October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Iran Says Cyberattack Disrupted Four Banks as Wider Banking Outages Follow

Iran confirmed a cyberattack disrupted services at four banks in June 2026. A later outage affected more institutions, but data theft, account manipulation and attribution remain unproven.
From TheFinanceBase Team6 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Iran acknowledged on June 14, 2026, that a cyberattack disrupted electronic and card-related services at four major banks. Officials described the incident as a “limited cyberattack” against shared communications infrastructure and said customer information was not accessed or deleted. That assurance had not been independently verified in the reporting available at the time.

A separate disruption reported on June 23 affected services at as many as eight banks. The later outage may have been related, a separate attack, or a precautionary shutdown; available reports do not establish which. The evidence confirms a serious availability incident, but not a nationwide banking collapse, stolen deposits, altered balances, or a publicly proven attacker.

What happened on June 13 and 14?

Reports of service problems emerged around Saturday, June 13. On Sunday, June 14, Iran’s Banking Coordination Council said a cyberattack had hit shared communications infrastructure used by four banks. The council’s account was reported by Anadolu Agency and other outlets.

“Shared communications infrastructure” does not necessarily mean that each bank’s core account database was breached. It can refer to systems connecting banks with payment processors, card authorization, ATMs, point-of-sale terminals, mobile and online banking gateways, authentication services, or interbank messaging. If that common layer is compromised or isolated, several banks can lose customer-facing services at once even while account ledgers remain intact. That is an architectural explanation of the reported impact, not a confirmed description of the attackers’ method.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The four banks initially named

Bank How it was identified in reports
Bank Melli Iran Named by Iranian banking authorities
Bank Tejarat Named by Iranian banking authorities
Bank Saderat Iran Named by Iranian banking authorities
Export Development Bank of Iran Also translated in some reports as Bank Tose’e Saderat

The differing English names for the fourth institution can make reports appear to list different banks. They refer to the same bank in this context.

Which banking services were disrupted?

Reports described interruptions affecting some combination of mobile-banking applications, online banking, ATMs, point-of-sale terminals, card transactions, and other electronic services. The exact effect and recovery time varied by bank and by stage of restoration.

The available evidence does not support saying that every Iranian bank stopped operating. Nor does it establish that every service at the four named banks failed simultaneously. A shared dependency can, however, produce a broad customer outage from a relatively contained technical point of failure.

Was customer money or data stolen?

Confirmed or widely reported: Customers experienced significant service disruption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Iranian officials said: There was no unauthorized access to customer information and no deletion of information.

Rank #2
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration

Not independently established in the available reporting: Data exfiltration, stolen deposits, changed balances, ransomware payment, or destructive wiping.

The distinction matters. Availability, confidentiality, and integrity are separate security objectives. An attack can prevent a customer from withdrawing cash or completing a payment without proving that personal data was copied or account balances were changed. Conversely, an official “no data access” statement is not the same as an independently published forensic finding. Reuters’ report as republished by Yahoo Finance likewise presented the position as an Iranian official claim.

What happened in the broader June 23 outage?

On June 23, a second and broader disruption was reported. Iran International said services at as many as eight banks were affected, with customers reporting slow or unavailable electronic services and disrupted card transactions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Banks named in June 23 reports Status of the report
Pasargad, Melli, Mellat, Sepah, Tejarat, Saderat, Tose’e Ta’avon and Resalat Reported as affected in the later disruption; the relationship to the June 14 incident was not established

Iran’s Informatics Services Corporation reportedly took card-based services temporarily offline as a protective measure. Iran’s Cyber Command later described disruptions at several banks as a cyberattack on banking infrastructure and said core banking systems were not directly connected to the public internet, according to IranWire.

Taking card services offline to prevent unauthorized access can itself create a large outage. It does not, by itself, prove that attackers manipulated account ledgers or reached core banking databases. The June 23 event should therefore be reported separately unless investigators later link it to the June 14 incident.

Why shared infrastructure creates concentration risk

Centralized networks and payment dependencies improve interoperability and can reduce operating costs. They also create a common failure point.

  • A single compromised or isolated dependency can affect multiple banks at once.
  • ATM withdrawals, card authorization, merchant payments and mobile access may fail together.
  • Emergency isolation can protect data while extending the customer outage.
  • Merchants, payroll systems, fuel stations and government-payment channels may feel secondary effects.
  • Restoration can be slower if banks share communications, authentication or payment providers.

