Cyber Resilience
← All news
Confirmed

17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities

Our takeDOJ charged 17 Iranians with running a years-long IP theft and ransomware operation on behalf of the IRGC and other state entities. Treat any Iranian-origin targeting of your IP or networks as state-backed, and keep critical IP off exposed systems.
Sources (1)
What this means for you — Security leader:Review contracts and access logs for any Iranian or Middle East-based vendors and contractors; treat this as confirmed state-sponsored intellectual property theft and tighten third-party risk reviews.
What this means for you — Lean IT orgs:If you work with any suppliers or cloud services that have ties to the Middle East, ask them what controls they have against state-sponsored theft. Otherwise, continue focusing on basics like strong passwords, MFA, and timely patching.
What this means for you — MSP:Scan client environments for any Iranian or regional vendor connections and review privileged access granted to third parties; this is confirmed IRGC-linked IP theft so prioritize third-party risk conversations with every client.
What this means for you — Researcher:DOJ indictment details 17 Iranians working on behalf of the IRGC and other entities in a years-long campaign of credential theft, data exfiltration, and intellectual property theft targeting universities, companies, and government entities.