U.S. Sanctions Iranian MOIS Hackers Behind Critical Infrastructure Attacks
The U.S. Department of the Treasury has imposed fresh sanctions on Iranian cyber actors as part of Operation Economic Outcast, an "unprecedented, whole-of-government, economic campaign" targeting Tehran's financial networks. Secretary of the Treasury Scott Bessent stated the objective is to "sever every economic lifeline that sustains this tyrannical regime." The action designates nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks, including digital assets. Notably, the sanctions hit a malicious cyber group affiliated with Iran's Ministry of Intelligence and Security (MOIS) that has been responsible for extensive compromises of U.S. critical infrastructure and financially motivated cyber theft.
Five individuals were sanctioned in connection with widespread compromises against U.S. entities: Behzad Mesri (previously designated by OFAC in March 2018 and February 2019 for targeting HBO and acting on behalf of the sanctioned Net Peygard Samavat Company), Mojtaba Ghal'eh-Kuhi, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i. The latter three are accused of conducting the bulk of network compromise activity, successfully breaching and exfiltrating data from multiple U.S. critical infrastructure companies since at least late 2023. Targeted sectors include energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions. According to the Treasury, "this group frequently conducts computer network exploitations on behalf, or for the benefit, of Iran's MOIS," with members also motivated by personal enrichment.
In summer 2024, the threat actors are believed to have broken into several local, state, and federal government offices across the U.S. The Treasury's designation underscores the dual nature of Iranian state-sponsored operations—blending espionage with financially motivated cybercrime. Organizations in the affected sectors are advised to audit their network exposures and credentials, starting with a port scanner to identify open services and a email breach checker to determine whether employee credentials have appeared in known leaks.
Defenders should also reassess credential hygiene across critical infrastructure environments. Given the group's reliance on credential abuse and network exploitation, security teams can validate password strength with a password checker and review DNS configurations for potential leaks that could expose internal infrastructure to threat actors.