The Cyber Security and Infrastructure Security Agency (CISA) and the FBI have released new guidelines to protect American political organizations from increasing cyber threats from Iran. These threats are aimed at undermining trust in U.S. democratic institutions, especially in view of the upcoming elections.

Important findings

  • CISA and FBI warn of Iranian hackers targeting US election campaigns and officials
  • The threats come from actors linked to Iran’s Islamic Revolutionary Guard.
  • The use of social engineering techniques to compromise accounts is widespread.
  • Recommended security measures include using multi-factor authentication and password managers.

Background of the threat

CISA and the FBI have determined that Iranian cyber actors, particularly those linked to the Islamic Revolutionary Guard (IRGC), are actively seeking access to the accounts of senior government officials, journalists and political activists. These actors use social engineering to impersonate trusted contacts and direct victims to fake login sites.

Incidents and confirmations

In August, the FBI confirmed that Iran had infiltrated the campaign of Republican presidential candidate Donald Trump. Reports show that both Iran and Russia are trying to gain access to people with direct access to both parties’ presidential election campaigns. A recent Google report identified a phishing campaign targeting candidates from both parties.

Recommendations for security measures

CISA and the FBI made specific recommendations to improve the security of affected individuals:

  1. Caution with unfamiliar contacts: Be careful about unexpected contact from new accounts or phone numbers.
  2. Email security: Suspicious emails with shortened links or unusual requests should be ignored.
  3. Use MFA: Use multi-factor authentication for all email and social media accounts.
  4. Password Manager: Use password managers to generate strong, unique passwords.
  5. Alert verification: Confirm the legitimacy of alerts by visiting the relevant website directly.

Training and awareness raising

Organisations associated with national campaigns should train employees to recognise and verify suspicious messages. Implementing strong MFA protocols and regularly updating software on personal devices are also crucial to improving security.

CISA Executive Assistant Director for Cyber Security, Jeff Greene, emphasized that IRGC cyber actors pose an ongoing and growing risk. The collaboration between CISA and the FBI aims to provide timely and actionable information to minimize risks to their partners.

Sources

  • CISA Issues Guidance to Counter Iran’s Election Interference, BankInfoSecurity.