The June 2025 breach of the Iranian exchange Nobitex, reported at approximately $90 million, has been characterised in published summaries as linked to regional cyber operations rather than to conventional financial motive.
A Financially Motivated Attacker Wants To Keep The Money
That objective constrains behaviour in useful ways: the attacker must launder, must avoid attention that attracts tracing, must preserve the ability to convert. Those constraints are what most defensive and investigative strategy is built around.
An attacker whose objective is to damage an institution has none of them. Funds can be rendered permanently unrecoverable rather than moved, the act can be publicised rather than concealed, and there is no laundering path to interdict because nobody intends to spend anything.
It Makes The Figure Ambiguous
This desk records amounts taken because they are the available measure. In this case the amount taken and the amount gained may be entirely different numbers, and the second may be zero.
That is a measurement problem the corpus has not previously had to handle. Every other value in this database is a loss to someone and a gain to someone; here it may be a loss to one party and a strategic outcome for another, denominated in something that is not currency.
What We Are Not Asserting
Graded low. The characterisation of motive rests on limited published analysis. We have not established who conducted the operation, what became of the funds, or whether the geopolitical framing is correct rather than inferred from timing and target.
It is recorded because the category matters — an attack on financial infrastructure as a method of pressure is a different object from theft, and the corpus should be able to name it — and it is graded low so the framing is not read as established.
Compiled from limited published summaries, listed below. Motive is as characterised in those summaries and is not established. No actor is named. Corrections: corrections@forensicpost.com.