Government

US Agencies Warn Political Campaigns of Iranian Phishing Attacks

CISA and the FBI have issued a warning on Iranian phishing attacks targeting national political organizations and campaigns.

Iranian malware

The US cybersecurity agency CISA and the FBI have issued a warning about Iranian threat actors targeting and breaking into the email accounts of individuals associated with national political entities.

Aiming to stir up conflict and undermine confidence in the US democracy, threat actors linked to the Iranian Government’s Islamic Revolutionary Guard Corps (IRGC) have been targeting government officials, activists, journalists, think tank personnel, and lobbyists, the agencies say in a joint advisory.

“IRGC actors seek access to American personal and business accounts using social engineering techniques that target email and chat applications,” it added.

The adversaries were seen impersonating known individuals, sending requests for interviews, invites for high-profile events, and solicitations from US campaigns and elections to deceit the intended victims into accessing a spoofed email login page.

The phishing page prompts victims to enter their usernames and passwords, which are harvested by the threat actors and used to access their accounts.

“Although we have not seen this actor do so, some nation-state actors use generative artificial intelligence capabilities to increase the believability of social engineering efforts,” the agencies said.

Advertisement. Scroll to continue reading.

Organizations and individuals at risk of such phishing attempts are advised to enhance their security and resilience, and CISA and the FBI have provided mitigation recommendations, such as using phishing-resistant multi-factor authentication (MFA).

Entities associated with national political campaigns and elections are advised to be wary of unsolicited contacts from unknown individuals or people claiming to use new accounts or phone numbers, unusual emails from known individuals, accounts delivering links or files via social media, emails conveying suspicious alerts, and unsolicited messages containing shortened links.

In addition to using phishing-resistant MFA for all accounts, at-risk individuals are urged to use password manager, refrain from clicking on links in emails, chat messages, or social media alerts, and ensure OS and applications are fully patched.

Related: US Charges 3 Iranians Over Presidential Campaign Hacking

Related: Iran Behind Text Messages Calling for Revenge Over Quran Burnings

Related: False Air Raid Sirens Possibly Triggered by Iranian Cyberattack

Related Content

Cybercrime

The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees.

Cybercrime

Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.

Cybercrime

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.

Cybercrime

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.

Government

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. 

ICS/OT

Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.

Data Breaches

The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. 

Nation-State

The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version