New York Department of Health Issues Urgent Cybersecurity Warning Following U.S. Strikes on Iranian Nuclear Facilities

The New York State Department of Health has issued an urgent cybersecurity advisory (the Advisory) warning of increased threat levels and a higher likelihood of cybersecurity attacks from Iranian state-backed actors following U.S. military strikes on the Fordow, Natanz, and Isfahan nuclear facilities in Iran.  The Advisory warns that “intelligence sources indicate a high likelihood of cyberattacks and heightened cybersecurity threat activity against the critical infrastructure of the United States and North Atlantic Treaty Organization (NATO) member states.”

Further, the Advisory recommends that healthcare providers and related organizations should “review, update and ensure organizational awareness of their disaster and emergency response plan and cybersecurity incident response plan, and verify they have adequate backups of critical systems and data.”  The Advisory also recommends that healthcare organizations should tighten their physical security controls and should “secure their Operational Technology (OT) systems against cyberattack[s] by removing OT connections to the public internet, chang[ing] default passwords and us[ing] strong, unique passwords, secur[ing] remote access to OT networks, and segment[ing] IT and OT networks.”

The Advisory comes on the heels of a bulletin published by the Department of Homeland Security (DHS) on June 22, 2025, in which DHS warned that cyberattacks by “by pro-Iranian hacktivists…and cyber actors affiliated with the Iranian government” are likely.  Moreover, the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Defense Cyber Crime Center (DC3), and the National Security Agency (NSA) issued a joint advisory on June 30, 2025, warning that organizations should “remain vigilant for potential targeted cyber activity against U.S. critical infrastructure and other U.S. entities by Iranian-affiliated cyber actors.”

This increase in the national cybersecurity threat posture strongly resembles the level reached in February of 2020 following the U.S. strike that killed Major General Qassem Soleimani of Iran’s Quds Force.  At that time, CISA and the New York Department of Financial Services issued similar threat escalation alerts.  The national threat posture concerning Iranian backed threat actors again increased in August of 2024, when DHS warned that Iran-based cyber actors were collaborating with ransomware organizations to increase attacks on U.S. based organizations across both the public and private sectors—including the healthcare sector.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Alston & Bird

Written by:

Alston & Bird
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Alston & Bird on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide