Skip to main content
SQD
Intelligence Terminal // CORE_NODE_01
// AD SLOT — top

// DOSSIER — us-treasury-sanctions-iranian-hackers-critical-infrastructure

MIDDLE EAST AMERICAS UNITED STATES IRAN CYBER POLICY INDUSTRY

US Treasury Sanctions Iranian Hackers Over Critical Infrastructure Breaches

REL_TIME: 25 Aug 2026 21:43Z · LANG: EN

// Disseminate
US Treasury Sanctions Iranian Hackers Over Critical Infrastructure Breaches
Unnamed artist working for US Treasury Department · Public domain · source
// AD SLOT — mid

On August 24, 2026, the U.S. Department of the Treasury announced sweeping sanctions against five Iranian cyber actors associated with the Ministry of Intelligence and Security (MOIS) and the Mabna Institute. Part of a massive, 60-entity sanctions package dubbed 'Operation Economic Outcast' or 'Economic D-Day,' the action targets individuals responsible for hacking U.S. critical infrastructure—including energy, defense, healthcare, and government sectors—since late 2023. The Treasury's actions, which run alongside a State Department reward of up to $10 million for information, aim to completely isolate the Iranian regime financially. Blockchain analysis revealed these actors also engaged in cryptocurrency theft for personal enrichment, receiving millions of dollars across linked digital wallets.

// Background

The sanctions come amid heightened tensions and a surge in Iranian cyber activity following U.S. and Israeli airstrikes against Iran in February 2026. Recent cyber operations attributed to Iran-aligned groups include the breach of FBI Director Kash Patel's personal email account, cyberattacks affecting over 30 water and wastewater utilities across 12 U.S. states, and a cyberattack that caused a four-day shutdown of a small power plant in the United Kingdom. The Mabna Institute, with which the sanctioned hackers are affiliated, has historically acted as a hacking-for-hire contractor for Iran's Islamic Revolutionary Guard Corps (IRGC), stealing terabytes of academic and intellectual property.

// Key Developments

  • The U.S. Treasury sanctioned five Iranian nationals (Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, Mojtaba Ghal’eh-Kuhi, and Arman Kahzadian) for cyberattacks on U.S. critical infrastructure.
  • The cyber sanctions are part of 'Operation Economic Outcast,' a broader package targeting nearly 60 entities, individuals, and vessels to sever Iran's global financial lifelines.
  • Four of the sanctioned individuals were indicted the previous week in an expanded Department of Justice case against 17 hackers affiliated with the Tehran-based Mabna Institute.
  • The hackers targeted U.S. energy, defense, healthcare, and financial sectors, as well as local, state, and federal government offices in summer 2024.
  • Blockchain analysis by TRM Labs identified $16.8 million in total funds received across 30 wallets linked to the Mabna Institute members, with Blagh holding 92% of the volume.
  • The State Department's Rewards for Justice program announced a reward of up to $10 million for information on foreign-directed cyberattacks against U.S. critical infrastructure.

// Timeline

  1. Keyvan Fayyaz Ghareh Blagh's cryptocurrency addresses receive $15.5 million, accounting for the vast majority of the network's on-chain volume.

  2. Arman Kahzadian illicitly gains control of a cryptocurrency wallet holding over $30,000 in Bitcoin.

  3. The MOIS-aligned hacking group begins breaching and exfiltrating data from U.S. critical infrastructure, including energy and healthcare firms.

  4. The hackers compromise several local, state, and federal government offices across the United States.

  5. Mojtaba Ghal’eh-Kuhi and Saber Shahbazi Balujeh target and exfiltrate data from an Iranian telecommunications company for personal profit.

  6. U.S. and Israel conduct airstrikes against Iran, triggering a wave of retaliatory Iranian cyber operations.

  7. The U.S. Department of Justice indicts 17 Iranian cyber actors affiliated with the Mabna Institute.

  8. The U.S. Treasury Department officially announces 'Operation Economic Outcast' and sanctions five Iranian hackers alongside nearly 60 other entities.

// Perspectives

[U.S. Department of the Treasury]

Aims to exert maximum economic pressure and completely isolate the Iranian regime and the IRGC by cutting off all global financial lifelines, including digital assets.

[TRM Labs]

Highlights that the sanctions serve as a warning of secondary sanctions for any country or platform, particularly in the digital assets space, continuing to do business with Iran.

[SentinelOne (Tom Hegel)]

Warns that the primary risk of Iranian cyber activity is 'access optionality,' where initial compromises can easily pivot from intelligence gathering to active disruption.

// Quotes

“We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone.”

[Scott Bessent] — U.S. Secretary of the Treasury explaining the strategic objective of the 'Operation Economic Outcast' sanctions package.

“The principal strategic risk is access optionality. The same compromised account, service provider, or remote-management foothold can support intelligence collection, downstream targeting, or selective disruption as tasking changes.”

[Tom Hegel] — Security researcher at SentinelOne analyzing the multi-pronged threat posed by Iran-linked cyber clusters.

“Iran is not the only target here. In fact, the focus is secondary sanctions. That is the Treasury's max pressure move. The Treasury is putting every country and platform still doing business with Iran on notice and the digital assets space is a focus of Operation Economic Outcast.”

[Ari Redbord] — Global Head of Policy at TRM Labs commenting on the broader geopolitical implications of the Treasury's sanctions.
// AD SLOT — bottom

// Related Briefs