The U.S. Department of the Treasury has implemented new sanctions against Iranian cyber actors, part of an initiative termed “Operation Economic Outcast,” aimed at severing financial connections that support the Iranian regime and its associated groups. This campaign specifically targets a malicious cyber group affiliated with Iran’s Ministry of Intelligence and Security (MOIS), responsible for extensive compromises of U.S. critical infrastructure entities and financially motivated cyber theft, according to The Hacker News.
U.S. Sanctions Target Iranian Cyber Actors Targeting U.S. Critical Infrastructure
These sanctions designate nearly 60 Iran-linked entities, individuals, and vessels across various sectors, including cyber networks and digital assets. The MOIS is noted for directing multiple networks of cyber threat actors engaged in cyber espionage to further Iran’s political objectives, which include harming American civilians. Five individuals, recently indicted by the U.S. Justice Department, are specifically targeted in these sanctions. These individuals are alleged members of the Tehran-based Mabna Institute.
Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda’i are accused of conducting the majority of network compromise activities. Since at least late 2023, these Iranian cyber actors targeting U.S. critical infrastructure have successfully breached and exfiltrated data from numerous U.S. entities. These include critical sectors such as energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions.
The Mabna Institute’s Broader Campaign and Financial Motivations
The Treasury states that this group frequently conducts computer network exploitations for the benefit of Iran’s MOIS. However, a significant aspect of their operations also includes personal enrichment. This dual motivation has reportedly led some members to prioritize their own profits, even extending to targeting Iranian companies.
Evidence of these activities includes reported breaches into several local, state, and federal government offices across the U.S. in summer 2024. A year later, Mojtaba Ghal’eh-Kuhi and Saber Shahbazi Balujeh reportedly targeted and exfiltrated data from an Iranian telecommunications company. Arman Kahzadian, another sanctioned individual, has primarily focused on cryptocurrency heists, having illicitly gained control of a wallet holding over $30,000 worth of Bitcoin in summer 2023. TRM Labs’ analysis of 30 wallets linked to the five Mabna Institute members identified approximately $16.8 million in total funds received, highlighting the financial aspect of their operations. These findings underscore the varied motivations and Mabna Institute members’ data exfiltration techniques used across their campaigns.
Beyond direct cyberattacks, the broader “Operation Economic Outcast” aims to isolate the Iranian regime financially. Earlier disclosures by TRM Labs revealed how U.K.-based front companies, Zedcex and Zedxion, facilitated operational financing for the Islamic Revolutionary Guard Corps (IRGC), processing about $1 billion in funds. DomainTools further described this as a financial façade ecosystem.
Broader Context and Call to Action for Defenders
The U.S. Department of State’s Rewards for Justice program has offered a reward of up to $10 million for information leading to the identification of individuals engaging in malicious cyber activities against U.S. critical infrastructure under foreign government direction. This move underscores the severity of the threat posed by state-sponsored cyber operations.
Iranian threat actors have been linked to a series of hacking campaigns following military actions in February 2026, including the breach of the FBI director’s personal email account and recent attacks on over 30 water and wastewater utilities in at least 12 U.S. states. Attacks have also extended to U.S. allies, with suspected Iranian hackers blamed for a four-day shutdown of a small U.K. power plant, though the U.K. government confirmed no wider energy system risk.
SentinelOne characterizes Iran-linked activity as a multi-pronged threat, encompassing diverse clusters with distinct missions, targeting, and tradecraft. This ranges from data collection and destruction to social engineering, cloud compromise, surveillance of dissidents, and opportunistic targeting of exposed operational technology (OT) assets. This complexity necessitates a comprehensive defense strategy.
Mitigation for State-Sponsored Cyber Espionage and Data Theft
Organizations, especially those within critical infrastructure, must prioritize defense against sophisticated state-sponsored threats. Key recommendations include:
- Implement Multi-Factor Authentication (MFA): Enforce MFA across all services, particularly for remote access and critical systems, to prevent unauthorized access even if credentials are compromised.
- Enhance Network Segmentation: Isolate critical systems and sensitive data from less secure networks to limit lateral movement by attackers.
- Regular Patch Management: Ensure all systems, software, and firmware are regularly updated to address known vulnerabilities that threat actors commonly exploit.
- Strengthen Endpoint Security: Deploy advanced endpoint detection and response (EDR) solutions to identify and mitigate malicious activities.
- Employee Training: Conduct ongoing training to educate employees about social engineering tactics, phishing attempts, and the importance of cybersecurity hygiene.
- Incident Response Planning: Develop and regularly test a comprehensive incident response plan to ensure rapid and effective action in the event of a breach.
- Monitor OT/IT Convergence: For critical infrastructure, closely monitor the intersection of operational technology (OT) and information technology (IT) networks for unusual activity.
Related: Iran Cyber Focus Expands: Securing Internet-Facing Vulnerabilities, OFAC Sanctions Nobitex: Disrupting Ransomware & Terror Finance