Security Stop Press : Beware of Iranian-Backed Spear Phishing Attacks

The UK’s National Cyber Security Centre (NCSC) and its US counterparts have issued a high-alert warning over a surge in spear-phishing attacks backed by Iran.

These attacks, linked to Iran’s Islamic Revolutionary Guard Corps (IRGC), are reportedly targeting politicians, journalists, activists, and others involved in Middle Eastern affairs.

The attackers are using social engineering techniques, impersonating trusted figures (e.g. colleagues or journalists) via email and messaging platforms to gain victims’ trust. The goal is to trick individuals into providing email credentials through fake log-in pages, thereby granting the attackers full access to sensitive communications and data. This poses significant risks not only to personal and business accounts but also to national security, as these compromised emails may be used to further cyber-espionage efforts.

The NCSC warns that these spear-phishing campaigns are escalating amidst geopolitical tensions, particularly as investigations into Iranian cyber operations grow. Recent developments include the indictment of three IRGC members in the US for hacking attempts related to political campaigns.

The advice is to implement multi-factor authentication (MFA), regularly update cybersecurity protocols, and to remain vigilant against unsolicited communications. Proactive steps, such as using the NCSC’s cyber defence tools, may also help mitigate the threat.

Security Stop Press : Insurance Industry and Security Coalition To Tackle Ransomware

Three major UK insurance associations have united in a coalition with GCHQ’s National Cyber Security Centre (NCSC) to help reduce ransom payments made by victims of cybercrime.

The Unprecedented cross-sector coalition is comprised of the NCSC and the Association of British Insurers (ABI), British Insurance Brokers’ Association (BIBA) and the International Underwriting Association (IUA).

With Ransomware being the biggest day-to-day cyber security threat to UK organisations, the coalition, working closely with the NCSC, has developed a set of guidelines and a frameworks for a broad range of stakeholders including insurance providers, businesses, and cyber security professionals, aimed at reducing the frequency and impact of ransomware attacks.

NCSC CEO Felicity Oswald said: “It’s really encouraging to see all corners of the insurance industry unite to support victim organisations with guidance that will help them to better understand their options and reduce harm and disruption to their businesses.”