Sepah Bank, following reports on social media about a group called 'Codebreakers' infiltrating its systems and leaking information of thousands of military and civilian customers, threatened media and citizens with legal action if they republish this information. In its statement, Sepah Bank once again denied the hacking of its systems, but at the same time stated that due to 'the bank's position with the armed forces' and the importance of 'the confidentiality of information related to military and security institutions of the country', any republishing of leaked data, especially regarding military institutions, would be considered a 'violation of confidentiality' and could lead to legal prosecution. The hacking group 'Codebreakers' published part of the information of the wealthiest customers of Sepah Bank, one of the most notable being the assets of General Hassan Polarak, former head of the Reconstruction Headquarters of Holy Shrines, which shows he has '634 billion tomans' deposited only in Sepah Bank. The top individual on this list has '768 billion tomans' in assets. This group also published information on 13 quasi-public companies that each borrowed over 100 billion tomans. On the sixth of Farvardin, they announced through images that they had hacked the customer information of Sepah Bank, which is also known as a military bank. The group claims to possess over 12 terabytes of data from 42 million customers of Sepah Bank from the years 1304 to 1404 (1925 to 2025). The hackers had given Sepah Bank 72 hours to negotiate to prevent the sale of the information. Radio Farda cannot independently verify the authenticity of this hack. However, the threat from Sepah Bank to media and individuals could be a strong indication of the confirmation of the 'hack' or 'data theft', which has recently been a topic of discussion among many social media users and information security experts. They have called for transparent accountability, technical investigation, and acceptance of responsibility by the bank's officials. Criticism has also been directed at Sepah Bank's denials, which in response to the cyber infiltration claims, stated that its systems are 'unhackable' and called the issue 'absolute falsehood'. Some social media users, including Ali Sharif Zarachi, a faculty member at Sharif University of Technology, have questioned: 'What is 634 billion tomans doing in a personal account of Hassan Polarak, former head of the Reconstruction Headquarters of Holy Shrines, when people are in need of bread for the night?' Polarak, born in Rafsanjan and a commander of the Quds Force of the Islamic Revolutionary Guard Corps, was a longtime friend of Qassem Soleimani, the former commander of the Quds Force, who was killed in a U.S. drone strike in January 2020. Hassan Polarak was placed on the U.S. Treasury Department's sanctions list in April 2020 and is also active in the private sector, having founded the 'Yeganeh Andish Sarmayeh' company with his son, Hadi Polarak, in 2010, which was mentioned in the Capital Bank corruption case. Under this company, automotive companies such as Rayen, Blue Swallow Erg (import of auto parts), Dan Communication Goya (food production), and Radkish (import of cosmetics) were active. The first two companies initially belonged to Hossein Marashi, a reformist economic activist of Kerman descent, and were later sold or given to the Polarak family, who were considered part of Qassem Soleimani's faction in Kerman province. In a third step, the father and son transferred these companies to the 'Yas Holding' affiliated with the IRGC's Cooperative Foundation. Yas Holding, one of the most powerful economic entities of the IRGC, was dissolved in February 2018 after widespread corruption and the arrest of its senior managers, including Masoud Mehrdadi and Mahmoud Saif. The Polarak family also has close ties with other Kerman figures, namely the Jahangiri brothers. Hassan Polarak once worked as an advisor to Eshaq Jahangiri, the first vice president of Iran, and had economic partnerships with Mehdi Jahangiri in some companies. Mr. Jahangiri was later found guilty in an economic corruption case and sentenced to prison. In recent years, customer information from various Iranian banks has repeatedly been targeted by cyber intrusions and sold in the virtual space and on the internet. However, banks usually deny these attacks, and the Central Bank has remained silent regarding these incidents. In previous years, numerous other similar hacks have been reported in banks such as Bank Melli, Bank Ayandeh, Bank Shahr, and even digital intermediary companies. Some of these attacks were carried out by international groups like 'Anonymous'. Additionally, a report from the American publication 'Politico' claimed that the Islamic Republic of Iran paid at least three million dollars in ransom through the 'Tosan' company to prevent the disclosure of information from 20 domestic banks. Reports from domestic media indicate the weak banking security infrastructure of the country, the lack of seriousness regarding customer information security, and the neglect of these incidents and the damage caused by the leakage of this information to Iranian users.
What Do We Know About the 'Hack' of Sepah Bank Customer Information?
Sepah Bank has denied a hacking incident reported by the group 'Codebreakers', which claims to have leaked sensitive information of its customers, including military personnel. The bank threatened legal action against those who share this information, highlighting the importance of confidentiality related to military and security institutions. The incident raises concerns about the security of banking information in Iran and the implications for public trust.
👥 Key Players
⚡ Actions
📰 What Happened
Hackers leaked Sepah Bank customer data, threatening military and civilian confidentiality.
- Codebreakers announce Sepah Bank
- Sepah Bank threaten media, citizens
- Sepah Bank deny public
💡 Why It Matters
📚 Background
The breach exposes significant weaknesses in Iran's cybersecurity and data protection.
📝 Key Evidence
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%