The U.S. Treasury launched Operation Economic Outcast, a sweeping sanctions campaign targeting the Iranian regime and its support network, designating nearly 60 entities, individuals, and vessels and issuing five sectoral sanctions determinations under Executive Order 13902. Treasury also explicitly identified digital assets as a sanctionable Iranian sector, a move that raises secondary-sanctions exposure for exchanges and other firms that facilitate significant transactions involving Iranian digital asset businesses.
A key cyber component of the action targeted five individuals tied to the Iran-based Mabna Institute, whose members were also charged by the U.S. Department of Justice for an alleged long-running hacking-for-hire operation conducted on behalf of the IRGC and other Iranian clients. OFAC published 30 cryptocurrency addresses linked to four Mabna defendants across Bitcoin, Ethereum, and TRON; blockchain analysis cited in reporting said the addresses received about $16.8 million since 2018, with roughly 92% of the volume concentrated in wallets attributed to Keyvan Fayaz.

See the reporting duties and controls this puts on the clock.
9 events from the most recent confirmed update back to the earliest known activity.
On August 24, 2026, OFAC designated UAE-based Ukrainian national Ivan Obukhov for acting as a broker for Iranian shadow fleet vessels and facilitating sanctions evasion. Treasury said he had processed more than $100 million in cryptocurrency payments since 2023 to support IRGC-Qods Force oil sales.
In the August 24, 2026 designations, OFAC included five individuals tied to the Mabna Institute and published 30 cryptocurrency addresses belonging to four of the 17 defendants across Bitcoin, Ethereum, and TRON. TRM said the addresses had received roughly USD 16.8 million in total funds.
As part of the August 24, 2026 action, OFAC issued five sectoral sanctions determinations under Executive Order 13902 covering digital assets, technology, gold, aviation, and shipping. The digital-assets determination allows sanctions on persons or entities providing services in support of Iran's digital assets sector and raises secondary sanctions risk for firms processing significant transactions for Iranian exchanges or digital asset businesses.
On August 24, 2026, the U.S. Department of the Treasury launched Operation Economic Outcast, describing it as a whole-of-government economic campaign against Iran and its enablers. OFAC designated nearly 60 entities, individuals, and vessels tied to nuclear and missile procurement, cyber operations, and oil revenue generation.
On August 18, 2026, the Department of Justice unsealed a superseding indictment charging 17 members of the Mabna Institute with hacking-related offenses. The filing added eight defendants to the nine previously charged in 2018.
Treasury alleged that Mabna-linked actors began breaching and exfiltrating data from U.S. critical-infrastructure-sector companies in late 2023, including organizations in the energy, defense, healthcare, IT, and financial sectors.
TRM said activity on the 30 cryptocurrency addresses later listed by OFAC stretched back to January 2018. Ten addresses attributed to Keyvan Fayaz received funds between January 6, 2018 and August 20, 2026.
The superseding indictment states that nine of the 17 Mabna defendants had previously been charged in a 2018 indictment.
According to the Department of Justice, the Iran-based Mabna Institute conducted a coordinated hacking-for-hire campaign on behalf of the IRGC and other Iranian government and university clients since at least 2013.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcechainalysis.com
Open sourceinfosecurity-magazine.com
Open sourcetrmlabs.com
Open sourcehome.treasury.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.