
The U.S. Treasury Department has sanctioned at least six Iranian nationals accused of carrying out cyberattacks on American critical infrastructure on behalf of Iran’s Ministry of Intelligence and Security (MOIS). The action came on the same day that reports emerged of a separate Iranian cyber intrusion on a small power plant in the United Kingdom — one that reportedly kept the facility offline for four days, though no customers lost power and the broader grid was unaffected.
Among those sanctioned are Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda’i — all accused of leading the group’s initial intrusions and data theft operations. According to Treasury, the team has been active since 2023 and has targeted energy companies, defense contractors, healthcare institutions, IT firms, financial institutions, and local, state, and federal government offices across the United States. Four of the men were also indicted last week for allegedly breaching employee email accounts at the Department of Labor, the Federal Energy Regulatory Commission, and organizations within the United Nations. Treasury officials noted that some members of the group were also motivated by personal financial gain, conducting cryptocurrency theft from Iranian coin holders on the side. The UK disclosure, reported by The Telegraph and acknowledged by UK Energy Minister Michael Shanks, adds to a growing pattern: Iranian threat actors have hit U.S. water systems in at least 12 states since the U.S. began airstrikes against Iran in February, took credit for breaching a medical device company, and targeted the personal email account of the FBI director. The FBI and NSA separately warned last week that unnamed hackers are actively targeting programmable logic controllers (PLCs) used by energy, water, and agricultural industries — the same class of industrial devices that were at the center of the UK power plant incident.
