The U.S. Department of the Treasury has announced new sanctions against Iranian cyber actors as part of what it describes as an unprecedented, whole-of-government economic campaign against Iran and organizations supporting its regime.
The action, known as Operation Economic Outcast, is designed to cut Iran and the Islamic Revolutionary Guard Corps (IRGC) off from financial networks that the U.S. says help sustain the Iranian government. The latest sanctions target nearly 60 Iran-linked individuals, entities and vessels connected to nuclear, missile, oil and cyber activities, as well as the digital assets sector.
Among the targets is an Iranian cyber group affiliated with the Ministry of Intelligence and Security (MOIS). U.S. officials say the group has been involved in extensive compromises of American critical infrastructure organizations as well as financially motivated cyber theft.
The Treasury said MOIS directs multiple cyber threat networks involved in espionage that supports Iran’s political objectives, including activities targeting American civilians.
Five individuals recently indicted by the U.S. Department of Justice have also been sanctioned over alleged widespread attacks against U.S. organizations. The individuals are accused of being members of the Tehran-based Mabna Institute. They include Behzad Mesri, Mojtaba Ghal’eh-Kuhi, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i and Arman Kahzadian.
U.S. authorities accuse Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh and Mohammad Reza Kadkhoda’i of carrying out much of the network compromise activity. Since at least late 2023, they allegedly breached and stole data from companies and organizations across several U.S. critical infrastructure sectors, including energy, defense, healthcare, information technology and financial services.
The Treasury said the group frequently conducts network exploitation activities for or on behalf of Iran’s MOIS. However, officials also said some members are strongly motivated by personal financial gain and have at times prioritized their own profits over activities benefiting the Iranian intelligence service. Some of the actors have even targeted Iranian companies.
In the summer of 2024, the threat actors allegedly compromised several local, state and federal government offices in the United States. About a year later, Mojtaba Ghal’eh-Kuhi and Saber Shahbazi Balujeh allegedly targeted an Iranian telecommunications company and stole data from it.
Arman Kahzadian has primarily been linked to cryptocurrency theft, according to the Treasury. Authorities say he gained unauthorized control of a cryptocurrency wallet containing more than $30,000 worth of Bitcoin in the summer of 2023.
Blockchain analytics company TRM Labs analyzed 30 cryptocurrency wallets associated with five Mabna Institute members and found that they had received approximately $16.8 million in total. Ten addresses linked to Keyvan Fayyaz Ghareh Blagh received about $15.5 million between January 6, 2018, and August 20, 2026, accounting for roughly 92% of the network’s on-chain volume.
TRM Labs also identified 15 wallet addresses associated with Behzad Mesri that received approximately $1.2 million between July 12, 2019, and August 22, 2026. The combined remaining balance across all 30 addresses was approximately $202,662.
The latest action also follows earlier findings involving two U.K.-registered companies, Zedcex and Zedxion. TRM Labs previously reported that the companies had facilitated operational financing for the IRGC, with the exchanges processing roughly $1 billion in funds linked to Iran’s armed forces. DomainTools later reported that the Zedxion-Zedcex network showed characteristics of a financial façade ecosystem.
TRM Labs Global Head of Policy Ari Redbord said the operation is not focused exclusively on Iran itself, but also on secondary sanctions aimed at countries and platforms that continue doing business with the country. He described digital assets as a major focus of the campaign.
At the same time, the U.S. State Department’s Rewards for Justice program announced rewards of up to $10 million for information about individuals involved in malicious cyber activity against U.S. critical infrastructure when those activities are directed or controlled by a foreign government.
Iran-linked threat actors have been associated with multiple hacking campaigns since the United States and Israel began conducting airstrikes against Iran in February 2026. These activities have included the reported compromise of FBI Director Kash Patel’s personal email account and attacks against more than 30 water and wastewater utilities across at least 12 U.S. states.
The activity has also affected U.S. allies. In the United Kingdom, suspected Iranian hackers were blamed for a cyberattack that caused a small power plant to shut down for four days last month. British officials said the incident did not pose a threat to the country’s wider energy system, and the facility involved has not been publicly identified.
Security company SentinelOne has described Iran-linked cyber activity as a multi-pronged threat involving several clusters with different objectives, targets and techniques. The activity can include data theft and destruction, social engineering, cloud compromises, surveillance of dissidents and opportunistic attacks against exposed operational technology systems.
Security researcher Tom Hegel said the main strategic risk is the ability to maintain multiple options after gaining access. A compromised account, service provider or remote-management system could potentially be used for intelligence gathering, further targeting or selective disruption depending on the task.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The ongoing conflict has also contributed to the growth of a pro-Iran hacktivist and so-called faketivist ecosystem. DomainTools Investigations described it as a decentralized network involving jihadist-aligned cyber collectives, nationalist actors and state-adjacent influence networks. These groups use Telegram channels and websites, shared target lists, DDoS-for-hire services, recycled stolen data and campaigns designed to amplify leaked information.
Unlike traditional cyber espionage operations, much of this activity is focused on creating psychological, political and economic pressure rather than maintaining long-term access to targeted networks. DomainTools said attack claims and propaganda frequently emerge within hours of major physical events, while much of the underlying technical activity remains relatively unsophisticated.
U.S. Sanctions Iranian Cyber Actors in New Economic Campaign





