Hackers “associated with the government of Iran” are actively targeting a wide range of US sectors, including with ransomware, a cybersecurity advisory issued by US, British and Australian governments said Wednesday.
The joint alert from the US Department of Homeland Security, the FBI, the Australian Cyber Security Center and the UK’s National Cyber Security Center said the hackers were targeting transportation, health care and public health sectors in the United States, as well as Australian organizations.
US authorities have observed that Iranian government-sponsored hackers exploited vulnerabilities in Microsoft Exchange and Fortinet “to target a broad range of victims across multiple critical infrastructure sectors in furtherance of malicious activities" since at least March.
The hackers “can leverage this access for follow-on operations, such as data exfiltration or encryption, ransomware and extortion,” the advisory said. The targets included a US-based hospital specializing in health care for children and a web server hosting the domain for a US municipal government.
AL-MONITOR All-Access gives you unlimited access to all our journalism, the full Daily Briefing, exclusive interviews, premium newsletters, and live events — for less than $2/week.