For customers, the practical lesson is that a service outage is not proof that money has vanished. For banks and payment operators, it shows why independent recovery paths, segmentation and tested alternatives matter as much as perimeter defenses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who was responsible?

No reliable attribution was established in the material available for the June 2026 outages. The reporting does not prove involvement by Israel, the United States, a named hacker group, Iran’s political opponents or a criminal ransomware organization.

Attribution is especially easy to overstate because Iran previously experienced a publicly claimed attack on Bank Sepah. In June 2025, the pro-Israel group Predatory Sparrow, also known as Gonjeshke Darande, claimed responsibility for an incident that disrupted Bank Sepah services; reporting also connected that episode with disruption at fuel stations. Axios reported on that 2025 case. It is separate context, not evidence that the same actor conducted the June 2026 incidents.

What the incident means for personal finances

A temporary inability to use an app, card or ATM is an availability problem, not automatically a balance problem. During an outage, customers should rely on verified bank notices, keep receipts for failed or duplicated transactions, and check statements after systems recover. They should not assume that a delayed card authorization means a payment permanently failed or permanently completed.

Financial institutions face a wider set of risks: merchant settlement delays, payroll interruptions, branch congestion, fraud during restoration, and loss of public confidence. A bank’s ability to restore clean systems and reconcile transactions is therefore as important as detecting the initial intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What remains unknown

  • How long each bank’s services were unavailable and whether ATM withdrawals remained possible throughout.
  • Whether any customer records, credentials, tokens or encryption keys were accessed.
  • Whether the June 23 disruption was an escalation, a separate attack or a defensive shutdown linked to the first event.
  • Whether banks restored from clean backups and rotated credentials or keys.
  • Whether regulators ordered emergency measures or published a post-incident forensic report.
  • Whether customers later reported unauthorized transactions or unreconciled balances.

Those questions require forensic evidence, bank-by-bank timelines and regulator disclosures. The official statements available in the cited reports do not answer them.

What financial institutions should learn

  1. Map dependencies. Identify shared networks, payment processors, authentication services, communications providers and recovery sites.
  2. Segment critical systems. Keep customer-facing services, administrative networks and core banking systems separated with tightly controlled access.
  3. Maintain independent recovery paths. Test alternatives for card authorization, ATM access, branch operations and emergency communications.
  4. Monitor continuously. Detection tools are useful only when alerts are investigated and response authority is available around the clock.
  5. Protect immutable backups. Recovery copies must not be reachable through the same compromise that affects production systems.
  6. Exercise simultaneous outages. Tabletop tests should include a shared-provider failure affecting several institutions at once.
  7. Preserve evidence. Retain logs and forensic images before restoration overwrites useful evidence.
  8. Control third-party risk. Contracts should specify incident notification, logging, recovery-time objectives and forensic access.

Products from vendors such as CrowdStrike, IBM, Microsoft and AWS can support monitoring or cloud controls, but no single endpoint, SIEM or cloud-security product is a substitute for resilient architecture and tested recovery. CrowdStrike’s published pricing, for example, ranges from entry-level per-device plans to sales-led managed services at its pricing page; IBM directs buyers to an estimator and sales process for QRadar EDR at its pricing page; Microsoft Defender Experts information is available at Microsoft’s overview; and AWS Security Hub uses usage-based pricing described at AWS’s pricing page. These commercial options are not evidence that any vendor was involved in Iran’s incident.

Bottom line: serious disruption, limited public proof

Iran experienced a serious multi-bank service disruption that authorities officially attributed to a cyberattack on June 14, 2026. The initial event involved Bank Melli, Bank Tejarat, Bank Saderat and the Export Development Bank of Iran, while a separate June 23 outage reportedly affected more institutions. Public reporting establishes disrupted access and defensive shutdowns, but it does not independently prove customer-data theft, account manipulation, ransomware, a nationwide banking collapse or responsibility by a specific foreign actor.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
Network Security, Firewalls, and VPNs: . (Issa)
Network Security, Firewalls, and VPNs: . (Issa)
New Chapter on detailing network topologies; Increased coverage on device implantation and configuration
$57.99
SaleBestseller No. 3

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.