Skip to main content

US says Iran-sponsored hackers targeting health, transportation sectors

US authorities and their British and Australian counterparts warned the hackers had exploited flaws in Microsoft Exchange and Fortinet “to target a broad range of victims" across critical US sectors.

National Cyber Director Chris Inglis listens during a hearing with the House Committee on Oversight and Reform.
National Cyber Director Chris Inglis listens during a hearing with the House Committee on Oversight and Reform in the Rayburn House Office Building on Nov. 16, 2021, in Washington, DC. The hearing was held to discuss how federal agencies are combatting cyber threats and criminal hackers. — Anna Moneymaker/Getty Images

Hackers “associated with the government of Iran” are actively targeting a wide range of US sectors, including with ransomware, a cybersecurity advisory issued by US, British and Australian governments said Wednesday. 

The joint alert from the US Department of Homeland Security, the FBI, the Australian Cyber Security Center and the UK’s National Cyber Security Center said the hackers were targeting transportation, health care and public health sectors in the United States, as well as Australian organizations.  

US authorities have observed that Iranian government-sponsored hackers exploited vulnerabilities in Microsoft Exchange and Fortinet “to target a broad range of victims across multiple critical infrastructure sectors in furtherance of malicious activities" since at least March. 

The hackers “can leverage this access for follow-on operations, such as data exfiltration or encryption, ransomware and extortion,” the advisory said. The targets included a US-based hospital specializing in health care for children and a web server hosting the domain for a US municipal government. 

SUBSCRIBER EXCLUSIVE

Continue reading this exclusive analysis

Original reporting and analysis unavailable elsewhere. Subscribe to AL-MONITOR to read this story and access everything we publish