US sanctions Mabna Institute members over infrastructure intrusions

The U.S. Department of the Treasury has sanctioned five individuals it says are linked to the Tehran-based Mabna Institute and responsible for widespread compromises of U.S. organizations, including critical-infrastructure entities. The designations form part of Operation Economic Outcast, a broader campaign that targets nearly 60 Iran-linked entities, individuals and vessels across nuclear, missile, oil and cyber networks.
Treasury said the cyber group operates on behalf of, or for the benefit of, Iran's Ministry of Intelligence and Security (MOIS). The agency alleges that three of the designated members, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh and Mohammad Reza Kadkhoda'i, carried out much of the network-compromise activity and exfiltrated data from U.S. companies since at least late 2023.
Critical sectors and alleged dual motives
The affected targets included energy companies, defence contractors, healthcare institutions, information-technology companies and financial institutions. Treasury also said the group combined activity aligned with MOIS objectives with financially motivated cyber theft, and that some members put personal enrichment ahead of operations benefiting the Iranian intelligence service.
In summer 2024, the actors were believed to have compromised several local, state and federal government offices in the U.S. Treasury further alleged that Mojtaba Ghal'eh-Kuhi and Saber Shahbazi Balujeh exfiltrated data from an Iranian telecommunications company a year later. Arman Kahzadian was described as focusing primarily on cryptocurrency theft, including the alleged takeover of a Bitcoin wallet holding more than $30,000 in summer 2023.
Financial tracking and a wider pressure campaign
TRM Labs analysed 30 wallets associated with the five Mabna Institute members and found that they had received about $16.8 million in total. The firm said 10 addresses linked to Keyvan Fayyaz Ghareh Blagh received a combined $15.5 million between January 6, 2018 and August 20, 2026, representing 92% of the network's on-chain volume. The aggregate remaining balance across the 30 addresses was $202,662.
The measures arrive alongside a State Department Rewards for Justice offer of up to $10 million for information on people conducting malicious cyber activity against U.S. critical infrastructure under the direction or control of a foreign government. Treasury's wider operation also places attention on digital-asset activity connected to Iran and the Islamic Revolutionary Guard Corps.
What defenders should take from the activity
SentinelOne described Iran-linked operations as a set of clusters with different missions and tradecraft, spanning data collection, destructive activity, social engineering, cloud compromise, dissident surveillance and opportunistic targeting of exposed operational-technology assets. Security researcher Tom Hegel characterized the key strategic risk as access optionality: the same compromised account, service provider or remote-management foothold may later be used for intelligence gathering, downstream targeting or selective disruption.
For businesses in critical sectors and their suppliers, the practical implication is to assess exposed accounts, third-party connections and remote-management access as enduring risk paths, because a single foothold can support more than one type of malicious operation as an actor's tasking changes.

