supply-chaintrade-pressNewsThe Broadside2 min read

Treasury sanctions MOIS hackers as UK plant goes dark four days

The US sanctions target email intrusions and credential theft stretching back to 2023; the UK just experienced an OT shutdown that took a power plant offline, same threat umbrella, entirely different operational consequence.


TL;DR

The Treasury Department sanctioned six Iranian nationals tied to an MOIS hacking unit on Monday, days after UK officials disclosed that Iranian cyber actors shut down a small British power plant for four days. Four of the six were indicted last week for breaching DOL, FERC, and UN email accounts. Treasury said the group has targeted energy, defense, healthcare, IT, and financial sectors since 2023. The UK incident didn't cause outages and the grid remained unaffected, but it's the kind of OT disruption CISA and the FBI have warned about across at least three advisories since late 2023.

Treasury sanctions MOIS hackers as UK plant goes dark four days
Editorial illustration · drawn by The Broadside

The sanctions package names the individuals (Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, Mojtaba Ghal'eh-Kuhi, and two previously sanctioned operatives) and describes a dual-purpose operation housed within Iran's Ministry of Intelligence and Security. The MOIS unit blends state-directed espionage with freelance greed: Treasury notes several members targeted Iranian companies and stole cryptocurrency on the side, sometimes prioritizing personal enrichment over MOIS objectives.

The UK incident is a different class of problem

The British power plant shutdown, reported by the Telegraph, is the sharper operational signal. Unlike the US sanctions, which address compromises of email and data assets, the UK attack involved an unsecured programmable logic controller, the same OT attack surface CISA flagged in its July 2026 advisory (AA26-097A) and earlier in joint FBI-NSA guidance from April. That advisory warned of PLC disruptions across US critical infrastructure sectors, naming Rockwell Automation, Schneider Electric, and Siemens devices as targets.

Markus Mueller of Nozomi Networks characterized the UK incident as a "major escalation" from water utility targeting. A power plant's control systems, he noted, present a genuine safety risk if compromised, "the type of facility that a capable adversary that understands the systems could cause real damage to."

The gap between sanctions and operational reality

The timeline is instructive. The Treasury designations cite activity from 2023 onward. But the UK shutdown happened within days of the sanctions announcement, and the April 2026 FBI advisory explicitly tied Iranian OT targeting to the ongoing military conflict between the US and Iran. The sanctions are punishing past intrusions while the adversary's operational playbook has already moved to kinetic-adjacent OT disruption.

For critical infrastructure operators, the takeaway isn't the sanctions, it's that an unsecured, internet-facing PLC can put a power plant offline for four days. CISA's guidance is clear: remove PLCs from direct internet exposure and deploy secure gateways. The UK incident suggests not everyone has done it yet.


Published ·Deep Fathom