Skip to main content

FBI warns U.S. energy and defense firms over hacking threat

A row of padlocks on a computer screen. The middle one is colored red and is open, indicating it is insecure.
Image used with permission by copyright holder
It’s been a week when large-scale hacking attempts have once again hit the headlines, and now the FBI is warning energy and defense companies in the U.S. about serious threats emanating from Iran: Reuters reports that the Bureau is telling firms to be on the alert based on information gathered from its own online activities.

The documents seen by Reuters tally with the recent findings of security firm Cylance, which believes that Iranian-based hackers have been focusing on infrastructure targets in the United States for over two years. If an energy, defense or educational organization were to be exposed in the same way that Sony Pictures has, then the effects could be far-reaching — which is why the FBI is now communicating with companies.

The leaked documents seen by Reuters go into technical detail about the type of hacks that might be attempted as well as how they can be stopped — the FBI is asking companies to get in touch immediately if they believe they’ve been the subject of a security exploit. While the agency doesn’t directly point the finger at the Iranian government, it reports that malicious activity has been traced to IP addresses within the country.

Iran has its own reasons to be on guard: Symantec recently published details of a malware program called Regin, similar to the Stuxnet code that destroyed Iranian nuclear systems in 2012. Symantec says Regin is being used by a “technically advanced” nation such as the United States or China.

As for Cylance’s report — which seems to refer to the same threat as the FBI’s warning — it says that an Iranian group referred to as ‘Cleaver’ is looking to penetrate hospitals, military institutions, energy firms and transport targets. The U.S., Canada, the U.K., China and Qatar are among the countries who are believed to have been on the group’s radar. So far, no critical infrastructure systems have been severely compromised.

It’s a reminder that large-scale cyber warfare is being waged in the background while we idly click around our favorite news and social media sites — and it looks like the stakes are getting higher.

Editors' Recommendations

David Nield
Dave is a freelance journalist from Manchester in the north-west of England. He's been writing about technology since the…
Insulin pumps recalled for vulnerability; concerns raised over medical IoT hacks
fitbit resting heart rate study medicine health glasses hospital clinic organ prescription doctor medical medic healthcare ap

Medical device company Medtronic is recalling a number of insulin pumps after discovering they are vulnerable to hacks -- and there's no way to patch the security holes. The FDA announced the vulnerability in the MiniMed 508 and Paradigm pumps this week, and Medtronic has sent a letter to around 4,000 patients currently using the devices.

"The FDA is warning patients and health care providers that certain Medtronic MiniMed insulin pumps have potential cybersecurity risks," the FDA said in its advisory. "Patients with diabetes using these models should switch their insulin pump to models that are better equipped to protect against these potential risks."

Read more
Russian hackers behind ‘world’s most murderous malware’ probing U.S. power grid
hydrostor grid of the future power mem4

A hacking group linked to the Russian government has been attempting to breach the U.S. power grid, Wired reports.

Security experts from the non-profit group the Electric Information Sharing and Analysis Center (E-ISAC) and security firm Dragos tracked the hackers -- and warn that the group has been probing the grid for weaknesses, searching for ways that they could access U.S. systems.

Read more
Data breach of unknown entity exposes private data of 80 million U.S. households
Stock photo of lock and data

Security researchers have recently discovered and reported an unprotected database that exposed the personal information of 80 million U.S. households to potential data security threats like identity theft.

According to PCWorld, a team of security researchers from a site known as vpnMentor discovered that the database contained unencrypted data that exposed information such as full street addresses, full names, ages, and dates of birth. Most unsettling was the fact that the data also included “exact longitude and latitude” locations for individuals. The researchers also reportedly found “coded references” to other pieces of personal information such as details on income, gender, marital status, and homeowner status. Interestingly though, the data only seems to expose the information of people ages 40 and older.

Read more