IRANIAN banks and other financial institutions have reportedly suffered widespread digital-certificate failures, disrupting access to their websites and online services. The article attributes the problem to US Office of Foreign Assets Control (OFAC) sanctions, which restrict US citizens and companies from conducting transactions with sanctioned organisations.
Since many major certificate authorities and root-certificate issuers are US-based, providers may be unable to issue certificates to Iranian government-affiliated organisations and banks, or may revoke certificates already issued. The result is that mainstream browsers no longer trust affected sites’ HTTPS connections.
The article says Let’s Encrypt changed its user agreement on 23 June 2026 to prohibit issuing certificates to sanctioned entities without explicit government authorisation. It says non-governmental organisations in sanctioned countries may still obtain certificates under certain authorisations, but Iranian state bodies and major banks cannot use the service for new certificates, renewals or existing certificates.
Some institutions are reportedly switching to less prominent backup domains, although certificates for those domains could also be revoked once their ownership is identified.
Iran is considering domestic certificate infrastructure, but the article notes that issuing certificates is technically straightforward while gaining trust from major browsers is not. Without browser and operating-system support, banks could require users to install special browsers or manually import root certificates. The article warns that such steps could increase phishing risk, but does not provide independent evidence confirming exploitation or quantify the number of affected institutions.