The U.S. Treasury sanctioned two Iranian firms—HormuzSafe Marine Services Authority and Persian Gulf Marine Insurance Company—for allegedly supporting an IRGC-backed extortion scheme targeting commercial shipping in the Strait of Hormuz. Treasury said the companies sold maritime insurance that benefited or was approved by the Islamic Revolutionary Guard Corps, including coverage against vessel seizure risks created by Iran itself, and accepted digital assets such as Bitcoin to help evade sanctions. The action was issued under Executive Order 13902 as part of broader pressure on Iran’s petroleum, petrochemical, and financial sectors.
OFAC also sanctioned eight shipping companies in China, Hong Kong, and the Marshall Islands and blocked eight vessels tied to Iran’s shadow fleet for transporting Iranian crude and petroleum products, largely to China and in some cases the UAE. Treasury said more than 100 vessels linked to Iran’s shadow fleet have been sanctioned since the start of the year, while maritime risk reporting separately described heightened regional tensions, including increased IRGC small-boat activity in Hormuz and signs of disrupted export operations around key Iranian and regional energy shipping routes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On July 29, 2026, a drone strike hit the LNG floating storage unit ENERGOS WINTER at Damietta, Egypt, and the resulting fire spread to the LNG tanker GASLOG SALEM. The incident was assessed in the report as likely Iranian-directed retaliation rather than part of the Houthi campaign.
The U.S. Treasury's Office of Foreign Assets Control announced sanctions against Persian Gulf Marine Insurance Company and HormuzSafe Marine Services Authority for supporting an IRGC-backed maritime extortion and insurance scheme in the Strait of Hormuz, including accepting digital assets such as Bitcoin. In the same action, OFAC also sanctioned related companies and identified or blocked vessels tied to Iran's shadow fleet transporting Iranian petroleum products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourcewindward.ai
Open sourcehome.treasury.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.