U.S. Treasury Imposes Sweeping Sanctions on Iranian Cyber Actors in "Operation Economic Outcast"
The U.S. Department of the Treasury has unveiled a new wave of sanctions targeting Iranian cyber actors as part of Operation Economic Outcast, an aggressive campaign to dismantle the financial networks sustaining Iran’s regime and its Islamic Revolutionary Guard Corps (IRGC). Announced by Treasury Secretary Scott Bessent, the initiative aims to sever Iran’s economic lifelines, including those supporting its cyber operations, nuclear programs, missile development, and oil trade.
At the center of the sanctions are nearly 60 Iran-linked entities, individuals, and vessels, with a particular focus on a cyber group tied to Iran’s Ministry of Intelligence and Security (MOIS). This group has been responsible for extensive breaches of U.S. critical infrastructure, including energy companies, defense contractors, healthcare institutions, and financial firms since late 2023. The Treasury alleges that while these actors conduct cyber espionage on behalf of MOIS, some prioritize personal financial gain, even targeting Iranian companies for profit.
Five individuals from the Tehran-based Mabna Institute Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, Mojtaba Ghal'eh-Kuhi, and Arman Kahzadian were indicted by the U.S. Justice Department for their roles in these operations. Their activities include data exfiltration from U.S. government offices in summer 2024 and cryptocurrency theft, with blockchain analytics firm TRM Labs estimating that the group has received nearly $17 million across 30 wallets since 2018. Keyvan Fayyaz Ghareh Blagh alone accounts for 92% of the network’s on-chain volume, while Arman Kahzadian is linked to a 2023 Bitcoin heist worth over $30,000.
The sanctions also target Zedcex and Zedxion, two U.K.-based front companies accused of processing $1 billion in funds for the IRGC. TRM Labs describes the operation as an effort to isolate Iran’s regime both financially and in the digital assets space, warning that secondary sanctions will pressure global entities still engaging with Iran.
In parallel, the U.S. State Department’s Rewards for Justice program is offering up to $10 million for information on foreign-directed cyber threats to critical infrastructure. Iranian cyber activities have escalated since February 2026, following U.S. and Israeli airstrikes, with attacks including the breach of FBI Director Kash Patel’s personal email and disruptions to over 30 U.S. water and wastewater utilities. Suspected Iranian hackers also caused a four-day shutdown of a small U.K. power plant last month, though officials assured no broader energy risks emerged.
Security firm SentinelOne characterizes Iran’s cyber operations as a multi-pronged threat, blending data theft, destructive attacks, social engineering, and opportunistic targeting of exposed operational technology. Meanwhile, a decentralized network of pro-Iran hacktivist groups operating via Telegram and DDoS-for-hire tools has amplified propaganda and psychological pressure campaigns, often timed with kinetic military actions. While technically unsophisticated, these efforts leverage speed and visibility to shape narratives in Western media.
The Treasury’s sanctions mark a significant escalation in the U.S. government’s efforts to counter Iran’s cyber and financial networks, signaling a broader strategy to isolate the regime through economic and digital means.
