Skip to main content
Geopolitics & DefenseNational Security

Treasury Targets Iranian Hackers Tied to US Critical Infrastructure Breaches

US Treasury Department podium with empty lectern and circular seal, set against a large window with daylight streaming in.

"an 'economic D-Day,'" Treasury Secretary Scott Bessent called the move Monday, as the Treasury Department announced sanctions on five Iranian citizens tied to a series of alleged cyber intrusions and thefts that Treasury says targeted U.S. critical infrastructure, government offices, and digital assets.

Treasury sanctions five Iranians and links the action to a broader Iran package

The Treasury Department identified five Iranian nationals in its cyber-designations: Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, Mojtaba Ghal’eh-Kuhi, and Arman Kahzadian. The measures were issued as part of a larger sanctions package — described by Secretary Bessent as an effort to isolate Iran and cut off revenue during the ongoing war — that targets nearly 60 people, companies and vessels tied to Iran’s nuclear and missile programs, oil trade and hacking operations. The sanctions block assets under U.S. control and generally prohibit Americans from doing business with those designated.

Alleged ties to Iran’s Ministry of Intelligence and Security and operational leadership

Treasury accused four of the named individuals — Blagh, Balujeh, Kadkhoda’i, and Ghal’eh-Kuhi — of participating in a hacking operation directed by Iran’s Ministry of Intelligence and Security. Treasury officials said Ghal’eh-Kuhi and Behzad Mesri, the latter previously sanctioned in 2018, have led the group since at least 2023. Officials added that while the group regularly conducted operations for the intelligence ministry, personal profit also factored into their activity.

Scope of intrusions and stolen data: energy, defense, health, technology, finance, and government

According to Treasury, Blagh, Balujeh, and Kadkhoda’i carried out most of the intrusions. Since late 2023 the department says those actors breached and stole data from U.S. energy companies, defense contractors, health care institutions, technology firms and financial institutions. Treasury officials further stated the three are believed to have compromised several local, state, and federal government offices during the summer of 2024. Separately, prosecutors in an expanded Justice Department case against 17 Iranian cyber actors affiliated with the Mabna Institute allege that the Tehran-based firm’s campaign stole more than 31 terabytes of academic research and intellectual property.

Cryptocurrency theft allegation and sanctions on Iran’s digital-assets activity

Treasury singled out Arman Kahzadian as a member of the network who focused on digital asset theft, saying he illicitly took control of a cryptocurrency wallet holding more than $30,000 in Bitcoin in 2023. In the broader package, Treasury also expanded sanctions categories to target people and companies operating in Iran’s digital assets, technology, gold, aviation and shipping sectors.

How CISA, the FBI, and U.S. water utilities, energy companies, and defense contractors are affected

  • CISA and the FBI: Federal agencies have recently assisted water utilities recovering from cyberattacks affecting at least 12 states, and some U.S. officials suspect Iran-linked hackers were responsible for those incidents — though CISA has not publicly attributed the intrusions. The agencies will remain central to incident response and to any attribution or remediation tied to the actors named in these sanctions.
  • U.S. water utilities and industrial-control operators: Federal warnings earlier this year flagged Iran-aligned groups as targeting industrial control systems used across the energy, water and government sectors; utilities that experienced recent incidents — and similarly exposed operators — will watch for related tactics and for any forensic connections to the individuals Treasury named.
  • Energy companies and defense contractors: Treasury’s allegation that Blagh, Balujeh and Kadkhoda’i breached U.S. energy companies and defense contractors since late 2023 puts those sectors on notice to review intrusions dating to that period and to coordinate with federal partners handling forensic and legal follow-up.

The designations arrive alongside a related law-enforcement action: four of the five people sanctioned Monday were also charged last week in the Justice Department’s expanded Mabna Institute case, which accuses a Tehran-based hacking-for-hire firm of widespread theft for Iranian partners. Treasury’s sanctions and the Justice Department’s charges therefore present parallel financial and criminal pressure on a set of individuals the U.S. government says have operated for both state-directed and profit-driven purposes.

The move tightens U.S. leverage by combining asset blocks, business prohibitions, and expanded sanctions categories aimed at Iran’s digital-asset and trade networks. Whether those tools will blunt the operational reach of the accused actors or alter the calculus of Iran-directed hacking for hire remains the immediate policy question left in plain view.

Original story