The U.S. Treasury Department on Monday, August 25, 2026 designated a group of Iranian nationals accused of running a Ministry of Intelligence and Security (MOIS) directed hacking operation against American energy companies, defense contractors, hospitals, IT firms, financial institutions and government offices. Treasury Secretary Scott Bessent framed the designations as part of a wider sanctions package billed as an "economic D-Day" against Tehran. Accounts of the action's size differ: Nextgov/FCW reports that five Iranian nationals were sanctioned Monday, noting that a sixth named man, Behzad Mesri, had already been sanctioned in 2018, while Tech Times describes the cell as six designated individuals and attributes roughly $16.8 million in cryptocurrency proceeds to the network. The $16.8M figure and the "Operation Economic Outcast" label appear only in the Tech Times account and should be treated as unconfirmed pending Treasury's own release. Nextgov separately reports that four of the named individuals were also charged last week under the Justice Department's expanded Mabna Institute case.
What Happened
Treasury named Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i and Mojtaba Ghal'eh-Kuhi as participants in an MOIS-directed intrusion set, with Arman Kahzadian designated separately over digital asset theft. Behzad Mesri, sanctioned in 2018, is described alongside Ghal'eh-Kuhi as a group leader.
The division of labor is consistent across both accounts. Blagh, Balujeh and Kadkhoda'i carried out the bulk of the network intrusions and data theft. Ghal'eh-Kuhi and Mesri led the group. Kahzadian specialized in cryptocurrency theft, including taking control of a Bitcoin wallet holding more than $30,000 in 2023.
Sources differ slightly on the operational start date. Nextgov reports intrusions "since late 2023" with leadership in place "since at least 2023"; Tech Times places the unit's activity from "at least mid-2023." Both agree the group compromised multiple critical infrastructure sectors, and Nextgov adds that the three primary operators are believed to have breached several local, state and federal government offices during the summer of 2024.
Both accounts also agree on a detail that matters more than it first appears: personal profit was a significant motive alongside intelligence tasking. Ghal'eh-Kuhi and Balujeh allegedly turned their tooling against targets inside Iran, including an Iranian telecommunications company. That is a criminal-enterprise behavior pattern wearing a state badge, and it changes the deterrence calculus. Sanctioning the Iranian state and sanctioning these individuals are not the same lever.
The designations land in the middle of an active, ongoing campaign against U.S. operational technology. CISA advisory AA26-097A, originally published April 7, 2026 and last revised July 22, 2026, warns of Iranian-affiliated actors disrupting programmable logic controllers across multiple U.S. critical infrastructure sectors. On July 30, 2026, the FBI and EPA issued a joint public service announcement reporting that water and wastewater utilities in at least seven states had filed incident reports since July 27, with some activity degrading water operations. Tenable's tracking, citing an ABC News report, puts the spread at at least 12 states, including more than 30 Minnesota communities; Dark Reading corroborates the dozen-state figure and names Georgia, Michigan, South Dakota, Alabama and New Jersey among affected states, with Columbus Water Works confirmed as a second Georgia victim.
Attribution for the water sector attacks specifically remains pending federal investigation, per Tenable, though the timing aligns closely with the Iranian-affiliated PLC exploitation documented in AA26-097A. Dark Reading characterizes the link as "possibly linked to the Iranian government." Treat the water campaign and the sanctioned MOIS cell as adjacent and temporally correlated, not as formally merged by any primary source.
What Was Taken
Two distinct categories of loss are in evidence.
Data. Treasury describes theft of data from U.S. energy companies, defense contractors, health care institutions, technology firms and financial institutions, plus compromise of local, state and federal government offices in summer 2024. Neither source quantifies records, files or volume. No record count has been published, and defenders should not assume one exists.
Money and control. The confirmed monetary figure attributed to a single named actor is the Bitcoin wallet containing more than $30,000 seized by Kahzadian in 2023. The much larger $16.8 million aggregate rests on Tech Times' account and a referenced TRM Labs on-chain analysis of roughly 30 Bitcoin, Ethereum and TRON addresses. Reported figures for the network's total proceeds therefore range from the ~$30K Treasury attributes to one wallet up to the ~$16.8M attributed by Tech Times citing TRM Labs. Only the smaller figure is corroborated by a second source.
