Our takeDOJ charged 17 Iranians with running a years-long IP theft and ransomware operation on behalf of the IRGC and other state entities. Treat any Iranian-origin targeting of your IP or networks as state-backed, and keep critical IP off exposed systems.Cyber Resilience desk
Sources (1)
- doj_press · doj_press
What this means for you — Security leader:Review contracts and access logs for any Iranian or Middle East-based vendors and contractors; treat this as confirmed state-sponsored intellectual property theft and tighten third-party risk reviews.
What this means for you — Lean IT orgs:If you work with any suppliers or cloud services that have ties to the Middle East, ask them what controls they have against state-sponsored theft. Otherwise, continue focusing on basics like strong passwords, MFA, and timely patching.
What this means for you — MSP:Scan client environments for any Iranian or regional vendor connections and review privileged access granted to third parties; this is confirmed IRGC-linked IP theft so prioritize third-party risk conversations with every client.
What this means for you — Researcher:DOJ indictment details 17 Iranians working on behalf of the IRGC and other entities in a years-long campaign of credential theft, data exfiltration, and intellectual property theft targeting universities, companies, and government entities.