The U. S. Department of the Treasury has unveiled new sanctions targeting Iranian cyber actors, intensifying its economic campaign against Iran. Dubbed Operation Economic Outcast, the initiative aims to dismantle the financial networks supporting Iran and its Islamic Revolutionary Guard Corps (IRGC), which the U. S. labels as a leading state sponsor of terror.
Secretary of the Treasury Scott Bessent emphasized the operation's goal to cut off Iran's financial ties globally, stating, “We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone.” The sanctions specifically target nearly 60 Iran-linked entities, individuals, and vessels involved in nuclear, missile, oil, and cyber networks, including the digital assets sector.
A key focus of the sanctions is a cyber group affiliated with Iran’s Ministry of Intelligence and Security (MOIS), accused of compromising U. S. critical infrastructure and engaging in financially motivated cyber theft. Five individuals, allegedly members of the Tehran-based Mabna Institute, were indicted by the U. S. Justice Department for their roles in these cyber activities.
Among those sanctioned are Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda’i, who are accused of breaching multiple U. S. critical infrastructure sectors, including energy and defense, since late 2023. The Treasury noted that some group members prioritize personal gain over operations benefiting the MOIS, even targeting Iranian companies for profit.
In summer 2024, these actors reportedly infiltrated several U. S. government offices. A year later, Mojtaba Ghal’eh-Kuhi and Saber Shahbazi Balujeh exfiltrated data from an Iranian telecommunications firm. Arman Kahzadian, another member, has been linked to cryptocurrency thefts, including a $30,000 Bitcoin heist in 2023.
Blockchain analytics firm TRM Labs reported that the five Mabna Institute members received approximately $16.8 million through 30 wallets. Keyvan Fayyaz Ghareh Blagh alone holds 10 addresses accounting for 92% of the network's on-chain volume, while Behzad Mesri's 15 addresses received $1.2 million.
Earlier this year, TRM Labs revealed that two U. K.-based companies, Zedcex and Zedxion, facilitated operational financing for the IRGC, processing about $1 billion linked to the Iranian military. DomainTools later described these companies as part of a financial façade ecosystem.
Ari Redbord, Global Head of Policy at TRM Labs, highlighted the broader implications of the sanctions, noting that the U. S. is targeting secondary sanctions to isolate Iran further, especially in the digital assets space. “Operation Economic Outcast is all about truly isolating the Iranian regime on- and off-chain, ” Redbord stated.
In a related move, the U. S. Department of State’s Rewards for Justice program announced a reward of up to $10 million for information on individuals conducting cyber activities against U. S. critical infrastructure under foreign government direction.
Iranian hackers have been linked to several attacks since the U. S. and Israel began airstrikes against Iran in February 2026. These include breaches of the personal email of a high-ranking U. S. official and attacks on water utilities in multiple U. S. states. The U. K. also reported a cyber attack that temporarily shut down a small power plant, though it assured there was no risk to the broader energy system.
Security firm SentinelOne characterized Iran-linked cyber activities as a multi-faceted threat, involving data collection, social engineering, and opportunistic targeting of operational technology assets. Security researcher Tom Hegel noted the strategic risk of these activities, stating that compromised accounts could support intelligence collection or selective disruption.
The ongoing conflict has also seen the rise of a pro-Iran hacktivist ecosystem, comprising jihadist-aligned cyber collectives and nationalist actors. These groups, operating through Telegram channels and websites, aim to exert psychological, political, and economic pressure on adversaries, often synchronizing their activities with kinetic events.







