US Sanctions Iranian Cyber Actors Over Critical Infrastructure Attacks
The U.S. Treasury Department announced sanctions on Monday against several Iranian nationals tied to state-sponsored cyber operations targeting American critical infrastructure, just days after the United Kingdom disclosed a cyberattack on a small British power plant. Treasury Secretary Scott Bessent unveiled the measures as part of a broader campaign to pressure Tehran, with at least six men accused of operating within Iran's Ministry of Intelligence and Security (MOIS) placed on the sanctions list. Four of the individuals were indicted last week for breaching employee email accounts linked to the Department of Labor, the Federal Energy Regulatory Commission, and multiple United Nations organizations.
The sanctioned group includes Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, and Mojtaba Ghal'eh-Kuhi, alongside two others previously designated. According to Treasury officials, Blagh, Balujeh, and Kadkhoda'i conducted the bulk of the group's initial intrusions and data thefts, targeting energy companies, defense contractors, healthcare institutions, IT firms, and financial institutions. "The MOIS directs several networks of cyber threat actors involved in cyber espionage in support of Iran's political goals, which include harming American civilians," the Treasury Department stated. Officials also noted that some members prioritized personal enrichment, stealing cryptocurrency from local holders and even targeting Iranian companies for profit. The targeting of government email accounts underscores the importance of monitoring for compromised credentials—security teams can verify exposure using an email breach checker—and enforcing strong credential hygiene through a reliable password checker.
In a related disclosure, Iranian threat actors reportedly shut down a small British power plant for four days, though no customers lost power and the wider grid remained unaffected. The incident has reignited concerns about the capability of Iranian-linked APT groups to penetrate operational technology environments responsible for water, power, and other essential utilities. Since the U.S. began conducting airstrikes against Iran in February, Tehran-linked hackers have been blamed for attacks on water systems in at least 12 states, a prominent medical device manufacturer, and the personal email account of FBI Director Christopher Wray. U.K. Energy Minister Michael Shanks confirmed the government was investigating the power plant intrusion, signaling heightened cross-Atlantic coordination on critical infrastructure defense.