Threat Actor Claims to Sell “Full Access” to Central Bank of Iraq

A newly registered threat actor on an underground cybercrime forum claims to be selling what they describe as “full access” to the Central Bank of Iraq (CBI).

According to the advertisement, the alleged access could include banking-related databases, payment and card-related data, personal identity information, and potentially broader internal resources.

If authentic, unauthorized access to a national central bank would represent a serious financial-sector security incident. As part of a country’s critical financial infrastructure, a central bank holds systems and information that are important to the stability and operation of the financial sector.

Depending on what systems were actually accessed, a genuine compromise could potentially expose sensitive financial information, disrupt internal or payment-related services, enable further attacks using stolen access, and create wider risks for financial institutions.

However, there are significant reasons to treat the claim with caution.

The threat actor reportedly joined the forum in August 2026, has only one post, has zero reputation, and has provided no visible technical evidence demonstrating that the claimed access exists. The seller is also directing potential buyers to private messages or Telegram.

This raises another possibility: the advertisement could be an attempt to scam other cybercriminals by selling fake or exaggerated access to individuals willing to pay for it.

At this stage, the claim should therefore be considered unverified and should not be treated as a confirmed compromise of the Central Bank of Iraq.

For ordinary customers, there is currently no evidence from this advertisement that personal bank accounts have been compromised. There is therefore no reason to panic or take special action based on the claim alone. Customers should continue following normal cybersecurity precautions and rely on official announcements for any confirmed developments.

Even if the claim ultimately proves to be false, the incident highlights a broader concern: access to high-value government and financial institutions is increasingly being treated as a commodity within underground cybercrime markets. This demonstrates how financial crime can intersect with wider national-security concerns.

The case also provides an important cybersecurity lesson: a dramatic claim on a cybercrime forum is not the same as a confirmed cyberattack. Evidence remains essential when assessing any alleged breach.