IRLeaks

Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:17:26

Targeted industries: retail-and-hospitality financial-services

Targeted regions: country_code:ir

Context

IRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB of sensitive data from 20 million user profiles. They have also compromised data from 23 leading Iranian insurance companies, offering over 160 million records for sale. Their operations involve extortion tactics, as seen in the ransom negotiations with Tosan, and they utilize malware such as StealC for data extraction. IRLeaks communicates primarily in Persian and has been active in selling stolen data on cybercriminal marketplaces.

Reports & references

  • hackread.com — Iranian Food Delivery Snappfood Cyber Attack (report)
  • cisoseries.com — Cyber Security Headlines Google 5B Suit Settled Orbit Chain Loses 80M Fda Cyber Agreement (report)
  • oodaloop.com — Pilfered Data From Iranian Insurance And Food Delivery Firms Leaked Online (report)
  • cybershafarat.com — Major Ir Leaks (report)
  • scmagazine.com — Significant Ransom Payment By Major Iranian It Firm Underway (report)

External references