The third category is not data at all. Per AA26-097A and the FBI/EPA PSA, actors exfiltrated PLC project files, then modified or deleted project logic, manipulated HMI and SCADA displays, changed device IP addresses and passwords, and disabled shutdown and alarm functions. What was taken there was operator visibility and control, producing what the FBI describes as loss of monitoring and control functionality and what Tenable records as reported physical consequences including pressure loss and flooding.
Why It Matters
Three things should reset priorities for anyone defending OT.
First, the intrusions are low-complexity and high-consequence. Dark Reading's framing is blunt: these are cheap attacks against ill-secured, internet-exposed controllers. There is no zero-day story here. The exposure is the vulnerability.
Second, the disruption is real-world and durable. SecurityWeek reports, based on a Telegraph story broken August 22, 2026 and subsequently followed by the BBC, Guardian and Financial Times, that Iran-linked hackers shut down a British power plant for four days in July 2026. Virtually no information has come from official UK sources such as the NCSC, so this remains press-sourced and officially unconfirmed. As Huntress's Muhammad Yahya Patel framed it, the significant fact is not the facility's size but that a cyberattack produced four days of operational disruption, and that recovery took that long.
Third, the financial motive inside a state unit means sanctions may not deter the way they are supposed to. Operators who steal from their own country's telecom company are operators whose incentives are not fully controlled by their principal. Expect continuity of activity under new names.
The Attack Technique
The technical picture from AA26-097A, the FBI/EPA PSA and SecurityAffairs' reporting on the joint CISA/FBI/NSA/DOE advisory is consistent and actionable:
- Initial access: direct connection to internet-exposed OT devices over OT protocol ports 44818 (EtherNet/IP), 2222, 102 (S7comm) and 502 (Modbus), and to modems over SSH (port 22).
- Targeted hardware: the FBI has specifically observed Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs. The July 22 CISA update expands scope to Schneider Electric, Siemens and potentially any other internet-exposed PLC.
- Project file abuse: exfiltration of PLC project files using legitimate vendor engineering tools including Studio 5000, EcoStruxure Control Expert and TIA Portal, followed by modification or deletion of project logic including Add-On Instructions (AOIs). The July 22 update adds guidance specifically for detecting malicious changes in reusable code modules within Rockwell programs.
- Operator blinding: manipulation of HMI and SCADA display data so operators see normal conditions, plus disabling of shutdown and alarm functions.
- Lockout: changing device IP addresses and passwords to strip owners of monitoring and control, per both the FBI PSA and CISA's sector alert.
Weak or default credentials on internet-facing controllers are the recurring enabler.
What Organizations Should Do
- Get PLCs off the public internet now. This is the single controlling recommendation from CISA, the FBI and EPA alike. Place controllers behind a secure gateway and firewall, and work with IT/OT staff or your integrator to verify the change actually removed exposure rather than relocating it.
- Rotate every credential on OT devices to strong, unique passwords, and audit for vendor defaults. Assume any device that was internet-facing during 2026 has had its credentials harvested.
- Apply access control lists permitting only expected control-system-to-control-system communication, and block external reachability of ports 44818, 2222, 102, 502 and 22 at the perimeter.
- Hunt against AA26-097A indicators. Query available logs for the IOCs published in the advisory, and specifically diff current PLC project files and Add-On Instructions against known-good offline baselines. Logic-level tampering will not show up in network telemetry.
- Baseline and verify HMI/SCADA integrity. If display data can be manipulated, your console is not a source of truth during an incident. Establish out-of-band physical verification for critical process values.
- Rehearse recovery, not just detection. The UK power plant case, as reported, took four days to restore. Maintain offline copies of PLC programs and configurations and time an actual restore drill.
- Sanctions compliance check. Organizations that have paid or transacted with any entity linked to these designations should review OFAC exposure with counsel, given that four of the named individuals also face DOJ charges under the expanded Mabna Institute case.
Sources: Operation Economic Outcast Exposes Iranian Spies Who Hacked U.S. In... | Minnesota & other US Water Cyber Attacks, CISA AA26-097A Tenable® | Iranian-Affiliated Cyber Actors Exploit Programmable Logic ... | Malicious Cyber Actors Targeting Water and Wastewater ... | Iran-Linked Hackers Shut Down UK Power Plant for Four Days - Securi... | Multistate Water System Attacks Widen, Iran Suspected | Iran-Linked Actors Breach Are Targeting US Water and Energy Control... | Treasury sanctions Iranian hackers tied to critical ...