"In the Second World War, D-Day marked the historic beginning of a campaign with our allies to target and drive the enemy from its positions, including those in third countries," Treasury Secretary Scott Bessent said. "Today, in that same spirit, we are launching an economic onslaught against Iran’s financial connections around the globe."
Treasury designations: four Iranians named in Monday action
As part of what the department called an "economic D-Day" against Iran, the Treasury Department designated four Iranians for sanctions on Monday for their alleged roles in hacking critical infrastructure and cybertheft against the United States. The department's release names Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, and Mojtaba Ghal’eh‑Kuhi as specifically conducting the hacks. The release also separately designated Arman Kahzadian for an alleged role in receiving or using business information stolen via cyber-enabled means.
Alleged campaign and claimed targets since late 2023
The Treasury said the operators "since at least late 2023" had "successfully compromised and exfiltrated data from multiple U.S. companies in various critical infrastructure sectors," explicitly listing energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions. The department also noted the group sometimes targets Iranian companies and said "members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleLinks to the Mabna Institute and MOIS-directed attacks
Federal law enforcement has tied the alleged hackers to the Tehran-based Mabna Institute, and the Treasury action follows a recently unsealed indictment that also named the group. The department's release described Mojtaba Ghal’eh‑Kuhi as one of the leaders of the gang carrying out Ministry of Intelligence and Security (MOIS)-directed attacks. Another leader associated with the group, Behzad Mesri, first faced U.S. sanctions in 2018, the Treasury noted.
Sanctions scope: secondary measures and five critical sectors
The department said it is expanding the categories of Iran-related conduct that may be subject to secondary sanctions in the future, with determinations against five critical sectors: digital assets, technology, gold, aviation, and shipping. Treasury framed the effort as seeking to "sever every economic lifeline that sustains this tyrannical regime" and said the move will make it easier to take action against those facilitating the regime. The release comes as the war with Iran, the department said, nears its five-month anniversary.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: The Treasury's list of targeted sectors and its description of data exfiltration across energy, defense, healthcare, IT, and finance underscores the cross-sector exposure the department attributes to the group. Teams in those sectors will likely treat the named individuals and their alleged tradecraft as signals to review intrusion detection, data-loss prevention, and third‑party risk practices.
- Policymakers and regulators: Expansion of categories that could trigger secondary sanctions — digital assets, technology, gold, aviation, and shipping — tightens the policy toolkit available to the Treasury. The department also said it has issued determinations against those five sectors, a procedural step that could lower the bar for future enforcement actions against facilitators of the regime.
- Affected enterprises and procurement leaders: Companies in the sectors the Treasury identified should expect heightened scrutiny of their supply chains and financial relationships tied to Iran-related networks. The designation of individuals for receiving or using stolen business information highlights the commercial risk of illicit data flows and may prompt additional due diligence in acquisitions, partnerships, and vendor onboarding.
The Treasury did not immediately respond to requests for comment about whether the newly sanctioned individuals were involved in recent attacks on U.S. water facilities, and the National Security Agency also did not respond to requests for comment about whether Iran was responsible for attacks at the center of an alert about water facilities. The article notes that hackers identified by the U.S. government as Iranian have been blamed for a spate of such attacks, even as President Donald Trump has denied Iranian culpability.
Questions remain about enforcement and effect: the department expanded potential secondary‑sanctions triggers and announced a broader list of sanctions, but the Treasury itself acknowledged debate over whether the measures will change behavior, "particularly based on how they will be enforced." Iran has vowed "consequences" in response to the action, leaving enforcement, attribution, and the diplomatic fallout as the immediate variables to watch.
Read the original CyberScoop report: https://cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/




