Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-26 ยท updated: 2026-08-26 ยท tags: [incident, apt-group, le-action, sector-energy, sector-defence, sector-healthcare, sector-technology, sector-finance] ยท confidence: high ยท severity: high ยท affected_sectors: [energy, defence, healthcare, technology, finance] ยท au_impact: true

US Treasury Sanctions Four Alleged MOIS-Directed Iranian Hackers Behind Critical Infrastructure Breaches

On 25 August 2026, the US Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned four Iranian cyber actors affiliated with the Ministry of Intelligence and Security (MOIS) and the Mabna Institute network for intrusions targeting US critical infrastructure.

Overview

Attribute Detail
Target Sectors Energy, defence contracting, healthcare, information technology, financial services
Designated Individuals Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, Mojtaba Ghal'eh-Kuhi (Leader)
Sponsoring Body Iranian Ministry of Intelligence and Security (MOIS) / Mabna Institute network
Enforcement Package US Treasury Secretary Bessent's "economic D-Day" sanctions wave
Date 2026-08-25

Intrusion Scope & Operations

Beginning in late 2023, the sanctioned network conducted persistent intrusion and data exfiltration campaigns against critical infrastructure entities in the United States. While directed by Iranian state intelligence, members of the group also engaged in financially motivated cybercrime for personal enrichment, which included targeting commercial organisations within Iran.

The secondary sanctions framework announced in conjunction with these designations encompasses digital assets, technology platforms, gold, aviation, and maritime shipping.

Significance & Attribution Texture

This action represents the second formal enforcement measure against this specific MOIS-linked intrusion cluster within two weeks. The explicit characterisation of operators oscillating between state-directed strategic espionage and domestic extortion highlights the complex dual-motive operational model common across Iranian state cyber units.

Australian Context

While no direct Australian compromises were cited in the initial designation, the targeted verticals โ€” energy, defence industry, healthcare, IT, and financial institutions โ€” closely match Australia's critical infrastructure sectors under the SOCI Act. The intelligence provides vital attribution context for Australian threat hunters assessing Iranian intrusion telemetry.

Sources