Also available in Persian — نسخه فارسی EN فا
❓ Unknown

Iran Police: Over Two Thousand Cases of 'WannaCry' Ransomware Infection Reported

Jan 27, 2026 January 27, 2026 2 min read 📰 Radio Farda
📋 Key Takeaway

Iran's police report over 2,100 infections of the 'WannaCry' ransomware, primarily affecting government and private organizations. The ransomware demands a $300 Bitcoin payment to avoid data loss. This incident raises concerns about cybersecurity in Iran and the potential for broader implications given the ransomware's global impact.

🔍 Quick Context Guide
💡 Bottom Line: The WannaCry ransomware infections in Iran reveal significant cybersecurity vulnerabilities that could have broader implications for national and regional security.

👥 Key Players

Saeed Montazeralmahdi MENTIONED
Spokesperson for the Iranian police
"He provides official information regarding cybersecurity incidents in Iran and represents the government's response to such threats."
WannaCry Ransomware MENTIONED
Cyber threat
"This ransomware has a significant global impact, affecting various countries and raising concerns about cybersecurity vulnerabilities."
Microsoft MENTIONED
Technology company
"They are responsible for providing software updates and patches that can mitigate vulnerabilities exploited by ransomware like WannaCry."

📰 What Happened

Iranian police reported over 2,100 cases of WannaCry ransomware infections, primarily affecting government and private organizations. The ransomware demands a $300 Bitcoin payment to avoid data loss.

  • The ransomware first appeared in Iran on May 9, 2023.
  • Concerns have been raised about the potential for broader cyberattacks in the region and globally.

💡 Why It Matters

🇮🇷 For Iran: This incident highlights vulnerabilities in Iran's cybersecurity infrastructure, particularly concerning government organizations.
🌍 Regional: The attack raises concerns about the potential for increased cyber warfare in the region, especially given accusations of state-sponsored cyberattacks.
🌐 International: It underscores the global nature of cybersecurity threats and the interconnectedness of nations in addressing such challenges.

📚 Background

WannaCry is a notorious ransomware that has affected numerous countries, demanding payment in Bitcoin to unlock data. Cybersecurity remains a critical issue as outdated software is often exploited.

Ransomware attacks Cybersecurity vulnerabilities
📡 Source: STATE MEDIA
📊 Confidence: 70%
The information comes from an official police spokesperson, which may reflect the government's perspective on the issue.

The spokesperson for the Iranian police stated that the 'WannaCry' ransomware has infiltrated at least 2,100 computers in Iran, with most infections related to government organizations and private companies. The 'WannaCry' ransomware, which has been observed in many countries worldwide, disrupted numerous business and economic activities from Mumbai in India to Los Angeles in the United States in early July. This ransomware threatens computer owners that if they do not pay a ransom of $300 in Bitcoin, they will lose the data stored on their computers. Saeed Montazeralmahdi, the spokesperson for the Iranian police, said on the morning of July 14 that at least 2,100 cases of infection have been reported in Iran, and 'a large portion of the infections are related to government and private organizations.' Montazeralmahdi also mentioned, 'It seems that data theft is not occurring, and the ransomware is only after money.' The Iranian police spokesperson urged citizens to 'keep their infected files' and not to use antivirus software from outside, 'as the police are working on an antivirus to recover the data.' No details of these measures have been provided. Despite Montazeralmahdi's statements, it has been reported that security agencies and cybersecurity experts doubt that the aim of ransomware attacks like 'WannaCry' is solely extortion. According to some of them, the ransom amount seems very small, and the hackers' goal may be more destructive actions than financial gain. However, the minimum requested ransom of $300 is not a small amount for private computers in many countries. The 'WannaCry' ransomware was first observed in Ukraine. Kyiv has repeatedly accused Moscow of cyberattacks on its infrastructure and institutions. The Russian government has denied these allegations. It appears that the 'WannaCry' attack primarily targets computers running outdated and unpatched versions of Microsoft. Microsoft has also provided patches in recent weeks to help prevent the spread of this virus. The Iranian police spokesperson stated that this ransomware was first identified in Iran on May 9, a week before reports of its widespread release in Asia. In this context, concerns about a widespread cyberattack in dozens of countries around the world have increased with the start of the workweek, including the ransomware attack on China and warnings about escalating attacks in Europe.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →