U.S.-Iran Conflict Raises Threat of Retaliatory Cyberattacks on American Banks
Iran has long used cyberattacks to offset its conventional military disadvantage. From late 2011 to 2013, “Operation Ababil” targeted 46 U.S. financial institutions with distributed denial-of-service attacks, including Bank of America, JPMorgan Chase and Capital One. The campaign prevented hundreds of thousands of customers from logging in and cost tens of millions of dollars to remediate. Because the financial sector underpins payments and transactions, it has again become a focus for retaliation.
After U.S. and Israeli airstrikes on Iran on February 28, 2026, Symantec confirmed on March 5 that the Iranian state-backed group MuddyWater had been lurking inside a U.S. bank’s network since February. On March 11, Iran’s Khatam al-Anbiya command named U.S. and Israeli banks and economic centers as targets and warned people to remain 1,000 meters away from banks. SIFMA and FS-ISAC are preparing for DDoS attacks, ransomware and deepfakes.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →