The pro-Israel 'Predatory Sparrow' hacking group conducted a politically motivated cyberattack on Nobitex, Iran's largest crypto exchange, stealing over $90 million in cryptocurrency. The attack, detected on June 19, 2025, involved unauthorized access to the company's reporting infrastructure and hot wallet. The hackers drained the funds into vanity addresses with anti-IRGC messages, effectively burning the crypto so no one could access it again. The attack was not financially motivated but aimed at disrupting Nobitex's operations and exposing its ties to the Iranian regime and IRGC.
TPRM report: https://scoringcyber.rankiteo.com/company/nobitexmarket
"id": "nob001061925",
"linkid": "nobitexmarket",
"type": "Cyber Attack",
"date": "6/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Financial Services',
'location': 'Iran',
'name': 'Nobitex',
'type': 'Crypto Exchange'}],
'attack_vector': 'Unauthorized Access',
'data_breach': {'data_exfiltration': True,
'file_types_exposed': ['Source code', 'Internal information'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Source code',
'Internal information']},
'date_detected': '2025-06-19',
'date_publicly_disclosed': '2025-06-19',
'description': "The pro-Israel 'Predatory Sparrow' hacking group claims to "
'have stolen over $90 million in cryptocurrency from Nobitex, '
"Iran's largest crypto exchange, and burned the funds in a "
'politically motivated cyberattack.',
'impact': {'data_compromised': ['Source code', 'Internal information'],
'downtime': 'Website offline since the attack',
'financial_loss': '$90 million',
'systems_affected': ['Reporting infrastructure', 'Hot wallet']},
'investigation_status': 'Ongoing',
'motivation': 'Political',
'references': [{'date_accessed': '2025-06-19',
'source': 'BleepingComputer',
'url': 'https://www.bleepingcomputer.com/news/security/predatory-sparrow-hackers-burn-90m-in-cryptocurrency-stolen-from-irans-nobitex/'}],
'response': {'communication_strategy': 'Public disclosure on X',
'containment_measures': 'Suspended all access',
'incident_response_plan_activated': True},
'threat_actor': 'Predatory Sparrow',
'title': 'Predatory Sparrow Hack on Nobitex Crypto Exchange',
'type': 'Cyberattack'}