Cyberattack Hits Shared Infrastructure of Four Major Iranian Banks, Disrupting ATMs, Mobile Banking and POS Services
A cyberattack on shared banking infrastructure in Iran disrupted ATMs, mobile and internet banking, and POS services across four major financial institutions. No customer data was compromised in this latest incident in an escalating pattern of attacks on Iranian financial systems.

Bank customers facing service disruptions at ATM terminals and counters following a cyberattack on shared communications infrastructure used by four major Iranian banks
A cyberattack struck the shared communications infrastructure used by four of Iran's largest state-linked financial institutions on 13 June 2026, causing simultaneous disruptions to electronic banking services across Bank Melli Iran, Bank Tejarat, Bank Saderat Iran, and the Export Development Bank of Iran, according to a statement from Iran's Bank Coordination Council cited by state media.
The attack targeted a common communications platform that supports operational connectivity among the four banks rather than their individual core banking systems. The effect was service-level disruption across multiple customer-facing channels simultaneously: mobile banking applications, internet banking platforms, ATMs, point-of-sale terminals, and card-based payment services were all affected. Customers across Iran reported failed payments, blocked transfers, and POS transaction errors during the outage period, with disruptions confirmed by Iran International.
Iran's Bank Coordination Council described the incident as a "limited cyberattack" focused on service interruption. Technical teams detected unusual activity on the shared infrastructure and implemented protective measures to isolate affected systems. The Council confirmed that no unauthorised access to customer information occurred, no customer data was deleted, and account balances, transaction histories, and core banking records remained intact. Recovery efforts to restore normal operations were underway within hours of the initial disruption.
No attribution has been made. The Council did not identify the source of the attack or name any suspected perpetrators, and no threat actor has publicly claimed responsibility.
The attack on shared infrastructure is significant from an architectural security perspective. A single compromised communications layer serving multiple institutions creates a single point of failure with cascading impact. The attacker does not need to breach each bank individually; disrupting the shared platform that binds them is sufficient to generate simultaneous outages across all connected institutions. This is the same logic that makes supply chain attacks on software vendors so operationally effective, applied here to banking communications infrastructure.
Iran's banking sector has faced repeated cyber pressure in recent years. The most significant prior incident was the August 2024 IRLeaks attack, which security researchers and Politico described as the worst cyberattack in Iranian banking history, affecting approximately 20 financial institutions and reportedly resulting in a ransom payment. The June 2026 incident appears narrower in scope but follows the same pattern of targeting shared or interconnected banking infrastructure to maximise disruption with minimal entry points.
For enterprise security teams and risk officers across the GCC, the incident carries two practical considerations. First, financial institutions with any correspondent banking, trade finance, or payment routing relationships involving Iranian banks should assess whether the disruption created downstream transaction failures or exposure in settlement windows. Second, the attack reinforces the systemic risk that shared infrastructure creates in regional financial ecosystems. GCC banks have made substantial investments in resilient architecture, but the interconnected nature of correspondent banking means that disruptions in adjacent financial systems can surface indirectly. As Oman's recently published cybersecurity investment report highlights, the GCC's drive toward sovereign cyber capability is partly a response to exactly this kind of cross-border infrastructure risk.
The broader lesson for financial sector CISOs is one of concentration risk in shared services. Whether the platform is a communications network, a cloud provider, a payment processor, or a managed security service, single points of dependency that span multiple institutions represent high-value targets. Assessing and mitigating that concentration risk should be a standing item on the enterprise security agenda, not a reactive measure triggered by an incident elsewhere in the region.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.