Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (11 days ago).

← Intel index

This coverage is stale.

Last updated May 22, 2026 (about 3 months ago).

people · May 22, 2026

Iranian State-Sponsored Hackers Exploit Fortinet Vulnerabilities in US Critical Infrastructure

Share the canonical public link.

Share as image

A Congressional Research Service report updated May 22, 2026 details Iranian government-sponsored actors exploiting vulnerabilities in Microsoft Exchange and Fortinet products. In one referenced campaign Iranian actors gained access to critical infrastructure organizations then conducted data theft ransomware encryption and extortion. The report covers campaigns from 2012 to 2025 attributing operations to IRGC-affiliated groups targeting ICS and OT environments.

Below validation threshold — auto-passed without scoring

Supporting evidence