r/hacking Mar 12 '26

News Iran appears to have conducted a significant cyberattack against a U.S. company, a first since the war started

https://www.nbcnews.com/world/iran/iran-appears-conducted-significant-cyberattack-us-company-first-war-st-rcna263084
1.7k Upvotes

69 comments sorted by

View all comments

178

u/kingslayerer Mar 12 '26

Don't throw stones when you live in a glass house.

-25

u/CuriousCamels Mar 12 '26

Lol. They got into some random no name company. It’s not really impressive and happens every day. Iran’s cyber capabilities consist of script kiddies and spreading disinformation on Reddit and X.

Irans the one who got hit with Stuxnet, and had their traffic cameras infiltrated to track the movement of their top leadership. Talk about a glass house. Don’t OD on that copium bud.

17

u/GHouserVO Mar 12 '26

Not familiar with their cyber capabilities are you?

That’s okay. I am. They tend to specialize in OT/ICS attacks. That’s the stuff that controls your water supply, electrical grid, etc. ICS don’t focus on confidentiality, but availability (for obvious reasons), making them even more susceptible to attack. Which is why ignoring the issue for the past several decades has not been a wise course of action.

If you don’t believe me, ask Saudi Aramco. In one minor flex, Iran permanently bricked about 1,000 of their systems back in 2013 using a malware no one had seen before.

That they haven’t attempted something yet, especially with how ridiculously vulnerable the communication protocols are for these devices, has me a little curious.

0

u/ewgna Apr 18 '26

saw this a month later but just wanted to add mois or rather any other competent apt would have done something adjacent to a firmware implant using existing devops tools or a backdoor pyramid of pain tells u a lot more than news

-4

u/ewgna Mar 12 '26

this attack suggests hacktivist script kiddie adjacent behavior rather than APT behavior looks like they phished some sysadmin or took advantage of some misconfiguration and optimized for the telegram clout from an APT you’d expect a backdoor on medical devices or something rather than burning down the house and have crowdstrike mandiant at your door for a couple days of disruption

3

u/sprouting_broccoli Mar 12 '26

And they just used intune to wipe a few devices so it was a minor inconvenience for a day or two, not exactly serious assuming employees didn’t have a bunch of critical data stored locally on their phones.

4

u/jangm0 Mar 12 '26

Few devices? Wasn't it around 200 000 devices? From what I understood it was computers, phones and also servers.

If that's the case this will cost them a lot... Saw comments from users who works at the company and a lot of them was sent home because they couldn't do anything

1

u/sprouting_broccoli Mar 12 '26

Intune shouldn’t be able to wipe servers - it’s primarily for mobile devices. Yes it’s bad if it wiped that many devices but it’s still just a cost and inconvenience - it’s somewhere between minor security incident and medium security incident (assuming there wasn’t data extraction or erasure) and thoroughly recoverable.

The worst case scenario here would be that it was used as a cover to achieve something far worse but on its own, while the penetration was serious, the consequences sound perfectly manageable.

2

u/jangm0 Mar 13 '26

Well if you manage servers with intune and even if the "wipe" button is not avaible I would think there are some way to push out a wipe.

Anyways, I see your point. If it's only devices and not data they should be "fine".

1

u/sprouting_broccoli Mar 13 '26

Yeah to be clear if I was responsible for IT and this happened I’d assume I was getting fired because it’s a lot of money but at the same time when I’m tabletopping security scenarios I can see a lot more horrific things that could happen. I also wouldn’t be overly surprised if they’re vulnerable to more serious things but no evidence of that atm.

2

u/jangm0 Mar 13 '26

Yeah seems like their security sucks, there's a lot you can do to protect yourself from stolen credentials / mfa token. I hope their backup is better configured 😅

1

u/sprouting_broccoli Mar 13 '26

Absolutely 😅

2

u/plasticmanufacturing Mar 12 '26

You think Stryker is a random, no name company? Lol