Full Breakdown
Iran’s Banking System Hit by Limited Cyberattack Disrupting Four Major Banks
6/14/2026, 9:39:36 PM
Incident Overview
On Saturday, June 13-14, a limited cyberattack targeted the shared communications platform used by four state-owned Iranian banks—Bank Melli, Bank Tejarat, Bank Saderat, and the Export Development Bank of Iran. Technical teams detected unusual activity, activated preventive protocols, and temporarily halted mobile and online banking, ATMs, POS terminals and some card services. The Banking Coordination Council said no unauthorized access to customer data occurred and no information was deleted.
Background
The outage coincided with the final stage of U.S.–Iran peace talks mediated by Qatar and Pakistan, prompting concerns that cyber pressure could affect the negotiations.
Data & Statistics
Four banks—Bank Melli, Bank Tejarat, Bank Saderat, Export Development Bank of Iran—were affected; disruptions spanned five service categories: mobile banking, online portals, ATMs, POS terminals and card processing.
Affected Institutions
All four banks share a single telecommunications layer that routes transaction data nationwide, making the network a single point of vulnerability.
Technical Impact
Customers experienced outages in mobile and online banking, ATM withdrawals, POS transactions and some card functions. The Council’s probe identified a limited cyberattack on the shared network; no malware or data exfiltration was found.
Official Statements & Responses
The Banking Coordination Council said it acted swiftly to protect data and restore services, and that the infrastructure is now under expert control. Qatasi, secretary of the Coordinating Committee of state-owned banks, confirmed repair measures are underway. Authorities have not identified the attackers or disclosed their methods.
On-the-Ground Reports
Patrons reported delayed transactions and unavailable ATMs, prompting complaints on social media. The Council apologized for the inconvenience and pledged to restore services as quickly as possible.
Conflicting Reports & Gaps
All reports agree no customer data was compromised and the attack was limited. However, source 2 lists National Bank of Iran and Bank Tosee Saderat among the affected institutions, while other sources name Bank Melli, Bank Tejarat, Bank Saderat and the Export Development Bank of Iran, indicating a naming discrepancy. No source identifies the attackers or their methods.
Verbatim Quotes
- “Technical teams immediately implemented the necessary preventive and protective measures to protect customer data and the country's banking infrastructure after identifying unusual signs,” — Banking Coordination Council statement
- “Technical assessments confirmed that no unauthorized access to customer data occurred and no data leaks have been detected.” — Council announcement
- “So far, no customer data has been accessed without authorization, and there has been no data breach.” — Qatasi, secretary of the Coordinating Committee
- “Technical investigation indicates that this problem was caused by a limited cyberattack on these four banks and fortunately there has been no unauthorized access to customer data and no information leak,” — Council briefing
Outlook
Technical teams are hardening the shared network, adding security layers and monitoring for further anomalies. The incident highlights the vulnerability of centralized banking infrastructure and may shape Iran’s future cyber-defense policies as peace talks continue.
