U.S. Sanctions Iranian Hackers Behind Critical Infrastructure Breaches

The U.S. Department of the Treasury has imposed sanctions on Iranian cyber actors responsible for multiple high-profile breaches of critical infrastructure, including a major U.S. energy company and a prominent Saudi Arabian utility.

Bottom line: The U.S. is increasing its economic pressure on Iran, targeting its financial connections to disrupt its cyber capabilities.

What's happening: The Treasury Department has imposed sanctions on six Iranian entities, including a hacker group known as APT33, also known as "Oiligarch," linked to the 2019 breach at Saudi Aramco, a state-owned oil company, and a 2020 breach at a major U.S. energy company, which stole sensitive data on the company's operations and infrastructure.

What to do: CISOs should review their supply chain risk management practices to ensure they are not inadvertently supporting Iranian cyber actors, and work with their vendors to implement robust cybersecurity controls to prevent similar breaches.

Source: The Hacker News