IRLeaks is a threat actor name associated with a major August 2024 intrusion and extortion incident targeting Iran’s banking sector. The group is reported to have compromised numerous Iranian financial institutions, including central banking and state-linked entities, stolen customer data at very large scale, disrupted banking operations, and sought payment in exchange for ending the incident and recovering stolen information. Reporting on the operation indicates that millions of customer records, including payment-card data, were taken and that service disruption was severe enough to contribute to ATM outages across the country. Available reporting most strongly supports IRLeaks as a financially motivated actor rather than a clearly attributable state-sponsored unit. The operation combined data theft, operational disruption, and ransom-style coercion. The group reportedly attempted to monetize the breach both by demanding payment and by offering stolen banking data for sale. Publicly observed messaging associated with the incident also included anti-regime political text displayed during the disruption, but the dominant motive supported by available evidence is financial gain. The intrusion reportedly affected a large share of Iran’s credit institutions and may have involved compromise through a third-party digital services provider used by banks, indicating capability to exploit trusted service relationships for initial access and broad downstream impact. IRLeaks therefore appears associated with initial access through a supply-chain or service-provider pathway, large-scale data exfiltration, extortion, and disruptive post-compromise activity against the financial sector.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.