A joint advisory issued Oct. 16 by the FBI, the Cybersecurity and Infrastructure Security Agency, the National Security Agency and international agencies warn of a threat of Iranian cyber actors using brute force and other techniques to compromise organizations in health care and other critical infrastructure sectors. The actors are likely attempting to obtain credentials and information about the victim's network that could be sold to cybercriminals, the advisory said. Since Oct. 2023, these cyber actors have used forceful actions such as password spraying and multifactor authentication "push bombing" to compromise user accounts to gain access to organizations. Additionally, they frequently modified MFA registrations which enabled persistent access and performed discovery on compromised networks to obtain additional credentials and other information to potentially gain additional access points. 

“This alert emphasizes the ongoing threat to the U.S. health care sector, including hospitals, from Iranian cyber threat actors,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Once these threat actors gain initial access to a system, they are selling that access to other threat actors who conduct much more sophisticated attacks, including ransomware attacks, often impacting the delivery of health care to patients and entire communities. Any ransomware attack which disrupts or delays patient care is a threat-to-life crime and the actors identified in this alert could be considered co-conspirators in these attacks. Hospitals should require the use of unique, complex passwords, which are changed regularly, and employ phishing-resistant multifactor authentication to help defend against these attacks. The voluntary Cybersecurity Performance Goals referenced in the alert, which the AHA helped to develop, are the best first line of defense against relatively unsophisticated initial access attacks like these. The AHA encourages hospitals to implement the CPGs to enhance their overall cybersecurity posture and help to thwart adversaries like these.” 

For more information on this or other cyber and risk issues contact Gee at sgee@aha.org. For the latest threat information and other cyber and risk resources visit www.aha.org/cybersecurity.

Headline
The FBI and the Department of Justice Aug. 26 announced the disruption of a China-linked hacking group known as QTFY. The group, which also identifies as QT…
Headline
Boston Scientific, a large supplier of medical devices, said in an Aug. 26 statement posted on its website that on Aug. 25 it “identified a cybersecurity…
Headline
Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart…
Headline
The National Security Agency and other federal agencies released a joint advisory Aug. 18 warning of active cyber threats to Siemens S7 Series programmable…
Headline
A joint advisory released Aug. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services provides…
Headline
The Department of Health and Human Services Aug. 14 released a request for comments through the Office of the National Coordinator for Health IT on a proposed…