show a disruption to internet connectivity in the central and southern governorates of the #Gaza Strip; Operator Paltel attributes the outage to a cut in one of the main routes due to ongoing aggression 📉 [image]
  • @negahdari_s Soroush Negahdari on x
    Earlier, @GhonchehAzad and I received reports from Tehran, Gilan, Mazandaran, Isfahan & Khuzestan of major internet slowdowns. VPNs are disrupted, WhatsApp access restricted. State TV warned today against using WhatsApp. Iran confirmed slowdowns yesterday, citing cyber threats [i…
  • r/worldnews r on reddit
    Iran plunged into a near-internet blackout during deepening conflict