Skip to main content
Geopolitics & DefenseGovernment & Policy

US Targets Iran-Linked Hackers in Sanctions Crackdown

Government officials stand at a podium with a subtle globe and financial/tech symbols in the background.

"We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone," said Secretary of the Treasury Scott Bessent.

Operation Economic Outcast: a coordinated Treasury campaign

The U.S. Department of the Treasury has unveiled a sanctions package it has codenamed Operation Economic Outcast, describing it as an "unprecedented, whole-of-government, economic campaign" against Iran and its enablers. The action designates nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks, and explicitly includes the digital assets sector.

The Treasury framed the effort as aimed at severing the financial "lifelines" that support what it called the "leading state sponsor of terror." The package targets, among others, a malicious cyber group the Treasury says is affiliated with Iran's Ministry of Intelligence and Security (MOIS) and responsible for "extensive compromises of U.S. critical infrastructure entities and financially motivated cyber theft."

Mabna Institute and the individuals named

Among sanctions listed are individuals the Treasury tied to the Tehran-based Mabna Institute. The notice says five people were indicted by the U.S. Justice Department last week in connection with widespread compromises against U.S. entities. The names provided by the Treasury are Behzad Mesri; Mojtaba Ghal'eh-Kuhi; Keyvan Fayyaz Ghareh Blagh; Saber Shahbazi Balujeh; Mohammad Reza Kadkhoda'i; and Arman Kahzadian.

The Treasury statement singled out Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i as having "conducted the bulk of the network compromise activity," which it says successfully breached and exfiltrated data from multiple U.S. critical infrastructure sector companies since at least late 2023. Those sectors include energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions.

The Treasury also described the MOIS-directed networks as motivated both by state tasking and by personal enrichment: "The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS. This has driven some of the group to target Iranian companies."

The release notes specific earlier actions tied to named individuals: Behzad Mesri was previously designated twice by the Office of Foreign Assets Control (OFAC) — in March 2018 and February 2019 — for his role in targeting and attempted extortion of HBO and for purportedly acting for or on behalf of the Net Peygard Samavat Company. Arman Kahzadian is described as having focused primarily on cryptocurrency heists, including illicit control of a wallet holding more than $30,000 worth of Bitcoin in summer 2023.

On-chain analysis and the digital-financial link

Blockchain and open-source investigators are central to the Treasury's digital targeting. TRM Labs' analysis of 30 wallets linked to the Mabna-related individuals found roughly $16.8 million in total funds received. TRM reported that Keyvan Fayyaz Ghareh Blagh holds 10 addresses that received a collective 15.5 million between January 6, 2018, and August 20, 2026, representing about 92% of the network's on-chain volume. Fifteen wallet addresses associated with Behzad Mesri have received $1.2 million between July 12, 2019, and August 22, 2026. The combined residual balance across all 30 addresses is $202,662.

Separately, TRM Labs disclosed in January that two U.K.-based front companies, Zedcex and Zedxion, facilitated operational financing for the Islamic Revolutionary Guard Corps (IRGC), with the exchanges processing about $1 billion in funds linked to the Iranian armed forces branch. DomainTools later said the Zedxion–Zedcex constellation exhibits "all hallmarks of a financial façade ecosystem."

"Operation Economic Outcast is all about truly isolating the Iranian regime on- and off-chain," said Ari Redbord, Global Head of Policy at TRM Labs, summarizing how secondary sanctions and digital-asset enforcement are being prioritized.

Scope of compromises, wider cyber activity, and pro-Iran hacktivists

The Treasury and allied security firms describe a diverse set of Iranian-linked cyber activities. The Department says the MOIS directs networks involved in cyber espionage "in support of Iran's political goals, which include harming American civilians." The sanctions notice cites breaches from at least late 2023 through 2026.

Attributed activity since February 2026 — following U.S. and Israeli airstrikes, per the Treasury notice — includes the breach of the personal email account belonging to Kash Patel, the director of the Federal Bureau of Investigation (FBI), and attacks that targeted more than 30 water and wastewater utilities across at least 12 U.S. states. The Treasury also highlighted intrusions in summer 2024 into several local, state, and federal government offices across the U.S., and said that a year later two named actors targeted and exfiltrated data from an Iranian telecommunications company.

Security vendors characterized the threat as multi-pronged. SentinelOne described Iran-linked activity as comprising distinct clusters with different missions — from data collection to opportunistic operational-technology targeting — and researcher Tom Hegel warned that "the principal strategic risk is access optionality." DomainTools Investigations described a pro-Iran "hacktivist (and faketivist) ecosystem" — decentralized channels, target lists, DDoS-for-hire tools, and leak amplification — whose strategic effect rests on speed, visibility, and ideological framing rather than high-end tradecraft.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: Expect continued emphasis on tracing on-chain transactions and linking them to actors; the Treasury's move signals that cryptocurrency analytics will be an enforcement focus and that access-based risks (compromised accounts or remote management footholds) can serve multiple operational purposes.
  • Policymakers and regulators: The Treasury's Operation Economic Outcast is explicitly targeting secondary sanctions levers and financial-feeder networks, including front companies and exchanges; the Rewards for Justice program simultaneously offers up to $10 million for information about individuals who carry out malicious cyber activity against U.S. critical infrastructure under foreign direction or control.
  • Affected enterprises (energy, defense, healthcare, IT, financial institutions): The Treasury's allegations tie these sectors to tangible compromise and exfiltration since late 2023, underscoring that breaches traced to state-directed groups may also have financially motivated elements and that remediation and threat hunting should prioritize indicators associated with the named actors and wallets.

The sanctions package, coupled with forensic findings from blockchain analysts and public attributions of disruptive incidents, crystallizes an enforcement approach that blends economic pressure with digital forensic reach. Whether Operation Economic Outcast will choke the financial arteries the Treasury describes — and how quickly the Treasury and private analysts can translate wallet-level attribution into operational disruption of networks — remains the next test for this blended campaign.

Original story