❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’

24 August 2026 at 15:06

As part of its “economic D-Day” against Iran, the Treasury Department designated four Iranians for sanctions Monday stemming from their alleged role in hacking critical infrastructure targets and waging cybertheft against the United States.

It’s the second time in as many weeks that the Trump administration has taken aim at the same group of alleged hackers, following on an indictment recently unsealed against cybercriminals that federal law enforcement authorities say are affiliated with the Tehran-based Mabna Institute.

A Treasury Department release points the finger at three people — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i and Mojtaba Ghal’eh-Kuhi — as specifically conducting the hacks.

“Since at least late 2023, these three individuals have successfully compromised and exfiltrated data from multiple U.S. companies in various critical infrastructure sectors, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions,” the release states.

A fourth individual included in Monday’s sanctions, Mojtaba Ghal’eh-Kuhi, is listed as one of the leaders of the gang carrying out the Ministry of Intelligence and Security (MOIS)-directed attacks. Another listed leader, Behzad Mesri, first faced sanctions in 2018, as part of another round of sanctions focused on the Mabna Institute.

Finally, the Treasury Department designated one additional person Monday over related activity, Arman Kahzadian, for his alleged role in receiving or using business information stolen via cyber-enabled means.

The department said the Iranian hackers sometimes turn their gaze to domestic targets.

“The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS,” it said. “This has driven some of the group to target Iranian companies.“

Hackers that the U.S. government has identified as Iranian have been behind a spate of attacks on U.S. water facilities, despite denials from President Donald Trump himself about Iranian culpability.  The Treasury Department did not immediately respond to a request for comment Monday about whether the sanctions designees were involved in those attacks, nor has the National Security Agency responded to requests for comment on whether Iran was responsible for attacks at the center of an alert about attacks on water facilities.

Treasury Secretary Scott Bessent announced a fuller list of sanctions Monday as the war with Iran nears its five-month anniversary with no end in apparent sight.

“In the Second World War, D-Day marked the historic beginning of a campaign with our allies to target and drive the enemy from its positions, including those in third countries,” he said. “Today, in that same spirit, we are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone.”

There are questions about whether the sanctions themselves are likely to change any behavior, particularly based on how they will be enforced. Iran has vowed “consequences” for the United States.

As part of the sanctions announced Monday, according to the department, “Treasury is expanding the categories of Iran-related conduct that may be subject to secondary sanctions in the future, making it easier to take action against those facilitating the regime. Treasury has issued determinations against five critical sectors –– digital assets, technology, gold, aviation, and shipping––  that the Iranian regime uses to try to prop up its failing economy.”

The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.

Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute

18 August 2026 at 16:12

Federal authorities on Tuesday unsealed an indictment against 17 Iranians affiliated with the tech firm Mabna Institute, alleging a campaign of vast cybertheft on behalf of the Iranian government against universities, governments and companies.

It’s a second wave of indictments against the Tehran-based firm, expanding on and replacing a 2018 indictment of nine of the defendants from then and adding others. 

“Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions,” said Jamie McDonald, U.S. Attorney for the Southern District of New York. “More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad.”

Unlike in 2018, the United States is currently waging a war against Iran that recently saw a 60-day negotiation deadline pass with no progress.

“Cyber operations have become a central instrument of national power, and attacks on American and allied institutions carry direct consequences for our security and economic strength,” McDonald continued.

According to the Justice Department, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 with the goal of helping Iranian universities and scientific and research organizations to steal from foreign scientific efforts. In doing so, it paid hackers-for-hire listed in the indictment.

The institute has compromised more than 100,000 professors’ email accounts globally, the indictment alleges, and successfully compromised 8,000 accounts at 144 U.S. universities and 178 universities in other parts of the world.

Its hackers used stolen credentials to take academic journals, dissertations and e-books across all fields of research, at least 31.5 terabytes worth in total. The institute sometimes sold stolen data, according to the indictment. 

“Through the course of the conspiracy, U.S.-based universities spent more than approximately $3.4 billion to procure and access such data and intellectual property,” a press release on the indictment states.

The defendants also have compromised and stolen from email accounts for at least five U.S. federal and state government agencies, 42 U.S. companies and 11 foreign companies, among them HBO. 

In all, the indictment brings 14 separate, sometimes overlapping charges against the 17 defendants, with sentences for each offense ranging from two to 20 years.

In conjunction with the indictment, the State Department’s Rewards for Justice program is offering up to $10 million for information leading to the location of four of the defendants.

The post Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute appeared first on CyberScoop.

❌
❌