Home Active U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
ActiveCybersecurity

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

Share
us.-sanctions-iran-linked-hackers-behind-critical-infrastructure-breaches
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
Share

The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its enablers.

“We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone,” said Secretary of the Treasury Scott Bessent.

The action, codenamed Operation Economic Outcast, aims to cut the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC) from the financial “lifelines” that support the “leading state sponsor of terror.”

To that end, the sanctions designate nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks, including the digital assets sector. Specifically, the sanctions take aim at a malicious cyber group affiliated with Iran’s Ministry of Intelligence and Security (MOIS) that’s behind extensive compromises of U.S. critical infrastructure entities and financially motivated cyber theft.

“The MOIS directs several networks of cyber threat actors involved in cyber espionage in support of Iran’s political goals, which include harming American civilians,” the Treasury said.

Among those sanctioned are five individuals who were indicted by the U.S. Justice Department last week in connection with carrying out widespread compromises against U.S. entities. They are alleged to be members of the Tehran-based Mabna Institute. The names of the individuals are listed below –

Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda’i have been accused of conducting the bulk of the network compromise activity, successfully breaching and exfiltrating data from multiple U.S. critical infrastructure sector companies since at least late 2023, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions.

“This group frequently conducts computer network exploitations on behalf, or for the benefit, of Iran’s MOIS.,” the Treasury said. “The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS. This has driven some of the group to target Iranian companies.”

In summer 2024, the threat actors are believed to have broken into several local, state, and federal government offices across the U.S. A year later, Mojtaba Ghal’eh-Kuhi and Saber Shahbazi Balujeh targeted and exfiltrated data from an Iranian telecommunications company.

Arman Kahzadian, per the Treasury, has primarily focused on cryptocurrency heists, having illicitly gained control of a wallet that held more than $30,000 worth of Bitcoin in summer 2023.

TRM Labs’ analysis of the 30 wallets linked to the five Mabna Institute members has found about $16.8 million in total funds received. Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm added, holds 10 addresses that have received a collective 15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network’s on-chain volume.

Likewise, 15 wallet addresses associated with Behzad Mesri have received $1.2 million between July 12, 2019, and August 22, 2026. The combined residual balance across all 30 addresses is $202,662.

That’s not all. Earlier this January, TRM Labs disclosed how two U.K.-based front companies Zedcex and Zedxion have facilitated operational financing for IRGC, with the exchanges processing about $1 billion in funds linked to the Iranian armed forces branch. In a follow-up report last month, DomainTools said the Zedxion-Zedcex constellation exhibits all hallmarks of a financial façade ecosystem.

“Iran is not the only target here. In fact, the focus is secondary sanctions. That is the Treasury’s max pressure move. The Treasury is putting every country and platform still doing business with Iran on notice and the digital assets space is a focus of Operation Economic Outcast,” said Ari Redbord, Global Head of Policy at TRM Labs. “Operation Economic Outcast is all about truly isolating the Iranian regime on- and off-chain.”

In tandem, the U.S. Department of State’s Rewards for Justice program has announced a reward of up to $10 million for information on individuals who engage in malicious cyber activities against U.S. critical infrastructure under the direction or control of a foreign government.

Iranian threat actors have been attributed to a series of hacking campaigns since the U.S. and Israel began conducting airstrikes against the country in February 2026, including the breach of the personal email account belonging to Kash Patel, the director of the Federal Bureau of Investigation (FBI), as well as recent attacks targeting over 30 water and wastewater utilities in at least 12 U.S. states.

The cyber activities have also extended to U.S. allies such as the U.K., with suspected Iranian hackers blamed for causing a 4-day shut down of a small power plant following a cyber attack last month, according to The Telegraph. However, the U.K. government emphasized there was no risk to the wider energy system as a result of the incident, which affected a small-scale energy generator. The name of the facility was not revealed.

The “Economic D-Day” comes as SentinelOne characterized the Iran-linked activity as a multi-pronged threat comprising various clusters, each with their own distinct mission, targeting, and tradecraft. This can range from data collection and destruction to social engineering, cloud compromise, surveillance of dissidents, and opportunistic targeting of exposed operational technology assets.

“The principal strategic risk is access optionality,” security researcher Tom Hegel said in an assessment published late last month. “The same compromised account, service provider, or remote-management foothold can support intelligence collection, downstream targeting, or selective disruption as tasking changes.”

The ongoing conflict has also led to the emergence of a pro-Iran hacktivist (and faketivist) ecosystem, a decentralized mix of “jihadist-aligned cyber collectives, nationalist actors, and state-adjacent influence networks” that operate through Telegram channels and websites, shared target lists, DDoS-for-hire tools, and recycled breach data and leak-amplification campaigns, per DomainTools Investigations (DTI).

The groups’ activities are not motivated by cyber espionage, state-centric cyber operations, or long-term persistence. Rather, the end goal is to work together as a loose knit mobilization network, exert psychological, political, and economic pressure on adversaries, and participate in synchronized wartime or anti-Western/Israel messaging.

“Attack claims and propaganda often appear within hours of kinetic events,” DTI said. “Most activity remains technically unsophisticated. The strategic effect comes less from technical capability than from speed, visibility, and ideological framing that make it into news cycles. In practice these actors use cyber activity as scalable asymmetric information warfare.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Share
Related Articles

Bipartisan Lawmakers Press Commerce to Close Gaps in China Intelligence Controls

American consultants can still legally work for foreign intelligence agencies, while U.S....

CBP Intercepts Counterfeit Jewelry From China Valued at More Than $3 Million

U.S. Customs and Border Protection (CBP) officers in Indianapolis have seized what...

Debate Over Forest Management Heats Up After Record Wildfires in Europe

PARIS—France has just lived through its worst fire season in decades. More...

US Crude Prices Extend Losses as Oil Market ‘Remains in Limbo’

Crude oil prices extended their losses as traders weighed the United States’...