Iranian banks' SSL certificates are being revoked due to OFAC sanctions
Recorded: Sept. 14, 2026, 7 p.m.
| Original | Summarized |
Iran Banks SSL Certificates Fail, Domains Change Digiato b q tina tapsi a eSIM it b q a ip tapsi rightel tina misinformation chatbot internet telegram Tablet nouri eSIM 2026 starlink
News Report Interview Insight Digiato Today’s Highlights About
Popular: AI Finance Tech Submit Feedback Please rate your satisfaction with Digiato. Very Satisfied Not Satisfied At All How can we improve your experience? Submit Feedback Your feedback has been successfully submitted.
Digiato Report
Report Written by Mojtaba Astaneh | 7 September 2026 | 23:00 Share: Copy Link Latest from Interview 3 days ago 1 week ago 2 weeks ago 7 February 2026 17 December 2025 Iranian banks are moving their websites to new addresses because browsers have stopped trusting the security certificates on the old ones. Bank Melli Iran, the country’s largest state-owned bank, sent customers a text message pointing them to its new domain. Bank Mellat, one of the country's largest commercial banks, switched without announcing the change and left no redirect from the address customers had been using. The trigger is the certificate itself. An SSL/TLS certificate is what lets a browser confirm that the site in the address bar is the site it claims to be, and Iranian institutions have been losing theirs. Finance Share: Copy Link Mojtaba Astaneh Mojtaba Astaneh View All Published Articles
Write Your Comments and Feedback Cancel reply
Digiato Suggestions
Iran Parliament Approves Digital Economy Growth Plan
Divar CEO Urges Reforms in Judicial Approach to Digital Platforms
Iran’s GPS Disruptions Tied to Drone Defence Efforts, Says ICT Minister Insight Follow Digiato on Social Media Digiato's social networks are the fastest way to access news about technology, science, and cars. If you want to stay updated, follow Digiato on social media. All rights reserved by Digiato.
Username or Email Password Login to your account Create New Account Login to Your Account
Username Password I have read and accept Digiato's terms and conditions. Create New Account Login to your account Create Account
Reset Password Create New Account Forgot Password |
Iranian financial institutions are actively migrating their online addresses because web browsers have ceased validating the security certificates associated with their legacy domains. This operational shift was initiated by major entities, such as Bank Melli Iran, which notified customers via text message regarding its new domain, and Bank Mellat, which transitioned without public announcement or redirection. The fundamental cause of this disruption lies with the SSL/TLS certificate system. A valid certificate must successfully chain back to a trusted authority for a browser to confirm the site's identity. When certificates fail to renew, are revoked, or cannot be traced through the established chain of trust, browsers block access and display security warnings. This situation highlights that banking institutions, being primary points of web trust, are acutely affected by failures in this infrastructure. The underlying issue relates to the global certificate authority system, which is a shared utility reliant on a limited number of political chokepoints. Iranian technologists attribute these revocations to compliance with international sanctions by the certificate authorities, although neither Let's Encrypt nor Certum, major issuers for Iranian websites, have provided specific statements regarding the affected banks. This dependency demonstrates that selecting a non-American issuer does not independently ensure the independence of the trust chain. The consequences of these certificate failures extend beyond financial institutions. Domains belonging to critical government entities, including the Central Bank of Iran, which manages exchange rates and payment providers, and the Communications Regulatory Authority, have also exhibited similar warnings. This indicates a broader systemic vulnerability affecting government and regulatory digital infrastructure. The act of changing domains creates a novel security challenge. While this process bypasses the immediate certificate failure on the old address, it simultaneously introduces a new attack surface. Customers who rely on old links, saved bookmarks, and search engine results to find their banking services are directed to the retired addresses. This ambiguity allows malicious entities to exploit the gap between official domains and convincing imitations, particularly in the environments where official and counterfeit banking domains are difficult to distinguish. The browser warning, designed to prevent users from entering sensitive information on sites whose identity cannot be verified, is intended to stop malicious activity. However, when users frequently encounter this warning on legitimate, high-traffic sites like banks, they habituate to dismissing it. This habit is not specific to a single domain; it trains the user to click through security warnings, making them susceptible to clicking on phishing pages that mimic the warning mechanism, thereby facilitating further exploitation. A significant challenge remains the lack of quantifiable data regarding the extent of the problem, as no authority or institution has published a definitive count of how many Iranian domains have experienced certificate loss. This lack of data obscures the full scope of the infrastructure instability caused by these technical failures. |