Treasury sanctions five Iranians for critical infrastructure hacks
Four of the five were indicted last week in the Mabna Institute case, but Treasury's sanctions expose a messier picture: state-directed hackers who also stole crypto and breached an Iranian telecom for personal profit.
TL;DR
The Treasury Department sanctioned five Iranian nationals Monday for cyberattacks on U.S. critical infrastructure, defense contractors, and government offices since late 2023. Four were indicted last week in DOJ's expanded Mabna Institute case. Treasury says the group mixed state-directed intrusions for Iran's Ministry of Intelligence with personal-profit schemes, including a $30,000 crypto theft and a 2025 breach of an Iranian telecom. Targets included energy companies, healthcare institutions, tech firms, and financial institutions, plus state, local, and federal government offices in summer 2024.
The sanctions follow a pattern that's now three years deep. In February 2024, Treasury sanctioned IRGC Cyber-Electronic Command officials over the Cyber Av3ngers PLC hacks on U.S. water systems. CISA has since warned repeatedly about Iranian-affiliated actors exploiting internet-connected PLCs across energy, water, and government sectors, most recently updating its advisory in July 2026.
Four of the five individuals sanctioned Monday were named in DOJ's expanded Mabna Institute indictment on August 18. That case now charges 17 Iranian cyber actors in a hacking-for-hire scheme that allegedly yielded more than 31 terabytes of stolen academic research and intellectual property for the IRGC and other Iranian entities. The parallel sanctions-and-indictment approach has become standard: sanctions freeze assets and block transactions with designated individuals, while criminal charges preserve the option of prosecution if any defendant enters a jurisdiction where extradition is possible.
What distinguishes this group is Treasury's unusual candor about their motives. While the hackers operated under Iran's Ministry of Intelligence and Security, Treasury explicitly noted that "personal profit also played a significant role." Arman Kahzadian allegedly seized a Bitcoin wallet holding more than $30,000. Other members breached an Iranian telecommunications company in 2025. That target served no state interest. For defenders, the mixed-motive profile cuts both ways: financially motivated intruders are often less operationally disciplined than strictly state-directed ones, but they're also harder to deter through geopolitical signaling alone.
Published ·Deep Fathom