The U.S. Treasury sanctioned five Iranian nationals for alleged cyber intrusions, data theft, and misuse of stolen business information tied to Iran’s Ministry of Intelligence and Security (MOIS). U.S. officials said the group had targeted critical infrastructure, government entities, and international organizations since at least late 2023, with victims spanning the energy, defense, healthcare, information technology, and finance sectors. Treasury said some of the accused also pursued personal financial gain and, in some cases, targeted Iranian companies in addition to foreign organizations.
The sanctions were announced amid broader U.S. and U.K. warnings about Iranian cyber activity affecting operational technology environments. Officials linked the action to ongoing concern over attacks on U.S. water systems and a reported disruption at a small British power plant, underscoring the risk to industrial control systems and programmable logic controllers (PLCs) used across energy, water, and agriculture. The move also aligns with a wider campaign against Iranian cyber operators, including a recently unsealed U.S. indictment involving alleged affiliates of the Tehran-based Mabna Institute.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
On Monday, the U.S. Treasury Department sanctioned four Iranians for alleged hacking and cyber-enabled theft against U.S. critical infrastructure and sanctioned Arman Kahzadian for allegedly receiving or using stolen business information. Treasury said the activity was directed by Iran's MOIS and that some members also pursued personal profit, including targeting Iranian companies.
The Treasury Department said the group compromised multiple local, state, and federal government offices across the United States during summer 2024.
Treasury said the accused individuals had conducted cyberattacks on behalf of Iran's Ministry of Intelligence and Security since at least late 2023, compromising and exfiltrating data from multiple U.S. companies. Targeted sectors included energy, defense, healthcare, information technology, and finance.
The Treasury Department said Behzad Mesri, identified as another leader of the MOIS-linked group, had previously been sanctioned in a 2018 action focused on the Mabna Institute.
The U.K. disclosed that Iranian hackers reportedly shut down a small British power plant for four days without causing outages, prompting renewed concern about operational technology security. Energy Minister Michael Shanks said the government briefed energy CEOs and shared additional security guidance with companies.
According to The Record, four of the sanctioned men were indicted the previous week for allegedly breaching employee email accounts linked to the U.S. Department of Labor, the Federal Energy Regulatory Commission, and multiple United Nations organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.