The U.S. Department of the Treasury has introduced new Iran-linked cyber sanctions as part of a broader economic effort against Iran and actors the U.S. says enable the regime. The announcement frames the action as a whole-of-government campaign intended to disrupt the financial and technical channels that support Iran’s strategic objectives.
According to Treasury statements, the plan—named Operation Economic Outcast—seeks to sever the “lifelines” that keep Iranian operations moving, including activities tied to nuclear, missile, oil, and cyber domains. A key message from the Treasury is that the pressure will extend globally, with the digital assets ecosystem specifically singled out for heightened scrutiny.
What the U.S. says Operation Economic Outcast will target
Operation Economic Outcast is designed to isolate Iran-linked networks from financial pathways that the U.S. associates with the Islamic Revolutionary Guard Corps (IRGC) and its support structures. The Treasury characterizes the IRGC as a central component in enabling violent activity and terrorism-related support.
To operationalize that goal, the Treasury designated nearly 60 entities, individuals, and vessels linked to Iran across multiple sectors. Among the targets are actors connected to cyber operations, including a malicious group the U.S. associates with Iran’s Ministry of Intelligence and Security (MOIS).
MOIS-linked hackers and critical infrastructure breaches
The Treasury’s core allegation is that the MOIS directs or supports networks of cyber threat actors involved in espionage and other operations aligned with Iran’s political objectives. The U.S. further states that these activities include actions harmful to American civilians.
In that context, the sanctions focus on a cyber group described as being affiliated with MOIS and linked to extensive compromises of U.S. critical infrastructure organizations, alongside financially motivated cyber theft.
Indicted individuals tied to the Mabna Institute
Five individuals sanctioned by the U.S. were previously indicted by the U.S. Department of Justice. The case ties them to widespread compromises against U.S. organizations, with the individuals alleged to be members of the Tehran-based Mabna Institute.
- Behzad Mesri
- Mojtaba Ghal’eh-Kuhi
- Keyvan Fayyaz Ghareh Blagh
- Saber Shahbazi Balujeh
- Mohammad Reza Kadkhoda’i
- Arman Kahzadian
While all of the individuals are connected to the network described by the Treasury, the U.S. singled out several as allegedly driving much of the compromise activity. The Treasury points to breaches and data exfiltration affecting multiple U.S. critical infrastructure sector companies, including organizations in energy, defense contracting, healthcare, information technology, and financial services.
The Treasury’s timeline indicates that such activity has been ongoing since at least late 2023, and that in summer 2024 the actors were believed to have broken into local, state, and federal government offices across the U.S.
Attack patterns reported by the U.S. and partners
Beyond the designations themselves, the U.S. provided examples of how the alleged group’s operations played out. The sanctions announcement cites activity involving both U.S.-based victims and Iranian entities used as part of the larger operational picture.
For instance, the Treasury states that Mojtaba Ghal’eh-Kuhi and Saber Shahbazi Balujeh targeted an Iranian telecommunications company in the period about a year after the U.S. compromises began. The alleged outcome in that case included data exfiltration.
In addition, the U.S. highlights that Arman Kahzadian focused primarily on cryptocurrency theft. The Treasury alleges that Kahzadian gained control of a wallet containing more than $30,000 worth of Bitcoin in summer 2023.
Blockchain-linked proceeds and wallet tracking
To support its claims about financially motivated behavior, the announcement references blockchain analysis. TRM Labs analysis is mentioned as having examined 30 wallets associated with the five Mabna Institute members and estimated that they collectively received about $16.8 million in funds.
In that reporting, TRM Labs also notes concentration of on-chain activity. It states that Keyvan Fayyaz Ghareh Blagh holds 10 addresses that received a combined 15.5 million across the analysis window running from January 6, 2018, to August 20, 2026. According to the same source, those addresses account for about 92% of the network’s on-chain volume.
For Behzad Mesri, the summary provided in the announcement indicates that 15 wallet addresses received around $1.2 million between July 12, 2019, and August 22, 2026. Across all 30 wallets, the residual balances are described as totaling $202,662.
Digital assets and secondary sanctions pressure
A major theme in the U.S. framing is that the campaign targets more than just Iran’s direct cyber operations. The Treasury and partners emphasize secondary sanctions—pressure applied to countries, entities, or platforms that continue doing business with Iran.
TRM Labs policy leadership is quoted describing the focus as a maximum-pressure move intended to reach both on-chain and off-chain activity. The argument is that isolation efforts must cover the full lifecycle of cyber and financial enablement, including where stolen value is moved, exchanged, or disguised.
In related analysis referenced by the announcement, TRM Labs previously disclosed how two U.K.-based front companies—Zedcex and Zedxion—helped facilitate operational financing for the IRGC. The announcement also points to follow-up work by DomainTools, describing a financial façade ecosystem associated with that cluster.
Rewards for information on malicious cyber activity
Alongside the sanctions, the U.S. Department of State’s Rewards for Justice program announced a potential reward of up to $10 million. The reward is intended to support information leading to the identification of individuals involved in malicious cyber activity against U.S. critical infrastructure, when such activity is directed or controlled by a foreign government.
This combined approach—financial restrictions plus incentives for reporting—signals that the U.S. aims to increase both disruption and accountability for cyber-linked threats.
Broader Iran-linked cyber activity and multi-front pressure
The sanctions announcement also places the cyber efforts in a wider context of conflict. It references a series of hacking campaigns attributed to Iranian threat actors following U.S. and Israel airstrikes in February 2026.
Examples cited include:
- A breach of the personal email account belonging to Kash Patel, director of the FBI.
- Attacks targeting water and wastewater utilities across at least 12 U.S. states, with claims that over 30 utilities were affected.
- Cyber activity described as extending to U.S. allies, including suspected Iranian-linked involvement in a short-term shutdown of a small power plant in the U.K.
The announcement notes that the U.K. government emphasized there was no risk to the wider energy system because the affected generator was small-scale, and the facility name was not disclosed.
How defenders should interpret the threat
Security analysis referenced in the announcement characterizes the Iran-linked activity as multi-pronged. It describes clusters of activity with different missions and tradecraft, ranging from data collection and destruction to social engineering and cloud compromise.
One security observation included in the announcement highlights the strategic risk of “access optionality.” The idea is that a single compromised account, service provider, or remote management foothold can support different goals depending on how tasking changes—such as intelligence collection, downstream targeting, or disruption.
In addition, the announcement mentions a decentralized pro-Iran hacktivist ecosystem operating through Telegram channels and websites. It describes a mix of jihadist-aligned collectives, nationalist actors, and state-adjacent influence networks that may share tools, target lists, and recycled breach data to increase visibility.
From a practical standpoint, this means that even when individual actions appear technically unsophisticated, the combined effect can be amplified through speed, reach, and messaging during periods of kinetic events.
Conclusion: Iran-linked cyber sanctions aim to isolate capabilities and value
The new Iran-linked cyber sanctions under Operation Economic Outcast are meant to address both the operational side of cyber intrusions and the financial pathways that enable them. By designating MOIS-affiliated actors tied to critical infrastructure compromises and cryptocurrency theft, the U.S. is targeting the mechanisms behind both disruption and monetization.
With secondary sanctions and incentives for information through Rewards for Justice, the campaign reflects a broader goal: to isolate Iran’s regime and its enablers—on- and off-chain—while increasing pressure on any country or platform still connected to Iranian activity.
Source: https://thehackernews.com/2026/08/us-sanctions-iran-linked-hackers-behind.html
