The U.S. Treasury has kicked off a sweeping round of sanctions aimed at choking off financial networks tied to Iran — and it named cyber actors as prime targets. The campaign is big, blunt, and designed to make it harder for Tehran and its affiliates to buy gear, pay operatives, or hide proceeds in the digital world.
What the sanctions do
Dubbed Operation Economic Outcast, the move flags nearly 60 Iran-related entities, people, and vessels spanning nuclear, missile, oil and, yes, cyber and digital-asset channels. The stated goal: sever the economic lifelines that bankroll hostile activity and force third parties to think twice before doing business with the regime.
Among the listed targets is a hacking network allegedly tied to Iran’s Ministry of Intelligence and Security. Officials say this group has been involved in a string of intrusions into U.S. systems and has also carried out financially motivated theft online. The sanctions aim not just at the hackers themselves but at the on-ramps they use — from banks to crypto wallets.
Who the hackers are (and what they allegedly did)
The Treasury named several individuals believed to be linked to a Tehran-based operation that has been blamed for widespread compromises of organizations across multiple sectors. The people called out include:
- Behzad Mesri
- Mojtaba Ghal’eh-Kuhi
- Keyvan Fayyaz Ghareh Blagh
- Saber Shahbazi Balujeh
- Mohammad Reza Kadkhoda’i
- Arman Kahzadian
Authorities say several of these operators were responsible for breaching and stealing data from companies in energy, defense, healthcare, information technology, and finance since late 2023. The group is accused of mixing political-motivated espionage with opportunistic cybercrime: some members allegedly prioritized personal profit, running theft and cryptocurrency heists alongside state-directed tasks.
Examples mentioned by investigators include break-ins to local, state and federal offices, targeted exfiltration from telecom providers, and crypto wallet takeovers. One individual is said to have hijacked a wallet that contained more than thirty thousand dollars in Bitcoin.
Blockchain analysis firms reviewing wallets linked to these suspects found roughly $16.8 million flowed through about 30 addresses tied to the group. Most of that on-chain volume was concentrated in a handful of addresses attributed to a single actor; other addresses show smaller sums and modest leftover balances.
Separately, researchers have pointed to front companies and exchange activity that appear to have helped move funds for Iran’s armed branches, sometimes involving large stablecoin flows. The Treasury is using these findings to justify tighter secondary sanctions and to warn intermediaries that continued business with sanctioned actors could draw consequences.
The State Department’s Rewards for Justice program has sweetened the pot with up to a $10 million reward for information about individuals who carry out malicious cyber activity against U.S. critical infrastructure under foreign direction.
Finally, the conflict has also unleashed a motley crew of pro-Iran hacktivists and sympathizers online. These loose networks — a chaotic stew of zealots, opportunists, and state-adjacent actors — trade target lists, DDoS tools, and leaked data via messaging channels. They’re often not technically elite, but they are fast, noisy, and good at turning cyber incidents into headlines and political pressure.
Bottom line: the sanctions are meant to squeeze both the technical operators and their financial helpers. Security folks warn that a single compromised account or service can serve many malicious purposes — intelligence, disruption, or theft — depending on who’s pulling the strings. In short: the problem is messy, mobile, and expensive to fix.