Iran Pays Millions in Ransom to End Cyberattack on Banks

Iranians at a bank branch in Tehran (IRNA)
Iranians at a bank branch in Tehran (IRNA)
TT

Iran Pays Millions in Ransom to End Cyberattack on Banks

Iranians at a bank branch in Tehran (IRNA)
Iranians at a bank branch in Tehran (IRNA)

A massive cyberattack that hit Iran last month threatened the stability of its banking system and forced the country's regime to agree to a ransom deal of millions of dollars, POLITICO reported on Thursday.

The newspaper said an Iranian firm paid at least $3 million in ransom last month to stop an anonymous group of hackers from releasing individual account data from as many as 20 domestic banks in what appears to be the worst cyberattack the country has seen, quoting industry analysts and western officials briefed on the matter.

A group known as IRLeaks, which has a history of hacking Iranian companies, was likely behind the breach, the officials said.

The hackers are said to have initially threatened to sell the data they collected, which included the personal account and credit card data of millions of Iranians, on the dark web unless they received $10 million in cryptocurrency, but later settled on a smaller sum.

Iran’s authoritarian regime pushed for a deal, fearing that word of the data theft would destabilize the country’s already-wobbly financial system, which is under intense strain amid the international sanctions the country faces, the officials said.

Iran never acknowledged the mid-August breach, which forced banks to shut down cash machines across the country.

IRleaks entered the banks’ servers via a company called Tosan, which provides data and other digital services to Iran’s financial sector, the officials said.

Using Tosan, the hackers appear to have siphoned data from both private banks and Iran’s central bank. Of Iran’s 29 active credit institutions, as many as 20 were hit, including the Bank of Industry and Mines and the Post Bank of Iran.

Though the attack was reported at the time by Iran International, an opposition news outlet, neither the suspected hackers nor the ransom demands were disclosed.

Iran’s supreme leader delivered a cryptic message in the wake of the attack, blaming the US and Israel for “spreading fear among our people,” without acknowledging the country’s banks were under assault.

Despite the growing tensions between Iran and both the US and Israel, people familiar with the Iranian banking hack told POLITICO that IRLeaks is affiliated with neither the US nor Israel.



Taiwan Reports Chinese Balloon, First Time in Six Months

A woman holds flags amid celebrations of the 130th foundation anniversary of Taiwan's largest opposition party Kuomintang (KMT), in Taoyuan, Taiwan November 24, 2024. (Reuters)
A woman holds flags amid celebrations of the 130th foundation anniversary of Taiwan's largest opposition party Kuomintang (KMT), in Taoyuan, Taiwan November 24, 2024. (Reuters)
TT

Taiwan Reports Chinese Balloon, First Time in Six Months

A woman holds flags amid celebrations of the 130th foundation anniversary of Taiwan's largest opposition party Kuomintang (KMT), in Taoyuan, Taiwan November 24, 2024. (Reuters)
A woman holds flags amid celebrations of the 130th foundation anniversary of Taiwan's largest opposition party Kuomintang (KMT), in Taoyuan, Taiwan November 24, 2024. (Reuters)

Taiwan's defense ministry on Monday reported that a Chinese balloon had been detected over the sea to Taiwan's north, the first time since April it has reported such an incident in what Taipei views as part of a pattern of harassment by Beijing.

Taiwan, which China claims as its own territory, complained that in the weeks leading up to its presidential election in January Chinese balloon activity took place at an "unprecedented scale".

It described the incidents as part of a Chinese pressure campaign - so-called grey-zone warfare designed to exhaust a foe using irregular tactics without open combat.

Taiwan strongly objects to China’s sovereignty claims and says only the island’s people can decide their future.

The ministry, in its regular morning update on Chinese military activities over the previous 24 hours, said the single balloon was detected at 6:21 p.m. (1021 GMT) on Sunday 60 nautical miles (111 km) to the north of Taiwan's Keelung port.

It then vanished some two hours later, having flown at an altitude of 33,000 ft (10,000 meters), but without crossing Taiwan itself, the ministry said.

China's defense ministry did not respond to a request for comment.

China has previously dismissed Taiwan's complaints about the balloons, saying they were for meteorological purposes and should not be hyped up for political reasons.

The potential for China to use balloons for spying became a global issue last year when the United States shot down what it said was a Chinese surveillance balloon. China said the balloon was a civilian craft that accidentally drifted astray.