LmCast :: Stay tuned in

Iranian banks' SSL certificates are being revoked due to OFAC sanctions

Recorded: Sept. 14, 2026, 7 p.m.

Original Summarized

Iran Banks SSL Certificates Fail, Domains Change

Digiato


Recently Searched Keywords

b

q

tina

tapsi

a

eSIM


Most Searched Keywords

it

b

q

a

ip

tapsi

rightel

tina

misinformation

chatbot

internet

telegram

Tablet

nouri

eSIM

2026

starlink

News

Report

Interview

Insight

Digiato

Today’s Highlights

About
Contact
Team

Popular:

AI

Finance

Tech

Submit Feedback

Please rate your satisfaction with Digiato.

Very Satisfied

Not Satisfied At All

How can we improve your experience?

Submit Feedback

Your feedback has been successfully submitted.
Thank you for helping us improve and grow Digiato.

Digiato Report

Report
Iran’s Banks Are Changing Domains After Their SSL Certificates Stopped Validating
With browsers flagging Iranian bank sites as unsafe, some banks moved addresses without warning customers

Written by Mojtaba Astaneh | 7 September 2026 | 23:00

Share:

Copy Link

Latest from Interview


Alopeyk reports 20-fold operational growth, puts service quality next

3 days ago


Former Iran Cyberspace Chief Says Hardliners Want a National ‘Splinternet’

1 week ago


GreenWeb Targets Tehran IPO to Fund AI Infrastructure Expansion

2 weeks ago


Silenced Streams: How a 20-Day Internet Blackout Left Persian Podcasts Stranded Offline

7 February 2026


IPO First, Region Next: How Achareh Plans to Scale Beyond Iran

17 December 2025

Iranian banks are moving their websites to new addresses because browsers have stopped trusting the security certificates on the old ones. Bank Melli Iran, the country’s largest state-owned bank, sent customers a text message pointing them to its new domain. Bank Mellat, one of the country's largest commercial banks, switched without announcing the change and left no redirect from the address customers had been using.

The trigger is the certificate itself. An SSL/TLS certificate is what lets a browser confirm that the site in the address bar is the site it claims to be, and Iranian institutions have been losing theirs.
That makes this more than a maintenance problem. A bank is the one place on the web where the browser’s identity check does the most work, and the workaround the sector has settled on-new domains, plus a warning screen users are expected to click past-degrades exactly that check. It is also a live demonstration of something the rest of the web rarely has to think about: the certificate authority system is a shared global utility with a small number of political chokepoints, and Iran is finding out what happens when access to it narrows.
The certificates stopped renewing
A certificate has to chain back to an authority the browser already trusts. If it expires, is revoked, or cannot be traced through that chain, the browser blocks the page and shows a security warning instead.
Iranian sites depend heavily on foreign issuers for those certificates. According to W3Techs, a survey that tracks certificate authority market share, Let’s Encrypt accounts for a very large share of the certificates used on Iranian websites, with Certum, a Polish certificate authority, the other issuer in wide use.
Iranian technologists attribute the revocations to sanctions compliance by those authorities. Neither Let’s Encrypt nor Certum has published a statement specific to Iranian banks, and no affected bank has publicly explained why its certificate stopped working. What the dependency does show is that picking a non-American issuer does not by itself make the trust chain independent.
Not only the banks
The errors have not been confined to lenders. Domains belonging to the Central Bank of Iran, which sets the official exchange rate and licenses the country’s payment providers, and to the Communications Regulatory Authority, the telecom ministry’s licensing arm, have shown the same warning at points, as have some other government sites.
A new domain is its own attack surface
Changing address does sidestep the certificate problem on the old domain. It also creates a new one.
Old links, search results, mobile apps and saved bookmarks still point at the retired address. A customer who cannot reach their bank goes looking for it-on a search engine, or on social media-and that is precisely the environment in which an official banking domain and a convincing imitation are hardest to tell apart. The banks that moved without notice or a redirect have pushed the largest number of customers into that search.
Browsers show a security warning rather than the page when a bank’s certificate cannot be verified. Credit: Digiato
The warning that stops meaning anything
The browser warning exists to stop people entering sensitive information on a site whose identity cannot be confirmed. It works because it is rare.
When it appears repeatedly on legitimate bank and government sites, and users have to dismiss it to do routine business, it stops functioning as a signal and becomes a step in the process. The habit is not domain-specific. A customer trained to click through “your connection is not private” on their own bank’s site will click through it on a phishing page built to look like that bank.
How many Iranian domains have lost certificates is not established, and no authority or institution has put a number on it.

