Yazılar

Iran’s Nobitex Crypto Exchange Hit by Hackers, $90 Million in Funds Destroyed

A powerful anti-Iranian hacking group known as Gonjeshke Darande (Predatory Sparrow) claimed responsibility on Wednesday for a devastating cyberattack on Nobitex, Iran’s largest cryptocurrency exchange. The attack allegedly destroyed around $90 million in digital assets and threatened to leak the platform’s source code.

This marks the group’s second strike in two days, following an earlier operation targeting Bank Sepah, a state-owned Iranian bank. The campaign comes amid escalating tensions and missile exchanges between Israel and Iran.

The hackers claim Nobitex aids the Iranian regime in evading sanctions and financing militant groups, including Hamas, Palestinian Islamic Jihad, and Yemen’s Houthis. Blockchain forensics firm Elliptic confirmed these ties in a blog post, noting that funds had been exchanged between Nobitex and wallets linked to those entities.

Early Wednesday, funds were transferred from Nobitex to hacker-controlled wallets displaying anti-IRGC (Islamic Revolutionary Guard Corps) messages. Analysis by TRM Labs and Chainalysis confirmed that approximately $90 million in cryptocurrency was irretrievably “burned” in the operation, meaning the attackers intentionally rendered the assets inaccessible as a political statement.

Elliptic noted that the structure of the hacker wallets ensured that even the attackers could not access the stolen assets.

Nobitex confirmed in a post on X (formerly Twitter) that it had taken its website and app offline due to “unauthorized access.” Its Telegram support channels did not respond to inquiries.

The cyberattack adds to a growing list of high-profile hacks by Predatory Sparrow, which has previously disabled Iranian infrastructure, including gas stations and steel mills. Though Israel has never officially claimed the group, its operations are widely considered to align with Israeli cyber interests.

Senators Elizabeth Warren and Angus King recently highlighted Nobitex’s suspected role in Iranian sanctions evasion in a letter to the Biden administration, citing prior Reuters investigations from 2022.

Cybersecurity experts warn that this breach could further inflame geopolitical tensions while demonstrating the increasing use of blockchain technology in modern cyber warfare.

Suspected Russian Hackers Use Sophisticated New Tactic to Target UK Researcher

Suspected Russian hackers deployed a novel and highly convincing tactic to trick British researcher Keir Giles into compromising his own accounts, according to Giles and cybersecurity experts.

Last month, the hackers impersonated a U.S. State Department official named “Claudie Weber” who contacted Giles via email to arrange a meeting requiring use of a secure government app. Although the email came from a Gmail address, the communication was fluent, idiomatic, and included apparent State Department colleagues copied on the exchange. Giles, a seasoned expert on Russia and espionage, was usually wary but was eventually deceived by the professionalism and persistence over nearly two weeks.

Giles provided an app-specific password—a credential that grants third-party app access but can bypass regular password protections—thus exposing his account.

Alphabet’s Google attributed the attack to the Russian government, citing similarities to prior campaigns. The Russian Foreign Ministry did not respond to inquiries. Giles described the operation as seamless, with no obvious red flags even in hindsight.

Cybersecurity researchers from Citizen Lab noted the attack’s fluency might indicate the use of advanced AI, such as large language models, to craft convincing messages—marking a significant upgrade from typical error-ridden phishing attempts. They also pointed out that the hackers exploited the lack of error messages when sending emails to fake State Department addresses.

This sophisticated social engineering attack highlights evolving cyber threats where even cautious experts can be deceived by carefully orchestrated campaigns.

The U.S. State Department did not immediately comment on the incident.

Marks & Spencer Resumes Online Orders After 46-Day Cyberattack Shutdown

British retailer Marks & Spencer (M&S) has resumed online orders for its clothing range after a 46-day suspension due to a cyberattack. The company’s shares rose 3.5% following the restart of standard home deliveries in England, Scotland, and Wales for most clothing items.

An M&S spokesperson noted that not all products are currently available online, with the initial focus on best-selling and new items. The retailer plans to expand the available product selection daily. Deliveries to Northern Ireland, as well as click-and-collect, next-day, nominated-day, and international delivery services, are expected to resume in the coming weeks.

M&S halted clothing and home orders through its website and app on April 25 after technical issues during the Easter holiday weekend disrupted contactless payments and click-and-collect services. The company had initially disclosed managing a “cyber incident” on April 22.

Last month, M&S projected that online disruptions would continue into July and estimated the financial impact at approximately £300 million ($404 million) in lost operating profit for the 2025/26 financial year. However, the company aims to reduce this loss through insurance claims and cost-cutting measures. The cyberattack also interfered with M&S’s supply chain, hindering its ability to stock stores during a period of high demand driven by warm weather.

Industry analysts anticipate that the upcoming end-of-season sale will feature larger inventories and deeper discounts than usual. Despite Tuesday’s share price recovery, M&S shares remain 9.5% lower since the cyberattack was first reported.

The breach occurred when hackers exploited a vulnerability by deceiving employees at a third-party contractor, allowing them to bypass M&S’s digital security measures. In response, M&S plans to use this incident as an opportunity to accelerate technological upgrades.

In recent weeks, several global retailers have reported similar cyber incidents, including UK grocer the Co-op Group, German sportswear brand Adidas, luxury jeweller Cartier, and U.S. lingerie retailer Victoria’s Secret.