The U.S. Department of the Treasury has announced new sanctions against Iranian cyber actors accused of carrying out attacks against American critical infrastructure and stealing sensitive information. The action is part of a wider U.S. campaign called Operation Economic Outcast, which is designed to put financial pressure on Iran and disrupt networks supporting the Iranian government. Treasury said the measures target people and organizations connected to Iran’s cyber, financial, nuclear, missile and oil networks.

The cyber-related sanctions focus on a group linked to Iran’s Ministry of Intelligence and Security, or MOIS. According to the Treasury, the group has carried out computer network compromises on behalf of or for the benefit of Iran’s intelligence service. Since at least late 2023, members of the group have allegedly broken into and taken data from U.S. companies working in important sectors including energy, defense, healthcare, information technology and financial services.

Four individuals named in the sanctions are Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i and Mojtaba Ghal’eh-Kuhi. Treasury said Blagh, Balujeh and Kadkhoda’i carried out most of the group’s network intrusion activities. The department also said that during the summer of 2024, members of the group compromised several local, state and federal government offices in the United States, showing that their activities extended beyond private companies.

The Treasury also linked the group to financially motivated cybercrime. It said some members were driven by personal profit and targeted organizations for their own financial benefit, including Iranian companies. Another individual, Arman Kahzadian, was identified for his focus on digital asset theft. Treasury said he gained control of a cryptocurrency wallet containing more than $30,000 worth of Bitcoin in the summer of 2023.

The latest sanctions also come shortly after the U.S. Justice Department announced charges against 17 Iranian nationals connected to the Mabna Institute. Prosecutors accuse the group of conducting a large cyber theft campaign targeting universities, companies and other victims to steal research, proprietary information and intellectual property. Four of the five people included in the new Treasury cyber action were also charged in the expanded Mabna Institute case announced on August 18.

The U.S. action comes as Iranian-linked cyber activity against critical infrastructure has attracted increasing attention. Recent investigations have examined cyber incidents involving water systems in several U.S. states, although officials have cautioned that attribution can change as investigations continue. Iranian-linked hackers have also been blamed for a cyberattack that temporarily shut down a small British energy facility for four days, although British officials said the incident did not threaten the wider electricity system.

Alongside the Treasury sanctions, the U.S. State Department’s Rewards for Justice program announced a reward of up to $10 million for information about people involved in malicious cyber activities against U.S. critical infrastructure when those activities are directed or controlled by a foreign government. The move highlights how seriously Washington is treating cyberattacks that could affect essential services and national security. It also adds another tool for identifying individuals operating behind foreign-backed cyber campaigns.

The sanctions are part of a broader U.S. effort to isolate Iran financially and weaken networks that support its government and security organizations. Treasury Secretary Scott Bessent described the campaign as an economic effort aimed at cutting Iran off from important financial connections around the world. For cybersecurity, the latest measures show that the U.S. is increasingly combining sanctions, criminal charges and financial disruption to respond to cyber actors accused of targeting critical infrastructure and stealing valuable information.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news