The GCHQ has issued a new alert to warn of a threat from targeted phishing attacks being carried out by hackers working on behalf of the Iranian government.
The National Cyber Security Centre, which is a part of the GCHQ, said cyber attackers working on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC) were using social engineering techniques to gain access to victims’ personal and business accounts online.
It said that individuals with a connection to Iranian and Middle Eastern affairs, such as current and former senior government officials, senior think tank personnel, journalists, activists and lobbyists, were at the highest risk.
The US, which has also issued an alert alongside the UK, said people associated with US political campaigns had been targeted.
Paul Chichester, director of operations at the National Cyber Security Centre, said: “With our allies, we will continue to call out this malicious activity, which puts individuals’ personal and business accounts at risk, so they can take action to reduce their chances of falling victim.
“I strongly encourage those at higher risk to stay vigilant to suspicious contact and to take advantage of the NCSC’s free cyber defence tools to help protect themselves from compromise.”
The hackers have often been impersonating contacts by email and messaging platforms, and building a rapport with victims before tricking them into sharing user credentials via a false email account login page, the cyber experts warned.
“The actors can then gain access to victims’ accounts, exfiltrate and delete messages and set up email forwarding rules,” they added.
This is a breaking story. More to follow…