U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime
Source: The Hacker News · August 26, 2026 at 4:31 AM · AI-assisted report
Single-source
KUALA LUMPUR, UNITED KINGDOM, UNITED STATES, IRAN, WASHINGTON, 26 AUGUST 2026 —
U.S. Slaps Sanctions on Iran-Linked Hackers in Bid to Disrupt Cyber Threats to Critical Infrastructure
Market Impact
KUALA LUMPUR, Aug 26 (Reuters/Bloomberg) — The U.S. Department of the Treasury has imposed sweeping new sanctions on nearly 60 Iran-linked entities, individuals, and vessels, targeting cyber actors accused of breaching American critical infrastructure and stealing data in a coordinated campaign tied to Tehran’s intelligence and military apparatus.
The move, part of a broader economic offensive codenamed Operation Economic Outcast, seeks to sever financial and digital lifelines supporting what Washington calls the “leading state sponsor of terror.” It follows a series of high-profile cyber intrusions into U.S. energy, defense, healthcare, and financial sectors, as well as government systems, since early 2023.
“This is an unprecedented, whole-of-government economic campaign,” U.S. Treasury Secretary Scott Bessent said in a statement. “We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone.”
Among those sanctioned are five individuals linked to the Tehran-based Mabna Institute, accused of orchestrating widespread compromises of U.S. critical infrastructure. The group is alleged to have breached energy companies, defense contractors, healthcare institutions, IT firms, and financial institutions since at least late 2023, often on behalf of Iran’s Ministry of Intelligence and Security (MOIS).
Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda’i are identified as leading members, with indictments unsealed last week by the U.S. Justice Department. According to the Treasury, the trio conducted the bulk of network compromise activity, exfiltrating sensitive data from multiple U.S. entities.
The sanctions also target Mojtaba Ghal’eh-Kuhi and Arman Kahzadian, the latter accused of orchestrating cryptocurrency heists, including the theft of over $30,000 in Bitcoin from a single wallet in summer 2023.
Blockchain analytics firm TRM Labs estimates that the 30 wallets linked to the five individuals have collectively received approximately $16.8 million in digital assets. Keyvan Fayyaz Ghareh Blagh alone controls 10 addresses that received 15.5 million units between January 6, 2018, and August 20, 2026 — accounting for 92% of the network’s on-chain volume.
Fifteen wallets tied to Behzad Mesri received $1.2 million between July 12, 2019, and August 22, 2026, with the combined residual balance across all 30 wallets standing at $202,662.
The Treasury’s action extends beyond individuals to include front companies in the United Kingdom — Zedcex and Zedxion — which TRM Labs and DomainTools allege facilitated the processing of about $1 billion in funds linked to Iran’s Islamic Revolutionary Guard Corps (IRGC). The exchanges are described as part of a financial façade ecosystem designed to obscure transactions for the Iranian armed forces.
“Operation Economic Outcast is all about truly isolating the Iranian regime on- and off-chain,” said Ari Redbord, Global Head of Policy at TRM Labs. “The Treasury is putting every country and platform still doing business with Iran on notice, and the digital assets space is a key focus.”
In parallel, the U.S. Department of State’s Rewards for Justice program has offered up to $10 million for information on individuals involved in malicious cyber activities against U.S. critical infrastructure under foreign government direction.
Iranian cyber threat actors have escalated operations since February 2026, when the U.S. and Israel began conducting airstrikes against Iran. Attacks have included the breach of the personal email account of Kash Patel, Director of the FBI, and recent intrusions targeting over 30 water and wastewater utilities across at least 12 U.S. states.
The cyber campaign has also affected U.S. allies. In July 2026, suspected Iranian hackers reportedly caused a four-day shutdown of a small power plant in the United Kingdom, according to The Telegraph. While the U.K. government stated there was no risk to the wider energy system, the incident underscored the cross-border reach of Iran-linked cyber operations.
Security researchers at SentinelOne describe the Iran-linked threat as a multi-pronged campaign involving various clusters with distinct objectives, from data destruction and surveillance of dissidents to opportunistic targeting of exposed operational technology assets.
“The principal strategic risk is access optionality,” said Tom Hegel, a security researcher. “The same compromised account, service provider, or remote-management foothold can support intelligence collection, downstream targeting, or selective disruption as tasking changes.”
The conflict has also spawned a decentralized pro-Iran hacktivist ecosystem, comprising jihadist-aligned collectives, nationalist actors, and state-adjacent influence networks. These groups operate through Telegram channels and websites, sharing target lists, DDoS-for-hire tools, and recycled breach data to amplify psychological, political, and economic pressure.
“Attack claims and propaganda often appear within hours of kinetic events,” said DomainTools Investigations (DTI). “Most activity remains technically unsophisticated. The strategic effect comes less from technical capability than from speed, visibility, and ideological framing that make it into news cycles.”
The sanctions come amid growing concern over Iran’s use of cyber operations as an asymmetric tool of statecraft, particularly in the wake of regional escalations. While the immediate impact is expected to disrupt financial flows and digital asset transactions tied to sanctioned entities, the broader implications for global cybersecurity and financial compliance remain uncertain.
For Malaysia and Southeast Asia, the move highlights the region’s exposure to transnational cyber threats and the need for enhanced vigilance in critical infrastructure protection. Financial institutions and digital asset service providers operating in the region may face increased scrutiny under secondary sanctions, particularly if they maintain indirect links to Iranian entities.
“Countries in the region must ensure due diligence and transaction monitoring to avoid unintended exposure to sanctioned networks,” said a regional compliance officer with a major bank in Kuala Lumpur, speaking on condition of anonymity.
The U.S. Treasury has urged international partners to align with the sanctions regime, warning that failure to comply could result in penalties or reputational damage. While Malaysia has not yet commented publicly on the new measures, regional cybersecurity experts anticipate a ripple effect on cross-border financial monitoring and digital asset regulation.
Looking ahead, analysts expect Iran to adapt its cyber tactics, potentially leveraging proxy groups or decentralized networks to evade detection. The convergence of state-sponsored espionage, financially motivated cybercrime, and hacktivist mobilization presents a complex threat landscape that demands coordinated global responses.
“This is not just about sanctions — it’s about reshaping the cost-benefit calculus for Iran’s cyber operations,” said Redbord. “The goal is to make malicious cyber activity too expensive, too risky, and too isolated to sustain.”