Treasury sanctions Iranian hackers tied to critical-infrastructure breaches

Treasury sanctions Iranian hackers tied to critical-infrastructure breaches

The Treasury Department sanctioned five Iranian citizens on Monday over alleged cyberattacks and theft aimed at U.S. critical infrastructure, government offices, and digital assets.

The designations were part of a much broader sanctions package that Treasury Secretary Scott Bessent called an “economic D-Day” aimed at isolating Iran and cutting off its revenue during the ongoing war.

Treasury accused four of the people — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, and Mojtaba Ghal’eh-Kuhi — of participating in a hacking operation directed by Iran’s Ministry of Intelligence and Security.

Blagh, Balujeh, and Kadkhoda’i allegedly carried out most of the group’s intrusions. Since late 2023, they have breached and stolen data from U.S. energy companies, defense contractors, health care institutions, technology firms and financial institutions, according to the department. The three are believed to have also compromised several local, state, and federal government offices during the summer of 2024.

Treasury officials said Ghal’eh-Kuhi and Behzad Mesri, who was previously sanctioned in 2018, have led the group since at least 2023. The hackers regularly conducted operations for the intelligence ministry, though officials said personal profit also played a role in their activity.

The department separately sanctioned Arman Kahzadian, another alleged member of the network who focused on digital asset theft. Officials said Kahzadian illicitly took control of a cryptocurrency wallet holding more than $30,000 in Bitcoin in 2023.

Other members sometimes turned their attention to targets inside Iran. Ghal’eh-Kuhi and Balujeh allegedly stole data from an Iranian telecommunications company in 2025. Treasury said that activity reflected the hackers’ willingness to put their own financial interests ahead of work benefiting Tehran.

Four of the five people sanctioned Monday were also charged last week in the Justice Department’s expanded case against 17 Iranian cyber actors affiliated with the Mabna Institute. Prosecutors have accused the Tehran-based firm of conducting a sprawling hacking-for-hire campaign for Iran’s Islamic Revolutionary Guard Corps and other Iranian partners. The group allegedly breached universities, government agencies, and companies while stealing more than 31 terabytes of academic research and intellectual property.

The sanctions come amid heightened concern about Iran’s ability to reach vulnerable U.S. infrastructure. CISA and the FBI have recently helped water utilities recover from cyberattacks affecting at least 12 states. Some U.S. officials suspect Iran-linked hackers were responsible, although CISA has not publicly attributed those intrusions.

Federal agencies also warned earlier this year that Iran-aligned groups were targeting industrial control systems used across the energy, water and government sectors.

The cyber sanctions were part of a broader package targeting nearly 60 people, companies and vessels tied to Iran’s nuclear and missile programs, oil trade and hacking operations. The moves block assets under U.S. control and generally prohibit Americans from doing business with those designated. Treasury also expanded sanctions categories to target people and companies operating in Iran’s digital assets, technology, gold, aviation and shipping sectors.



Read the full article here