The fallout from the Nobitex hack continues to be unfolding, and it might now not be simply in regards to the lacking funds as new experiences level to a doable hyperlink between the breach and the latest arrests of three Israeli residents.
In response to the blockchain intelligence platform TRM Labs, Israeli authorities have arrested three people accused of spying for Iran.
The suspects, aged between 19 and 28, had been allegedly recruited by Iranian handlers to hold out intelligence-related duties in alternate for cryptocurrency. Their actions ranged from surveillance and photographing army websites to tagging pro-Iran graffiti and monitoring high-profile officers.
Particulars of the arrests surfaced on June 24, coming simply days after the June 18 Nobitex hack. The breach, which resulted in losses exceeding $90 million, was carried by Gonjeshke Darande, the pro-Israel hacking collective identified for focusing on Iranian-linked infrastructure.
Per TRM Labs, the cyberattack could have performed extra than simply drain wallets. Whereas no direct hyperlink between the 2 occasions has been confirmed, the evaluation means that information obtained throughout the Nobitex breach could have performed a job in figuring out the not too long ago arrested suspects.
From hacks to handcuffs?
Each Israeli cyber protection groups and Gonjeshke Darande, also called Predatory Sparrow, have a historical past of utilizing cyber instruments for intelligence gathering. On this case, they might have accessed inside information similar to pockets data, KYC data, or personal communications, which doubtlessly aided the identification of the Iranian handlers or tracing funds to operatives.
That risk is supported by the leak of Nobitex’s delicate information only a day after the breach, suggesting the hackers had deep entry into the alternate’s infrastructure.
The arrested suspects had been reportedly paid hundreds of {dollars} for varied operations, with funds delivered via anonymized channels. Israeli authorities stated these funds had been traceable on-chain and fashioned a part of the proof used within the investigation.
In the meantime, the Nobitex hack additionally revealed suspicious fund actions by the alternate relationship again a number of months, tied to illicit exercise and potential cash laundering. A separate investigation pointed to quiet, structured fund transfers, and using stealth ways to obscure their path.
In some instances, these funds had been linked to wallets related to malicious actors, and the emergence of the potential ties to espionage raises additional questions on Nobitex’s transparency and operations.


