- calendar_today September 3, 2025
Two significant cyberattacks that have rocked Iran’s financial system are still being felt there. Believed to be in line with Israeli interests, the hacker group Predatory Sparrow has claimed responsibility for both attacks—one aimed at Sepah Bank, a significant financial institution connected to the Iranian military, and the other targeting the top bitcoin exchange Nobitex.
Still, these were not typical breaches.
Not stolen but rather destroyed, the attack on Nobitex claimed almost $90 million worth of cryptocurrencies. Leading blockchain analytics company Elliptic claims that the hackers poured the money into custom “vanity” wallet addresses, each starting with politically charged words like “FuckIRGCterrorists.” These wallets are meant to be irretrievable. From a cryptocurrency standpoint, they are black holes. Once sent there, assets are gone permanently.
“This was a political message masquerading as a cyberattack,” co-founder of Elliptic, Tom Robinson, said. “The hackers aimed not for profit. The bitcoin they pilfered has been essentially burned.
Predatory Sparrow charged Nobitex with being instrumental in Iran’s attempts to evade foreign sanctions. The group claimed the trade handled transactions for terror-linked groups including Hamas, the Houthis, the Islamic Revolutionary Guard Corps (IRGC), and Palestinian Islamic Jihad. Later on, Elliptic verified that blockchain information supports the link to approved companies.
After the hack, Nobitex—a main platform used by Iranian crypto enthusiasts—went dark. Its website is currently down. Thousands of users are still waiting to find out whether their accounts have been compromised; the exchange has not yet made a statement.
The second cyberattack arrived just hours later.
Predatory Sparrow claimed to have destroyed all internal Sepah Bank systems, among Iran’s most venerable and powerful financial institutions. The group produced records purportedly proving financial ties between Sepah’s military operations and Iran’s ballistic missile development, as well as nuclear funding.
“Who’s next?” they cautioned along with their announcement.
The website of Sepah Bank briefly failed, then came back later. Still, beneath the surface, all seems unusual. Living in Sweden, Iranian cybersecurity specialist Hamid Kashfi claimed to have heard from contacts in Iran that ATMs and online banking services linked to Sepah remain offline. People find they cannot access their money. Not only government agencies, but also people are being hit, Kashfi said. “The collateral damage is rather noteworthy.”
Predatory Sparrow has become known for starting some of the most disruptive cyberattacks on Iran recently. They closed the gas station payment systems across the nation in 2021. By adjusting control systems, they created molten metal that spilled and almost killed manufacturing workers in a dramatic attack on a steel plant in 2022. The group even produced a video of the event.
Though it claims to be an Iranian resistance group, most experts agree it is too structured, too competent, too equipped to run without outside support. The group runs under or alongside Israeli intelligence, according to the accepted wisdom.
This is more than just hacktivism. John Hultquist, head analyst of Google’s threat intelligence division, described strategic cyberwarfare. “Predatory Sparrow follows through instead of merely posing threats. Their discipline and deliberate nature are admirable.
These twin strikes represent more than just a financial loss; their significance is found in As a means of escape from economic sanctions, Iran has been turning more and more to cryptocurrencies; Nobitex was at the center of that ecosystem. Meanwhile, Sepah Bank is a pillar of Iran’s traditional financial system, particularly with relation to the military.
Predatory Sparrow did more than just create disturbance by destroying both. They warned both inside and outside of Iran that working with approved organizations might have actual, negative results.
“Caution: Associating with the regime’s instruments for evading sanctions… is bad for your long-term financial health,” they said as their sign-off message.





