Treasury sanctions alleged Iranian hackers as part of ‘economic D
US Treasury sanctioned four Iranians linked to MOIS-directed hacks that compromised and exfiltrated data from US critical infrastructure, energy, defense, and financial targets.
The Treasury Department designated four Iranian individuals over alleged hacking and cybertheft against US companies in energy, defense, healthcare, IT, and financial sectors since at least late 2023, as part of an 'economic D-Day' sanctions package. It is the second action in weeks against the group, following an indictment of cybercriminals affiliated with Tehran's Mabna Institute; leadership includes Behzad Mesri, first sanctioned in 2018, and the attacks are described as directed by the Ministry of Intelligence and Security (MOIS). Treasury also expanded secondary-sanction categories across digital assets, technology, gold, aviation, and shipping, and noted some group members pursued personal enrichment, including targeting Iranian companies.
- Four Iranians sanctioned for hacking US critical infrastructure and cybertheft, with one designated for using stolen business information
- Second action in weeks after indictment of alleged Mabna Institute-affiliated hackers
- Attacks described as MOIS-directed, led by Behzad Mesri and Mojtaba Ghal'eh-Kuhi
- Secondary sanctions expanded for digital assets, technology, gold, aviation, and shipping sectors
- Sanctions come amid ongoing US-Iran conflict and reported water facility attacks
Full article861 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute.
Listen to this article
0:00
Learn more.
As part of its “economic D-Day” against Iran, the Treasury Department designated four Iranians for sanctions Monday stemming from their alleged role in hacking critical infrastructure targets and waging cybertheft against the United States.
It’s the second time in as many weeks that the Trump administration has taken aim at the same group of alleged hackers, following on an indictment recently unsealed against cybercriminals that federal law enforcement authorities say are affiliated with the Tehran-based Mabna Institute.
A Treasury Department release points the finger at three people — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i and Mojtaba Ghal’eh-Kuhi — as specifically conducting the hacks.
“Since at least late 2023, these three individuals have successfully compromised and exfiltrated data from multiple U.S. companies in various critical infrastructure sectors, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions,” the release states.
A fourth individual included in Monday’s sanctions, Mojtaba Ghal’eh-Kuhi, is listed as one of the leaders of the gang carrying out the Ministry of Intelligence and Security (MOIS)-directed attacks. Another listed leader, Behzad Mesri, first faced sanctions in 2018, as part of another round of sanctions focused on the Mabna Institute.
Finally, the Treasury Department designated one additional person Monday over related activity, Arman Kahzadian, for his alleged role in receiving or using business information stolen via cyber-enabled means.
The department said the Iranian hackers sometimes turn their gaze to domestic targets.
“The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS,” it said. “This has driven some of the group to target Iranian companies.“
Hackers that the U.S. government has identified as Iranian have been behind a spate of attacks on U.S. water facilities, despite denials from President Donald Trump himself about Iranian culpability. The Treasury Department did not immediately respond to a request for comment Monday about whether the sanctions designees were involved in those attacks, nor has the National Security Agency responded to requests for comment on whether Iran was responsible for attacks at the center of an alert about attacks on water facilities.
Treasury Secretary Scott Bessent announced a fuller list of sanctions Monday as the war with Iran nears its five-month anniversary with no end in apparent sight.
“In the Second World War, D-Day marked the historic beginning of a campaign with our allies to target and drive the enemy from its positions, including those in third countries,” he said. “Today, in that same spirit, we are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone.”
There are questions about whether the sanctions themselves are likely to change any behavior, particularly based on how they will be enforced. Iran has vowed “consequences” for the United States.
As part of the sanctions announced Monday, according to the department, “Treasury is expanding the categories of Iran-related conduct that may be subject to secondary sanctions in the future, making it easier to take action against those facilitating the regime. Treasury has issued determinations against five critical sectors –– digital assets, technology, gold, aviation, and shipping–– that the Iranian regime uses to try to prop up its failing economy.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/