US Treasury Sanctions Four Alleged MOIS-Directed Iranian Hackers Behind Critical Infrastructure Breaches
On 25 August 2026, the US Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned four Iranian cyber actors affiliated with the Ministry of Intelligence and Security (MOIS) and the Mabna Institute network for intrusions targeting US critical infrastructure.
Overview
| Attribute | Detail |
|---|---|
| Target Sectors | Energy, defence contracting, healthcare, information technology, financial services |
| Designated Individuals | Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, Mojtaba Ghal'eh-Kuhi (Leader) |
| Sponsoring Body | Iranian Ministry of Intelligence and Security (MOIS) / Mabna Institute network |
| Enforcement Package | US Treasury Secretary Bessent's "economic D-Day" sanctions wave |
| Date | 2026-08-25 |
Intrusion Scope & Operations
Beginning in late 2023, the sanctioned network conducted persistent intrusion and data exfiltration campaigns against critical infrastructure entities in the United States. While directed by Iranian state intelligence, members of the group also engaged in financially motivated cybercrime for personal enrichment, which included targeting commercial organisations within Iran.
The secondary sanctions framework announced in conjunction with these designations encompasses digital assets, technology platforms, gold, aviation, and maritime shipping.
Significance & Attribution Texture
This action represents the second formal enforcement measure against this specific MOIS-linked intrusion cluster within two weeks. The explicit characterisation of operators oscillating between state-directed strategic espionage and domestic extortion highlights the complex dual-motive operational model common across Iranian state cyber units.
Australian Context
While no direct Australian compromises were cited in the initial designation, the targeted verticals โ energy, defence industry, healthcare, IT, and financial institutions โ closely match Australia's critical infrastructure sectors under the SOCI Act. The intelligence provides vital attribution context for Australian threat hunters assessing Iranian intrusion telemetry.