US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
The United States imposed sanctions on several Iranian nationals for cyberattacks on critical infrastructure, days after the United Kingdom disclosed a cyber intrusion at a small power plant. The timing suggests coordinated disclosure between Washington and London.
The Treasury Department's action targets individuals linked to operations against infrastructure networks. The UK incident involved a power generation facility, though officials have not publicly attributed the intrusion to the sanctioned actors. The sequence—UK disclosure followed by US sanctions—indicates intelligence-sharing and joint messaging on Iranian cyber activity.
Iran has expanded its targeting of industrial control systems over the past three years, moving beyond reconnaissance to operations that could disrupt physical processes. Energy infrastructure remains a priority target, particularly in countries perceived as aligned with US policy in the Middle East.
- 01Energy operators in allied nations face elevated targeting from Iranian cyber units
- 02Sanctions framework now extends to ICS intrusions, not just data theft or espionage
- 03UK-US intelligence coordination on critical infrastructure defense is tightening
- 04Iranian actors operating abroad face increased legal and travel restrictions
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.
Toronto children's hospital breached again, employee data stolen
The Hospital for Sick Children disclosed a data theft incident linked to third-party software, two years after a disruptive ransomware attack.