The 12-Day War: US-Israel Strikes on Iran's Nuclear Sites 2025·5 min read

Cyber Warfare Targeting Bank Sepah and Nobitex Exchange

During the brief conflict of June 2025, cyber operations targeted the financial infrastructure of Iran, successfully paralyzing Bank Sepah and destroying ninety million dollars on the Nobitex exchange.

In June 2025, during the intense 12-day conflict known as Operation Rising Lion, cyber operations emerged as a critical second front alongside traditional kinetic airstrikes. While military aircraft targeted physical nuclear installations and military commands in Iran, covert digital strikes systematically dismantled the financial network that sustains the Islamic Revolutionary Guard Corps. By bringing down major banking institutions and burning millions in digital assets, these operations demonstrated a new capability to disrupt the Iranian regime's financing of proxy networks. This financial frontline severely degraded Tehran's command structure and economic stability during the height of the hostilities.

Historical Context: Bank Sepah and Nobitex

Bank Sepah, established as Iran's first national bank, holds a central role in the Islamic Republic's economic and military architecture. The state-owned institution serves as the primary financial platform for Iran’s Ministry of Defense and Armed Forces Logistics, facilitating domestic payrolls and international financial transfers for the military. Because of its direct involvement in financing the Islamic Revolutionary Guard Corps and its ballistic missile program, the bank has been a frequent target of international sanctions, including reimposed measures by the United States Treasury Department in 2018. Over the years, the bank has consolidated multiple military-linked financial institutions to streamline funding for overseas operations.

In contrast, Nobitex represents the modern, decentralized frontier of Iran's financial survival strategy under heavy international sanctions. As Iran's largest cryptocurrency exchange, Nobitex has provided crucial avenues for the regime to bypass traditional banking sanctions, launder illicit capital, and move funds globally. Cryptocurrencies have become a vital tool for the regime to sustain its proxy networks, such as Hezbollah and Hamas, and to acquire restricted military hardware. United States lawmakers and financial analysts had long expressed concern over how Nobitex hosted guides explaining how users could evade international scrutiny, turning the platform into a key pillar of Iran's modern cyber-enabled financial system.

Key Facts of the Cyber Offensive

The coordinated digital strikes against Iran's financial infrastructure unfolded in rapid succession during the mid-June hostilities. These operations bypassed sophisticated defense systems, leaving key sectors of the Iranian economy paralyzed and unable to support ongoing military mobilization. The disruption spread quickly through public channels, causing nationwide panic and showing the vulnerability of Iran's financial core.

  • On June 17, 2025, the Israel-linked hacker group known as Gonjeshke Darande, or Predatory Sparrow, executed a massive cyber operation that took Bank Sepah entirely offline. This operation halted nationwide automated teller machines and disrupted card processing networks, freezing civilian and military transactions alike.
  • On June 18, 2025, the same hacker collective targeted Nobitex, wiping out nearly ninety million dollars worth of digital currency. Instead of stealing the funds for profit, the hackers transferred them to specialized wallets with names denouncing the Islamic Revolutionary Guard Corps, effectively burning the assets.
  • The dual attacks triggered deep panic within the regime, prompting the Islamic Revolutionary Guard Corps Cybersecurity Command to ban security teams from using any internet-connected smart devices. This emergency measure was driven by fears of device-based kinetic strikes or further deep system intrusions.

These actions crippled both conventional state banking and alternative crypto channels, creating an unprecedented cash and payment crisis across the country. The simultaneous failure of banking networks and fuel payment systems forced the regime to divert its military resources to manage widespread public unrest and maintain basic domestic control.

Cyber Warfare and Sanctions Evasion

The cyber campaign of June 2025 highlights a fundamental shift in how modern conflicts are waged, particularly concerning state-sponsored financial systems. Analysts from the Foundation for Defense of Democracies noted that targeting Bank Sepah and Nobitex directly degraded the regime's capability to launder illicit funds and finance foreign proxies. This operation is detailed in an analysis on the Foundation for Defense of Democracies website, which describes how these actions exposed major vulnerabilities in Iran's financial architecture. By neutralizing both state-run and decentralized financial pipelines, the attackers disrupted the funding streams of the Revolutionary Guard at a moment when rapid capital movement was essential for military operations.

Furthermore, the decision to burn ninety million dollars in cryptocurrency on Nobitex rather than siphon it off is a significant tactical evolution in information warfare. This action, verified in a report by CNBC, demonstrated that the primary goal of the attackers was political disruption and denial of resources rather than monetary gain. By publicly associating the frozen funds with anti-regime statements, the cyber actors undermined the credibility of Iranian domestic cyber defenses. This operation proved that digital assets, once considered a safe haven for sanctions evasion, are highly vulnerable to targeted disruption by advanced nation-state adversaries.

Conclusion: Strategic Significance for Israel

The cyber campaign against Iran's financial heart during the 2025 war has lasting strategic implications for Israel and its Western allies. By successfully neutralizing Bank Sepah and Nobitex, the operations demonstrated that cyber warfare can achieve strategic containment objectives without the collateral damage associated with physical bombings. These actions have effectively forced the Iranian regime to recognize that its alternative financial networks are within reach of allied capabilities. This has greatly hampered its ability to fund regional proxies, thereby strengthening Israel's security posture on its borders.

Ultimately, these events have established a new precedent for how democratic nations can counter asymmetric threats posed by hostile regimes. The disruption of Iran's financial systems during a kinetic war shows that digital superiority is just as vital as air superiority in modern conflicts. As Israel continues to navigate complex regional threats, the integration of financial cyber operations will remain a cornerstone of its defense strategy. This approach ensures that hostile states cannot easily finance aggression against democratic nations with impunity.

Sources

  1. 1.https://cyberlaw.ccdcoe.org/wiki/Predatory_Sparrow%E2%80%99s_operations_against_Iranian_financial_cyber_infrastructure_(2025)
  2. 2.https://en.wikipedia.org/wiki/Predatory_Sparrow
  3. 3.https://www.trmlabs.com/resources/blog/inside-the-nobitex-breach-what-the-leaked-source-code-reveals-about-irans-crypto-infrastructure
  4. 4.https://www.iranintl.com/en/202508299204
  5. 5.https://www.picussecurity.com/resource/blog/predatory-sparrow-inside-the-cyber-warfare-targeting-irans-critical-infrastructure