A joint advisory issued Oct. 16 by the FBI, the Cybersecurity and Infrastructure Security Agency, the National Security Agency and international agencies warn of a threat of Iranian cyber actors using brute force and other techniques to compromise organizations in health care and other critical infrastructure sectors. The actors are likely attempting to obtain credentials and information about the victim's network that could be sold to cybercriminals, the advisory said. Since Oct. 2023, these cyber actors have used forceful actions such as password spraying and multifactor authentication "push bombing" to compromise user accounts to gain access to organizations. Additionally, they frequently modified MFA registrations which enabled persistent access and performed discovery on compromised networks to obtain additional credentials and other information to potentially gain additional access points. 

“This alert emphasizes the ongoing threat to the U.S. health care sector, including hospitals, from Iranian cyber threat actors,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Once these threat actors gain initial access to a system, they are selling that access to other threat actors who conduct much more sophisticated attacks, including ransomware attacks, often impacting the delivery of health care to patients and entire communities. Any ransomware attack which disrupts or delays patient care is a threat-to-life crime and the actors identified in this alert could be considered co-conspirators in these attacks. Hospitals should require the use of unique, complex passwords, which are changed regularly, and employ phishing-resistant multifactor authentication to help defend against these attacks. The voluntary Cybersecurity Performance Goals referenced in the alert, which the AHA helped to develop, are the best first line of defense against relatively unsophisticated initial access attacks like these. The AHA encourages hospitals to implement the CPGs to enhance their overall cybersecurity posture and help to thwart adversaries like these.” 

For more information on this or other cyber and risk issues contact Gee at sgee@aha.org. For the latest threat information and other cyber and risk resources visit www.aha.org/cybersecurity.

Headline
The AHA provided comments Sept. 30 to the Senate Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia and…
Headline
The FBI Sept. 29 announced an arrest of one of the alleged leaders of ShinyHunters, a cybercriminal group linked to cyberattacks in the U.S. and…
Headline
The FBI and the Cybersecurity and Infrastructure Security Agency have released a fact sheet for critical infrastructure organizations on ways to reduce risk…
Headline
The AHA will host a webinar Sept. 30 at 1 p.m. ET on ways healthcare organizations can build an effective, closed-loop cybersecurity program designed…
Headline
New guidance from the Cybersecurity and Infrastructure Security Agency encourages healthcare organizations to consider internal network and internet facing…
Headline
The National Institute of Standards and Technology and the Cybersecurity and Infrastructure and Security Agency have released guidelines to protect…