A joint advisory issued Oct. 16 by the FBI, the Cybersecurity and Infrastructure Security Agency, the National Security Agency and international agencies warn of a threat of Iranian cyber actors using brute force and other techniques to compromise organizations in health care and other critical infrastructure sectors. The actors are likely attempting to obtain credentials and information about the victim's network that could be sold to cybercriminals, the advisory said. Since Oct. 2023, these cyber actors have used forceful actions such as password spraying and multifactor authentication "push bombing" to compromise user accounts to gain access to organizations. Additionally, they frequently modified MFA registrations which enabled persistent access and performed discovery on compromised networks to obtain additional credentials and other information to potentially gain additional access points. 

“This alert emphasizes the ongoing threat to the U.S. health care sector, including hospitals, from Iranian cyber threat actors,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Once these threat actors gain initial access to a system, they are selling that access to other threat actors who conduct much more sophisticated attacks, including ransomware attacks, often impacting the delivery of health care to patients and entire communities. Any ransomware attack which disrupts or delays patient care is a threat-to-life crime and the actors identified in this alert could be considered co-conspirators in these attacks. Hospitals should require the use of unique, complex passwords, which are changed regularly, and employ phishing-resistant multifactor authentication to help defend against these attacks. The voluntary Cybersecurity Performance Goals referenced in the alert, which the AHA helped to develop, are the best first line of defense against relatively unsophisticated initial access attacks like these. The AHA encourages hospitals to implement the CPGs to enhance their overall cybersecurity posture and help to thwart adversaries like these.” 

For more information on this or other cyber and risk issues contact Gee at sgee@aha.org. For the latest threat information and other cyber and risk resources visit www.aha.org/cybersecurity.

Headline
A joint advisory released April 23 from U.S. and international cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency, FBI,…
Headline
FBI Co-deputy Director Andrew Bailey discussed a rise in cyber and physical threats impacting health care. He discussed health care as the top critical…
Headline
Health care and public health was the top sector targeted for cyberthreats in 2025, according to the FBI’s latest annual report on internet crimes. There were…
Headline
The Cybersecurity and Infrastructure Security Agency released an alert March 27 on a vulnerability in F5 BIG-IP Access Policy Manager software that is being…
Headline
The FBI released an alert March 20 warning of a technique used by cyber actors working on behalf of the Iranian government to conduct malicious cyber activity…
Headline
The Cybersecurity and Infrastructure Security Agency March 18 released an alert urging U.S. organizations to harden their endpoint management systems following…