The US Treasury has unveiled sweeping new sanctions against more than 50 individuals, entities, and vessels linked to Iran, including a cyber group tied to the Ministry of Intelligence and Security (MOIS). The move is part of what officials are billing as “Operation Economic Outcast,” a push to sever Tehran’s financial networks and weaken the Islamic Revolutionary Guard Corps. The goal: to cut off sources funding Iran’s cyber operations and state-backed aggression.
Who Got Targeted
Among those sanctioned are five individuals indicted by the US Justice Department for orchestrating widespread cyberattacks on American critical infrastructure—namely energy firms, healthcare providers, defense contractors, financial services, and tech companies. These attacks, allegedly carried out since late 2023, targeted both theft and espionage.
Individuals singled out include several members of the Mabna Institute based in Tehran, including Behzad Mesri, Mojtaba Ghal’eh-Kuhi, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, and Arman Kahzadian. They are accused of roles ranging from orchestrating network compromises to carrying out cryptocurrency theft.
Modus Operandi and Financial Trail
The Treasury alleges this group not only acts at the direction of MOIS for political and intelligence-gathering missions, but also pursues personal profit. Some members are reported to prioritize payoffs even when those diverge from Tehran’s strategic goals.
One hack attributed to Arman Kahzadian involved the illicit seizure of a Bitcoin wallet containing over $30,000 in 2023. Blockchain investigations by TRM Labs reveal that 30 wallets tied to these individuals have received roughly $16.8 million in total, including $15.5 million going to addresses linked to Keyvan Blagh since 2018. Remaining balances across the set are a few hundred thousand dollars.
Broader Context: Hacktivism, Fronts, and Laundering
Further charges include allegations that UK-based shell companies—Zedcex and Zedxion—played key roles as fronts for financing the IRGC. These firms reportedly processed nearly $1 billion tied to the IRGC according to TRM Labs and related investigations.
In parallel, there’s been a rise in loosely organized pro-Iran hacktivist and fake-activist (“faketivist”) groups. These entities operate through Telegram channels and websites, selling cyber-attacks, sharing stolen data, and pushing propaganda—especially around kinetic escalation with the US and Israel. Although their tactics aren’t always technically sophisticated, their impact comes from speed and public visibility.
US Retaliation and Incentives
As part of its response, the US is offering up to $10 million via the State Department’s Rewards for Justice program for information leading to individuals conducting cyber attacks on US critical infrastructure under foreign direction.
This campaign arrives against a backdrop of escalating cyber conflict linked to the June 2026 airstrike and retaliation cycle. Iranian-sponsored campaigns have been tied to a 2026 breach of the FBI director’s personal email, plus attacks on over 30 US water and wastewater utilities across at least a dozen states.
Experts are warning the threat picture is evolving into a multipronged challenge. State-aligned actors, financially motivated crime hackers, hacktivists, and faketivists are orchestrating a spectrum of operations—from espionage and data theft to influence operations and infrastructure disruption.
This strategy underscores a US intent to use economic power—on-chain and off-chain—to isolate Iran. Sanctions aim to signal to any country or platform still doing business with Iran that partners in its cyber operations face consequences.
What this means:For the first time, the digital asset side of Iran’s operations is being treated as a frontline element in sanctions strategy. The financially lucrative side of cybercrime is now firmly part of the target set—not just traditional espionage or sabotage. Moving forward, private sector vigilance, enhanced blockchain forensics, and stricter oversight of exchanges and crypto wallets will be critical to enforcing sanctions. What to watch: whether more countries join the pressure campaign, how well US and allied law enforcement can disrupt these networks and collect actionable intelligence, and whether this leads to a measurable drop in successful cyber incursions tied to the MOIS or other Iranian threat actors.