Finance
Tech

Share:

Copy Link

Mojtaba Astaneh

Mojtaba Astaneh

View All Published Articles

Write Your Comments and Feedback

Cancel reply
Submit

Digiato Suggestions

Iran Parliament Approves Digital Economy Growth Plan

Divar CEO Urges Reforms in Judicial Approach to Digital Platforms

Iran’s GPS Disruptions Tied to Drone Defence Efforts, Says ICT Minister

Insight
Interview
News
Report

Follow Digiato on Social Media Digiato's social networks are the fastest way to access news about technology, science, and cars. If you want to stay updated, follow Digiato on social media.

All rights reserved by Digiato.

Username or Email

Password

Login to your account

Create New Account
I forgot my account details

Login to Your Account

Username

Email

Password

I have read and accept Digiato's terms and conditions.

Create New Account

Login to your account
I forgot my account details

Create Account

Email

Reset Password

Create New Account
Login to your account

Forgot Password

Iranian financial institutions are actively migrating their online addresses because web browsers have ceased validating the security certificates associated with their legacy domains. This operational shift was initiated by major entities, such as Bank Melli Iran, which notified customers via text message regarding its new domain, and Bank Mellat, which transitioned without public announcement or redirection.

The fundamental cause of this disruption lies with the SSL/TLS certificate system. A valid certificate must successfully chain back to a trusted authority for a browser to confirm the site's identity. When certificates fail to renew, are revoked, or cannot be traced through the established chain of trust, browsers block access and display security warnings. This situation highlights that banking institutions, being primary points of web trust, are acutely affected by failures in this infrastructure.

The underlying issue relates to the global certificate authority system, which is a shared utility reliant on a limited number of political chokepoints. Iranian technologists attribute these revocations to compliance with international sanctions by the certificate authorities, although neither Let's Encrypt nor Certum, major issuers for Iranian websites, have provided specific statements regarding the affected banks. This dependency demonstrates that selecting a non-American issuer does not independently ensure the independence of the trust chain.

The consequences of these certificate failures extend beyond financial institutions. Domains belonging to critical government entities, including the Central Bank of Iran, which manages exchange rates and payment providers, and the Communications Regulatory Authority, have also exhibited similar warnings. This indicates a broader systemic vulnerability affecting government and regulatory digital infrastructure.

The act of changing domains creates a novel security challenge. While this process bypasses the immediate certificate failure on the old address, it simultaneously introduces a new attack surface. Customers who rely on old links, saved bookmarks, and search engine results to find their banking services are directed to the retired addresses. This ambiguity allows malicious entities to exploit the gap between official domains and convincing imitations, particularly in the environments where official and counterfeit banking domains are difficult to distinguish.

The browser warning, designed to prevent users from entering sensitive information on sites whose identity cannot be verified, is intended to stop malicious activity. However, when users frequently encounter this warning on legitimate, high-traffic sites like banks, they habituate to dismissing it. This habit is not specific to a single domain; it trains the user to click through security warnings, making them susceptible to clicking on phishing pages that mimic the warning mechanism, thereby facilitating further exploitation.

A significant challenge remains the lack of quantifiable data regarding the extent of the problem, as no authority or institution has published a definitive count of how many Iranian domains have experienced certificate loss. This lack of data obscures the full scope of the infrastructure instability caused by these technical failures.