Treasury sanctions Iranian hackers tied to critical-infrastructure breaches
Four of the five people named in the cyber action were also charged last week in the Justice Department’s expanded Mabna Institute case.
The Treasury Department sanctioned five Iranian citizens on Monday over alleged cyberattacks and theft aimed at U.S. critical infrastructure, government offices, and digital assets.
The designations were part of a much broader sanctions package that Treasury Secretary Scott Bessent called an “economic D-Day” aimed at isolating Iran and cutting off its revenue during the ongoing war.
Treasury accused four of the people — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, and Mojtaba Ghal’eh-Kuhi — of participating in a hacking operation directed by Iran’s Ministry of Intelligence and Security.
Blagh, Balujeh, and Kadkhoda’i allegedly carried out most of the group’s intrusions. Since late 2023, they have breached and stolen data from U.S. energy companies, defense contractors, health care institutions, technology firms and financial institutions, according to the department. The three are believed to have also compromised several local, state, and federal government offices during the summer of 2024.
Treasury officials said Ghal’eh-Kuhi and Behzad Mesri, who was previously sanctioned in 2018, have led the group since at least 2023. The hackers regularly conducted operations for the intelligence ministry, though officials said personal profit also played a role in their activity.
The department separately sanctioned Arman Kahzadian, another alleged member of the network who focused on digital asset theft. Officials said Kahzadian illicitly took control of a cryptocurrency wallet holding more than $30,000 in Bitcoin in 2023.
Other members sometimes turned their attention to targets inside Iran. Ghal’eh-Kuhi and Balujeh allegedly stole data from an Iranian telecommunications company in 2025. Treasury said that activity reflected the hackers’ willingness to put their own financial interests ahead of work benefiting Tehran.
Four of the five people sanctioned Monday were also charged last week in the Justice Department’s expanded case against 17 Iranian cyber actors affiliated with the Mabna Institute. Prosecutors have accused the Tehran-based firm of conducting a sprawling hacking-for-hire campaign for Iran’s Islamic Revolutionary Guard Corps and other Iranian partners. The group allegedly breached universities, government agencies, and companies while stealing more than 31 terabytes of academic research and intellectual property.
The sanctions come amid heightened concern about Iran’s ability to reach vulnerable U.S. infrastructure. CISA and the FBI have recently helped water utilities recover from cyberattacks affecting at least 12 states. Some U.S. officials suspect Iran-linked hackers were responsible, although CISA has not publicly attributed those intrusions.
Federal agencies also warned earlier this year that Iran-aligned groups were targeting industrial control systems used across the energy, water and government sectors.
The cyber sanctions were part of a broader package targeting nearly 60 people, companies and vessels tied to Iran’s nuclear and missile programs, oil trade and hacking operations. The moves block assets under U.S. control and generally prohibit Americans from doing business with those designated. Treasury also expanded sanctions categories to target people and companies operating in Iran’s digital assets, technology, gold, aviation and shipping sectors.
Facts Only
* Five Iranian citizens were sanctioned by the Treasury Department over alleged cyberattacks and theft targeting U.S. critical infrastructure, government offices, and digital assets.
* Four individuals—Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, and Mojtaba Ghal’eh-Kuhi—were accused of participating in a hacking operation directed by Iran’s Ministry of Intelligence and Security.
* Blagh, Balujeh, and Kadkhoda’i allegedly carried out most of the group's intrusions.
* Since late 2023, these individuals allegedly breached and stole data from U.S. energy companies, defense contractors, healthcare institutions, technology firms, and financial institutions.
* The three named individuals are believed to have also compromised local, state, and federal government offices during the summer of 2024.
* Mohdtaba Ghal’eh-Kuhi and Behzad Mesri were previously sanctioned in 2018 and allegedly led the group since at least 2023.
* Arman Kahzadian was separately sanctioned for digital asset theft, reportedly taking control of a cryptocurrency wallet holding over $30,000 in Bitcoin in 2023.
* Ghal’eh-Kuhi and Balujeh allegedly stole data from an Iranian telecommunications company in 2025.
* The sanctions were part of a package targeting nearly 60 people, companies, and vessels tied to Iran’s nuclear and missile programs, oil trade, and hacking operations.
Executive Summary
Full Take
The narrative presents a multifaceted picture where state-sponsored cyber activity is directly linked to financial sanctions and geopolitical conflict. The key tension lies between the public acknowledgment of threats to physical infrastructure (energy, utilities) and the attribution of specific criminal acts (data theft, crypto fraud) to state entities or their proxies. This structure leverages fear regarding national security while simultaneously detailing specific economic harms. A pattern emerges where attribution moves from broad geopolitical concern to specific criminal designations, suggesting an attempt to frame illicit activity within a recognized state conflict framework. The inclusion of internal financial motivations, such as personal profit derived from digital asset theft alongside service to the intelligence ministry, complicates the simple dichotomy of state-versus-non-state actors. This layering implies that the operational logic may not be purely ideological but involves complex, localized incentives driving actions against both domestic and foreign entities. The broader sanctions context suggests an attempt to use legal mechanisms to enforce a comprehensive economic isolation strategy, forcing external parties to absorb the costs associated with this perceived threat.
What shifts in focus when discussing attribution? Does emphasizing the shared criminal methodology (hacking-for-hire) over specific political alignment reveal more about the operational reality of these groups? If we observe how digital asset theft coexists with state intelligence work, what does that suggest about the evolving strategy of non-state actors operating within a sanctioned environment? Does the focus on recovering stolen data align with the overarching goal of infrastructure protection, or is it a separate objective layered upon the primary geopolitical aims?
Sentinel — Human
The analysis reads like a factual news report synthesizing official statements and legal actions, exhibiting the complexity and specific cross-referencing typical of human journalistic production.
