UK intelligence agency warns of new Iran cyber threat

What fake MRI spyware scam means for UK cyber insurance

UK intelligence agency warns of new Iran cyber threat

Cyber

By Matthew Sellers

Journalists, activists and government critics worldwide have been targeted with spyware hidden inside what looks like an ordinary hospital file: an MRI scan report. That's the finding of a joint advisory from the UK's National Cyber Security Centre (NCSC), the FBI and the Dutch AIVD, which says Iranian state actors have run a long campaign against people the regime sees as a threat. 

The malware, tracked as "Chosen Brick", lifts contacts, emails and social media messages from infected devices, and can capture screen content and switch on a microphone, according to the agencies' technical guidance. Stolen data has since turned up on pro-Iranian leak sites. 

A patient, personal con 

What's notable is the legwork behind each attack. Operators research a target, then contact them via WhatsApp or Telegram posing as someone trustworthy, building rapport before nudging them toward a file: sometimes a fake app, sometimes a document dressed up as medical results.  

A convincing MRI file from a familiar-seeming contact is far more likely to be opened than a generic phishing email, and once opened, the malware survives a reboot. Both agencies say it targets only Windows machines and has been deployed on behalf of Iran's Ministry of Intelligence and Security since at least 2023 the FBI says. 

Paul Chichester, the NCSC's director of operations, said the campaign shows how Iran "ruthlessly uses digital surveillance in pursuit of its aim to repress critics" of the regime. Iran's embassy in London did not respond to a request for comment. 

Why this belongs on an insurance desk 

The named targets are dissidents and journalists, but the tradecraft matches tactics increasingly used against executives and family offices. As the personal cyber risk market has told brokers, high-profile clients are now targeted as individuals, their own digital footprint used to build the trust that gets a file opened.  

There's a device problem too: the NCSC notes attackers often try a work device first, then ask targets to open the file on a personal phone if corporate controls block it, a gap bring-your-own-device policies need personal cyber cover to anticipate. 

The attribution question 

Naming a government as the culprit can trigger a war exclusion, and the FBI has attributed this malware to a specific Iranian ministry, close to the territory covered by the state-backed cyberattack exclusions Lloyd's has required since 2023.  

George Grimshaw of Clear Group has told Insurance Business UK that conflict-zone tension brings "the unfortunate byproduct of war in these territories and cyber warfare being employed." The personal harm described here sits well short of the "major detrimental impact on a state" language these exclusions target, so automatic exclusion is unlikely, but it's a live prompt to walk state-exposed clients through their wording. 

The bigger pattern 

This fits a wider trend. The NCSC's latest Annual Review recorded 204 "nationally significant" cyber incidents in the year to August 2025, more than double the 89 the year before, with the most serious cases up around 50%. CyberCube has flagged Iran as one of several nation-state "hot zones" it expects to keep complicating how the (re)insurance market prices state-backed risk. 

What brokers can do with this 

For clients who might see themselves here, executives, journalists, NGOs, anyone with a public profile, a personal cyber or social engineering endorsement can close the gap a corporate policy leaves at the office network.  

Device hygiene still matters: the malware only worked once a file was opened, and unsolicited files via messaging apps remain the way in. Worth stressing too that the trust-building is the real warning sign, not just the attachment; staff trained only to spot dodgy files miss earlier cues, like a contact who's oddly well-informed or shifts the chat to a personal app. 

Gary Barlet of Illumio summed up the problem: too many "organisations and individuals still underestimate how often they're being targeted." For an industry that prices exactly that risk, it's a fair description of the job ahead. 

Keep up with the latest news and events

Join our mailing list, it’s free!