Iran appears to have conducted a significant cyberattack against a U.S. company, a first since the war started

2026-03-14T08:51:41Z10e3b00a5ea1be5a040776d3eeaed7a9403d3468b046bc070e7bbd3e2ad9bfca
critical infrastructurecyberattackeuropolfake remote supporthealthcareiranmedical devicemicrosoftphishing kitpro-iranransomwarestate‑linkedtakedowntrustconnecttycoon 2fa

What happened

Proofpoint published multiple intelligence and news items in Feb–Mar 2026 highlighting an apparent escalation in Iranian-aligned cyber activity and several takedowns of criminal tooling. Key items: reports that Iran (or pro‑Iran operators) conducted a significant cyberattack against a U.S. company — including claims of an attack on a major U.S. medical‑device maker — marking a notable escalation since the war began; a global coalition (Europol, vendors, Microsoft involvement) dismantled the “Tycoon 2FA” phishing kit and a related global hacking service; and warnings about a fake remote‑support

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
proofpoint_blog
Record identifier
10e3b00a5ea1be5a040776d3eeaed7a9403d3468b046bc070e7bbd3e2ad9bfca
Enrichment time
2026-03-14T08:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Iran appears to have conducted a significant cyberattack against a U.S. company, a first since the war started · Baitaphish