U.S. sanctions Iranian attackers behind U.S. power grid attacks

Published August 25, 2026

The U.S. Treasury sanctioned Iranian attackers tied to Iran's intelligence ministry for breaking into American energy, defense, healthcare, IT, and financial companies and stealing data, plus stealing cryptocurrency for personal profit.

Report priority
High
Involves
Defense contractors

What to do

The Treasury's sanctions freeze any U.S. assets of the five named individuals and bar Americans from dealing with them, so organizations in these sectors should watch for guidance from CISA or the FBI and report any related intrusion.

Reported details

One of the sanctioned men, Arman Kahzadian, took control of a cryptocurrency wallet holding more than $30,000 in Bitcoin in summer 2023. Blockchain analysis firm TRM Labs later traced tens of wallets tied to the group, finding they had received about $16.8 million total. Separately, other members of the same network broke into and pulled data from multiple U.S. critical infrastructure companies starting in late 2023.

The Treasury Department's Office of Foreign Assets Control sanctioned five men tied to Iran's Ministry of Intelligence and Security (MOIS) and the Tehran-based Mabna Institute, following a DOJ indictment. Three of them, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i, are accused of breaching and exfiltrating data from multiple U.S. critical infrastructure companies since late 2023. A fourth, Arman Kahzadian, focused on cryptocurrency theft.

TRM Labs traced roughly $16.8 million across 30 wallets linked to the group. No specific intrusion technique, malware, or software vulnerability was disclosed in connection with these breaches.