Iran’s Ariomex cryptocurrency exchange suffered a significant data leak that exposed sensitive user and transaction information spanning 2022–2025, according to findings published by Resecurity. The leaked database reportedly contained 11,826 customer records (about 7,710 associated with Iran based on IP/network intelligence) and included user identities, email addresses, IP addresses, transaction histories, and contextual details about cryptocurrency operations; some records reportedly showed missing or altered KYC information despite high-value activity. Resecurity’s analysis also highlighted examples of suspicious, multi-million-dollar transactions and communications suggesting attempts to move large sums, and noted that some users appeared to treat the exchange as a de facto “bank” for storing crypto.
Reporting indicated the exposure likely originated from a compromised customer support system, and the stolen data has been circulating on dark web channels. The dataset’s geographic indicators suggest Iranian crypto holders’ activity across multiple countries (including the US and several European jurisdictions), which could enable follow-on risks such as user identification, targeting, and potential investigative mapping of illicit financial activity. Separate coverage on Iran’s Nobitex exchange focused on market/chain-analysis and a prior 2025 hack, and did not describe the Ariomex leak itself.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On or before early March 2026, Resecurity publicly reported the Ariomex data leak and said the records suggested possible sanctions-evasion and money-laundering activity, including high-value transfers and heavy use of TRON-based stablecoins such as USDT. The firm said the leak could help map the global footprint of Iranian crypto holders and identify potentially illicit financial activity.
Resecurity reported that a stolen Ariomex database was being circulated on dark web channels. The exposed data included personal identifiers, transaction histories, and operational details linked to cryptocurrency activity.
Resecurity assessed that the most likely root cause of the Ariomex exposure was a compromise of the exchange's customer support or helpdesk environment. The compromise allegedly enabled theft of sensitive user and transaction data later seen in the leaked database.
The leaked Ariomex database contained user identity, account activity, IP address, and transaction records spanning the period from 2022 through 2025. Reports said the dataset included 11,826 records, with many tied to users in Iran and some showing missing or altered KYC information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.