CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

August 25, 2026

The U.S. Department of the Treasury has announced new sanctions targeting Iranian cyber actors as part of Operation Economic Outcast, an economic campaign aimed at severing financial lifelines to the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC). The sanctions designate nearly 60 entities, individuals, and vessels across nuclear, missile, oil, and cyber networks, including the digital assets sector.

Among those sanctioned are five individuals indicted by the U.S. Justice Department for widespread compromises of U.S. critical infrastructure. These individuals are alleged members of the Tehran-based Mabna Institute, operating under Iran’s Ministry of Intelligence and Security (MOIS). The group has been linked to breaches of energy companies, defense contractors, healthcare institutions, IT firms, and financial entities since late 2023. They have also targeted U.S. government offices and conducted cryptocurrency heists.

Blockchain analytics firm TRM Labs analyzed 30 wallets linked to the five members, finding approximately $16.8 million in total funds received. The Treasury’s action also highlights the role of U.K.-based front companies Zedcex and Zedxion in facilitating IRGC financing, processing about $1 billion in funds. DomainTools described the Zedxion-Zedcex constellation as a financial façade ecosystem.

The State Department’s Rewards for Justice program is offering up to $10 million for information on individuals conducting malicious cyber activities against U.S. critical infrastructure under foreign government direction. Iranian threat actors have been attributed to recent attacks, including the breach of FBI Director Kash Patel’s email and intrusions into over 30 water utilities across 12 states.

Security firm SentinelOne characterized the Iran-linked activity as a multi-pronged threat with various clusters, ranging from data collection to operational technology targeting. The ongoing conflict has also spawned a pro-Iran hacktivist ecosystem, which uses Telegram, DDoS-for-hire tools, and leak amplification to exert psychological and political pressure.

CVEs: CVE-2026-58231

Attack groups: Mabna Institute, MOIS cyber group

Companies: TRM Labs, DomainTools, SentinelOne

Events: Operation Economic Outcast