HomeSecurityUS: Iranian hackers target critical infrastructure

US: Iranian hackers target critical infrastructure

The FBI and NSA, in collaboration with CISA, have issued an urgent warning of an increased risk of cyberattacks by Iranian hackers. While there is no evidence of a coordinated campaign at this time, authorities are warning of potential targeted attacks on critical US infrastructure due to the tense geopolitical situation in the Middle East.

Iranian hackers critical infrastructure

Particular concern is expressed for companies operating in the Defense Industrial Base (DIB), especially those collaborating with Israeli defense or research institutions. Critical infrastructure such as energy, water and healthcare are also at the center of the threat.

See also: Iranian hackers leaked data of Saudi Games athletes

According to the official advisory, Iranian hackers often exploit security vulnerabilities and default passwords to infiltrate networks. A typical example is the November 2023 attack, when Unitronics programmable logic controllers (PLCs) were compromised to compromise a water utility in Pennsylvania.

At the same time, these groups act either autonomously or together as hacktivists, launching DDoS and defacing attacks, often accompanied by politically charged messages. Their actions are promoted on social networks, mainly through Telegram and X (formerly Twitter), enhancing the psychological impact of the attacks.

See also: US Homeland Security: Warns of attacks by Iranian hackers

Iranian hackers collaborate with Russian ransomware gangs

Iranian cybercriminal activity appears to be escalating, as new reports from US agencies show they are increasingly involved in ransomware, often in collaboration with notorious Russian groups such as NoEscape, RansomHouse and ALPHV (also known as BlackCat). Many of these attacks have targeted Israeli businesses, with the perpetrators encrypting critical data and leaking sensitive information online.

In some cases, instead of ransom, attackers opt for purely destructive tactics, using data wipers to erase their victims' data, causing severe operational disruptions.

Protection measures and best security practices

To address the growing threats from Iranian hackers, CISA, NSA, FBI, and the U.S. Department of Defense are calling on organizations—particularly those managing critical infrastructure—to implement a set of immediate steps to strengthen cybersecurity:

  • Isolation of OT/ICS systems from the internet and restriction of remote access.
  • Change default passwords and use strong, unique credentials across all accounts.
  • Enable multi-factor authentication (MFA) for critical services.
  • Immediate installation of software updates, especially on exposed systems.
  • Continuous monitoring for suspicious activity on networks and servers.
  • Create and test recovery and incident response plans, ensuring that backups are operational and accessible.

See also: Iranian man confesses to involvement in Robbinhood ransomware

US: Iranian hackers target critical infrastructure

The authorities refer to additional material, such as Iran Threat Overview CISA's and related reports FBI, for organizations wishing to be more thoroughly informed and prepared.

The situation is particularly worrying — not only because of the increased activity from state-sponsored threat actors, but also because a new phase of alliances between different cybercrime groups with geopolitical motives is emerging. The collaboration of Iranian hackers with Russian ransomware gangs (such as ALPHV/BlackCat) shows that the lines between hacktivism, espionage, and pure cybercrime are blurring.

Global geopolitical tension is now being transferred digitally, with cyberspace becoming the new front lines. Countries or businesses that do not adapt to new cybersecurity requirements in a timely manner become easy targets.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS