US says Iran-sponsored hackers targeting health, transportation sectors
US authorities and their British and Australian counterparts warned the hackers had exploited flaws in Microsoft Exchange and Fortinet “to target a broad range of victims" across critical US sectors.
Hackers “associated with the government of Iran” are actively targeting a wide range of US sectors, including with ransomware, a cybersecurity advisory issued by US, British and Australian governments said Wednesday.
The joint alert from the US Department of Homeland Security, the FBI, the Australian Cyber Security Center and the UK’s National Cyber Security Center said the hackers were targeting transportation, health care and public health sectors in the United States, as well as Australian organizations.
US authorities have observed that Iranian government-sponsored hackers exploited vulnerabilities in Microsoft Exchange and Fortinet “to target a broad range of victims across multiple critical infrastructure sectors in furtherance of malicious activities" since at least March.
The hackers “can leverage this access for follow-on operations, such as data exfiltration or encryption, ransomware and extortion,” the advisory said. The targets included a US-based hospital specializing in health care for children and a web server hosting the domain for a US municipal government.