Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    What It Does to Your SOC

    September 12, 2026

    Is A Free VPN Worth Using? Here’s Why It Could Be Risky

    September 12, 2026

    Researchers link another hacking campaign to OpenAI agents

    September 12, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
    Cybersecurity

    U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

    InfoForTechBy InfoForTechAugust 26, 2026No Comments6 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its enablers.

    “We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone,” said Secretary of the Treasury Scott Bessent.

    The action, codenamed Operation Economic Outcast, aims to cut the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC) from the financial “lifelines” that support the “leading state sponsor of terror.”

    To that end, the sanctions designate nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks, including the digital assets sector. Specifically, the sanctions take aim at a malicious cyber group affiliated with Iran’s Ministry of Intelligence and Security (MOIS) that’s behind extensive compromises of U.S. critical infrastructure entities and financially motivated cyber theft.

    “The MOIS directs several networks of cyber threat actors involved in cyber espionage in support of Iran’s political goals, which include harming American civilians,” the Treasury said.

    Among those sanctioned are five individuals who were indicted by the U.S. Justice Department last week in connection with carrying out widespread compromises against U.S. entities. They are alleged to be members of the Tehran-based Mabna Institute. The names of the individuals are listed below –

    Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda’i have been accused of conducting the bulk of the network compromise activity, successfully breaching and exfiltrating data from multiple U.S. critical infrastructure sector companies since at least late 2023, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions.

    “This group frequently conducts computer network exploitations on behalf, or for the benefit, of Iran’s MOIS.,” the Treasury said. “The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS. This has driven some of the group to target Iranian companies.”

    In summer 2024, the threat actors are believed to have broken into several local, state, and federal government offices across the U.S. A year later, Mojtaba Ghal’eh-Kuhi and Saber Shahbazi Balujeh targeted and exfiltrated data from an Iranian telecommunications company.

    Arman Kahzadian, per the Treasury, has primarily focused on cryptocurrency heists, having illicitly gained control of a wallet that held more than $30,000 worth of Bitcoin in summer 2023.

    TRM Labs’ analysis of the 30 wallets linked to the five Mabna Institute members has found about $16.8 million in total funds received. Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm added, holds 10 addresses that have received a collective 15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network’s on-chain volume.

    Likewise, 15 wallet addresses associated with Behzad Mesri have received $1.2 million between July 12, 2019, and August 22, 2026. The combined residual balance across all 30 addresses is $202,662.

    That’s not all. Earlier this January, TRM Labs disclosed how two U.K.-based front companies Zedcex and Zedxion have facilitated operational financing for IRGC, with the exchanges processing about $1 billion in funds linked to the Iranian armed forces branch. In a follow-up report last month, DomainTools said the Zedxion-Zedcex constellation exhibits all hallmarks of a financial façade ecosystem.

    “Iran is not the only target here. In fact, the focus is secondary sanctions. That is the Treasury’s max pressure move. The Treasury is putting every country and platform still doing business with Iran on notice and the digital assets space is a focus of Operation Economic Outcast,” said Ari Redbord, Global Head of Policy at TRM Labs. “Operation Economic Outcast is all about truly isolating the Iranian regime on- and off-chain.”

    In tandem, the U.S. Department of State’s Rewards for Justice program has announced a reward of up to $10 million for information on individuals who engage in malicious cyber activities against U.S. critical infrastructure under the direction or control of a foreign government.

    Iranian threat actors have been attributed to a series of hacking campaigns since the U.S. and Israel began conducting airstrikes against the country in February 2026, including the breach of the personal email account belonging to Kash Patel, the director of the Federal Bureau of Investigation (FBI), as well as recent attacks targeting over 30 water and wastewater utilities in at least 12 U.S. states.

    The cyber activities have also extended to U.S. allies such as the U.K., with suspected Iranian hackers blamed for causing a 4-day shut down of a small power plant following a cyber attack last month, according to The Telegraph. However, the U.K. government emphasized there was no risk to the wider energy system as a result of the incident, which affected a small-scale energy generator. The name of the facility was not revealed.

    The “Economic D-Day” comes as SentinelOne characterized the Iran-linked activity as a multi-pronged threat comprising various clusters, each with their own distinct mission, targeting, and tradecraft. This can range from data collection and destruction to social engineering, cloud compromise, surveillance of dissidents, and opportunistic targeting of exposed operational technology assets.

    “The principal strategic risk is access optionality,” security researcher Tom Hegel said in an assessment published late last month. “The same compromised account, service provider, or remote-management foothold can support intelligence collection, downstream targeting, or selective disruption as tasking changes.”

    The ongoing conflict has also led to the emergence of a pro-Iran hacktivist (and faketivist) ecosystem, a decentralized mix of “jihadist-aligned cyber collectives, nationalist actors, and state-adjacent influence networks” that operate through Telegram channels and websites, shared target lists, DDoS-for-hire tools, and recycled breach data and leak-amplification campaigns, per DomainTools Investigations (DTI).

    The groups’ activities are not motivated by cyber espionage, state-centric cyber operations, or long-term persistence. Rather, the end goal is to work together as a loose knit mobilization network, exert psychological, political, and economic pressure on adversaries, and participate in synchronized wartime or anti-Western/Israel messaging.

    “Attack claims and propaganda often appear within hours of kinetic events,” DTI said. “Most activity remains technically unsophisticated. The strategic effect comes less from technical capability than from speed, visibility, and ideological framing that make it into news cycles. In practice these actors use cyber activity as scalable asymmetric information warfare.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    What It Does to Your SOC

    September 12, 2026

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026

    Best Practices for Deception Technology Implementation

    September 12, 2026

    Weekly Update 521: Breach Perception v. Reality

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.