The US Department of the Treasury has announced new sanctions against Iranian cyber actors as part of a wider campaign targeting Iran’s financial networks and the Islamic Revolutionary Guard Corps (IRGC).
The operation, called “Operation Economic Outcast,” targets nearly 60 Iran-linked individuals, entities and vessels involved in Iran’s nuclear, missile, oil and cyber networks. The sanctions also target parts of Iran’s digital assets sector.
The list includes five individuals linked to the Tehran-based Mabna Institute who, according to US authorities, have carried out cyberattacks against American critical infrastructure since at least 2023. The targets reportedly included energy companies, defense contractors, healthcare organizations, technology firms and financial institutions.
The group is also accused of breaking into local, state and federal government offices in the US during 2024. Authorities say some of the attackers were also involved in stealing cryptocurrency.
Blockchain analysis by TRM Labs found that 30 cryptocurrency wallets linked to the five Mabna Institute members received about $16.8 million in total. One of the accused, Keyvan Fayyaz Ghareh Blagh, was linked to 10 addresses that received about $15.5 million between 2018 and August 2026.
The Treasury also targeted financial networks allegedly supporting the IRGC. TRM Labs previously reported that two UK-based companies, Zedcex and Zedxion, processed around $1 billion in funds linked to the Iranian military.
US officials said the sanctions are intended to cut off financial networks that support Iran’s cyber operations and other activities considered a threat to the United States.
Earlier this month, reports emerged that the suspected Iranian cyberattack caused a 4-day shut down of a unnamed small power plant in the UK. British government said the incident affected a small-scale energy generator and didn’t lead to the wider energy system disruption.