• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Iran-backed hackers are targeting U.S. with ransomware. Here’s how companies can protect themselves

By
Jonathan Vanian
Jonathan Vanian
By
Jonathan Vanian
Jonathan Vanian
November 17, 2021, 2:36 PM ET

U.S. officials are urging companies to back up their data, update software, and disable hyperlinks in employee emails to protect themselves against Iranian hackers who are targeting firms and critical infrastructure with ransomware. 

The cybersecurity tips were part of a warning about Iran-backed hackers issued on Wednesday by the Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, the Australian Cyber Security Centre, and the U.K’s National Cyber Security Centre.

The coalition said that hackers associated with Iran’s government have been trying to exploit vulnerabilities in Microsoft’s Exchange email server product and certain products sold by networking and security firm Fortinet. After exploiting the software flaws, the hackers then carry out “follow-on operations” involving ransomware, extortion, and data theft to further compromise their victims, which have included U.S. transportation and healthcare firms and unspecified Australian organizations.

Some of the recent attacks identified include a June 2021 attack in which the Iranian hackers were able to compromise a U.S. children’s hospital. 

Earlier this week, Microsoft released research indicating a rise in activity from malicious actors based Iran that are “increasingly utilizing ransomware to either collect funds or disrupt their targets.” That the hacking groups are believed to be linked to Iran’s government is significant considering most ransomware groups are criminal syndicates.

The coalition said that companies using Microsoft Exchange email servers and Fortinet products should inspect their products and corporate networks for signs that they have been compromised. For instance, IT managers could review their corporate network’s antivirus logs to discover if they were unexpectedly turned off.

Companies also should back up all corporate data and create password-protected copies that are maintained offline. They should also audit employee accounts that have administrator privileges and require that all user accounts require logins with strong, unique passwords.   

Organizations should also consider adding an “email banner” that indicates whether an email sent to an employee came from a third party, which could be a sign of a phishing attack.

More tech coverage from Fortune:

  • Biden’s new FCC chair may signal a return to net neutrality, but it could take a while
  • Cybersecurity experts say public-private partnership is the key to preventing future attacks
  • GM’s heated seats and steering wheels are the latest casualty of the chip shortage
  • CEOs say the pandemic spurred companies to make unlikely tech transformations
  • IBM debuts quantum machine it says no standard computer can match

Subscribe to Fortune Daily to get essential business stories straight to your inbox each morning.

About the Author
By Jonathan Vanian
LinkedIn iconTwitter icon

Jonathan Vanian is a former Fortune reporter. He covered business technology, cybersecurity, artificial intelligence, data privacy, and other topics.

See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.