Episodes › Latest
Government & Public SectorRansomware & ExtortionScams, Phishing & Social Engineering

Iran Hits US Water,Abbott Extorted for 30M Records, Teams Call Ends in Ransomware

3 days ago Hornung · Bryan · Andre

Hackers got inside America’s drinking water controls. In one Minnesota town, the tower called for water while the well sat dead. This wasn’t a data leak. Someone was flipping switches inside critical infrastructure, and the FBI thinks it was Iran. *Your attacker isn’t malware anymore. It’s a voice you decided to trust.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week’s stories for executives, owners, and operators who can’t afford to be blindsided. First, the water. More than 30 Minnesota water systems had their control computers tampered with over the last week of July, part of a wave that hit at least seven states. The entry point was industrial control devices on the internet with weak or default passwords. Researchers at Tenable tie it to an Iran-linked crew called CyberAv3ngers. Nobody demanded a ransom, and that’s the chilling part. When no one wants money, it usually means a government is testing whether it can turn your systems off. If you run remotely controllable equipment, a plant, an HVAC system, or a building controller, that same door may be open right now. Then, the healthcare giant. Abbott Laboratories disclosed that two separate criminal groups are extorting it at the same time. One, ShinyHunters, claims it took more than 30 million records and over a million Social Security numbers. The entry point was a phone call. Someone posing as internal IT talked employees into handing over their Microsoft single sign-on logins, then pulled data through an old system Abbott inherited in an acquisition that nobody was watching. No virus. No zero-day. Just a convincing voice and one over-trusted login. Finally, the one you’ll feel in your own office. Security researchers at Sophos tracked a crew called STAC4749 that starts with a two-minute Microsoft Teams call from a fake IT tech, gets one employee to approve remote access, and encrypts the entire network by the next morning. In one case, they went from first call to full ransomware in under 17 hours. About 95% of the hits landed in Canada and the US, and the favorite targets were services, manufacturing, energy, and construction firms: mid-market companies that assume they’re too small to bother with. Real internal IT does not cold-call and ask you to approve access. That one rule would have stopped every one of these. Three different targets. One common thread: the door wasn’t kicked in. Someone opened it by trusting a device, a voice, or a message. • Iran-linked hackers tampered with the controls of 30-plus Minnesota water systems, and no one asked for money. • Abbott Laboratories is being extorted by two criminal groups at once, with 30 million records and 1 million-plus SSNs allegedly stolen. • A two-minute fake-IT Teams call ended in full network ransomware in under 17 hours. • The way in for all three was trust, not clever code. • Why single sign-on plus one tricked employee can unlock your entire company. • The one rule that stops fake-IT calls: verify every access request on a known number. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Ransomware #DataBreach #Abbott #MicrosoftTeams #SocialEngineering #Vishing #CriticalInfrastructure #SmallBusiness #BusinessRisk #MSP

Catch the full breakdown every week.