Source: https://thehackernews.com/2026/08/us-sanctions-iran-linked-hackers-behind.html
Federal Bureau of Investigation (FBI) cybersecurity rating report: https://www.rankiteo.com/company/fbi
Office of Technical Assistance, U.S. Department of Treasury cybersecurity rating report: https://www.rankiteo.com/company/office-of-technical-assistance-u.s.-department-of-treasury
U.S. Department of the Treasury cybersecurity rating report: https://www.rankiteo.com/company/us-treasury
Center for Threat-Informed Defense cybersecurity rating report: https://www.rankiteo.com/company/center-for-threat-informed-defense
"id": "FBIOFFUS-CEN1787682734",
"linkid": "fbi, office-of-technical-assistance-u.s.-department-of-treasury, us-treasury, center-for-threat-informed-defense",
"type": "Breach",
"date": "2/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Public Sector',
'location': 'United States',
'name': 'U.S. government offices',
'type': 'Government'},
{'industry': 'Energy',
'location': 'United States',
'name': 'Energy companies',
'type': 'Private Sector'},
{'industry': 'Defense',
'location': 'United States',
'name': 'Defense contractors',
'type': 'Private Sector'},
{'industry': 'Healthcare',
'location': 'United States',
'name': 'Healthcare institutions',
'type': 'Private Sector'},
{'industry': 'Finance',
'location': 'United States',
'name': 'Financial firms',
'type': 'Private Sector'},
{'industry': 'Utilities',
'location': 'United States',
'name': 'Water and wastewater utilities',
'type': 'Public Sector'},
{'industry': 'Energy',
'location': 'United Kingdom',
'name': 'Small U.K. power plant',
'size': 'Small',
'type': 'Private Sector'}],
'attack_vector': ['Phishing',
'Social Engineering',
'Exploiting Exposed Operational Technology'],
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Government data',
'Corporate data',
'Personally identifiable '
'information']},
'date_detected': '2023',
'description': 'The U.S. Department of the Treasury imposed sanctions on '
'Iranian cyber actors as part of *Operation Economic Outcast*, '
'targeting nearly 60 Iran-linked entities, individuals, and '
'vessels. The sanctions focus on a cyber group tied to Iran’s '
'Ministry of Intelligence and Security (MOIS) responsible for '
'breaches of U.S. critical infrastructure, including energy '
'companies, defense contractors, healthcare institutions, and '
'financial firms. The group has conducted cyber espionage and '
'financially motivated attacks, including data exfiltration '
'and cryptocurrency theft.',
'impact': {'data_compromised': 'Government data, corporate data, personally '
'identifiable information',
'downtime': 'Four-day shutdown of a U.K. power plant',
'financial_loss': '$17 million (cryptocurrency theft)',
'identity_theft_risk': 'High (personally identifiable information '
'exposed)',
'operational_impact': 'Disruptions to critical infrastructure, '
'including water and wastewater utilities',
'systems_affected': ['Energy companies',
'Defense contractors',
'Healthcare institutions',
'Financial firms',
'Water and wastewater utilities',
'Power plants']},
'initial_access_broker': {'high_value_targets': 'Critical infrastructure '
'(energy, defense, '
'healthcare, finance)'},
'investigation_status': 'Ongoing',
'motivation': ['State-sponsored espionage',
'Financial gain',
'Disruption of critical infrastructure',
'Propaganda'],
'post_incident_analysis': {'corrective_actions': 'Sanctions on Iranian '
'entities, blockchain '
'analytics to track '
'cryptocurrency flows, '
'rewards for information on '
'cyber threats',
'root_causes': 'State-sponsored cyber operations, '
'exploitation of exposed '
'operational technology, '
'financially motivated attacks'},
'ransomware': {'data_exfiltration': 'Yes'},
'references': [{'source': 'U.S. Department of the Treasury'},
{'source': 'TRM Labs'},
{'source': 'U.S. Justice Department'},
{'source': 'SentinelOne'}],
'regulatory_compliance': {'legal_actions': 'Indictments by U.S. Justice '
'Department'},
'response': {'law_enforcement_notified': 'U.S. Justice Department, U.S. '
'Treasury',
'third_party_assistance': 'TRM Labs (blockchain analytics)'},
'stakeholder_advisories': 'U.S. Treasury sanctions, Rewards for Justice '
'program ($10 million for information on cyber '
'threats)',
'threat_actor': ['Mabna Institute',
'Ministry of Intelligence and Security (MOIS)',
'IRGC-affiliated groups'],
'title': 'Operation Economic Outcast: U.S. Treasury Sanctions Iranian Cyber '
'Actors',
'type': ['Cyber Espionage',
'Data Exfiltration',
'Ransomware',
'Cryptocurrency Theft']}