The U.S. Treasury Department has imposed sanctions on nearly 60 Iran-linked entities, individuals, and vessels, including five hackers who collectively received $16.8 million through cryptocurrency wallets tied to extensive breaches of American critical infrastructure. The sanctions, announced this week as part of "Operation Economic Outcast," target a cyber group affiliated with Iran's Ministry of Intelligence and Security (MOIS) accused of compromising U.S. energy companies, defense contractors, healthcare institutions, financial firms, and government offices. Treasury Secretary Scott Bessent described the initiative as an "economic onslaught" designed to cut every financial connection sustaining what he called Iran's "tyrannical regime."
The five sanctioned individuals—Behzad Mesri, Mojtaba Ghal'eh-Kuhi, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i—were indicted by the Justice Department last week for their alleged roles as members of the Tehran-based Mabna Institute. Analysis by TRM Labs traced 30 cryptocurrency wallets linked to the group, finding total funds received of approximately $16.8 million. Keyvan Fayyaz Ghareh Blagh alone controls 10 wallet addresses that received a collective $15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network's on-chain volume. Behzad Mesri's 15 wallet addresses received $1.2 million between July 12, 2019, and August 22, 2026, while the combined residual balance across all 30 addresses stands at $202,662. Three of the hackers—Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i—conducted the majority of network intrusions, successfully penetrating and stealing data from multiple U.S. critical infrastructure companies since at least late 2023. During summer 2024, the threat actors breached several local, state, and federal government offices across the country, while a year later, two members targeted and exfiltrated data from an Iranian telecommunications company. Arman Kahzadian concentrated primarily on cryptocurrency theft, illegally seizing control of a wallet containing more than $30,000 worth of Bitcoin in summer 2023.
According to the Treasury Department, the MOIS directs several networks of cyber threat actors involved in cyber espionage to support Iran's political goals, "which include harming American civilians." The report states that "this group frequently conducts computer network exploitations on behalf, or for the benefit, of Iran's MOIS," but notes the members are also heavily motivated by personal enrichment and greed, leading some to prioritize their own profits over operations that benefit the MOIS—which has driven some of the group to target Iranian companies. The State Department's Rewards for Justice program has announced a reward of up to $10 million for information on individuals who engage in malicious cyber activities against U.S. critical infrastructure under foreign government direction or control.
The sanctions reflect broader pressure on Iran's financial networks following a series of escalating cyber attacks since the U.S. and Israel began conducting airstrikes against the country in February 2026, including the breach of FBI Director Kash Patel's personal email account and recent attacks targeting over 30 water and wastewater utilities in at least 12 U.S. states. Iranian hackers are also blamed for a four-day shutdown of a small power plant in the U.K. last month, though the British government emphasized there was no risk to the wider energy system. TRM Labs' Ari Redbord characterized the operation as focused on "secondary sanctions," explaining that "the Treasury is putting every country and platform still doing business with Iran on notice and the digital assets space is a focus of Operation Economic Outcast." SentinelOne described the Iran-linked activity as a multi-pronged threat comprising various clusters, each with their own distinct mission, targeting, and tradecraft, ranging from data collection and destruction to social engineering, cloud compromise, surveillance of dissidents, and opportunistic targeting of exposed operational technology assets. The conflict has also spawned a pro-Iran hacktivist ecosystem—a decentralized mix of jihadist-aligned cyber collectives, nationalist actors, and state-adjacent influence networks that operate through Telegram channels, shared target lists, DDoS-for-hire tools, and recycled breach data to exert psychological, political, and economic pressure on adversaries, with most activity remaining technically unsophisticated but strategically effective through speed and visibility. The combination of state-directed espionage and profit-driven cybercrime creates what security researchers call "access optionality," where the same compromised account or foothold can support intelligence collection, downstream targeting, or selective disruption as priorities shift. Treasury's designation of cryptocurrency wallets alongside traditional sanctions signals that digital asset flows have become a primary enforcement frontier, forcing exchanges and platforms to choose between Iranian business relationships and access to Western financial systems.

