US Treasury Unleashes 'Operation Economic Outcast' Against Iranian Cyber Actors, Targets Digital Assets
The U.S. Department of the Treasury has launched an 'unprecedented, whole-of-government, economic campaign' dubbed 'Operation Economic Outcast' against Iran, imposing fresh sanctions on nearly 60 entities and individuals, including malicious cyber actors. This aggressive move aims to sever financial lifelines supporting the Iranian regime, with a particular focus on the digital assets sector.

The **U.S. Department of the Treasury** has announced a significant escalation in its economic pressure campaign against Iran, codenamed **Operation Economic Outcast**. This initiative targets nearly 60 Iran-linked entities, individuals, and vessels across various sectors, including nuclear, missile, oil, and crucially, cyber networks and digital assets.
According to Secretary of the Treasury Scott Bessent, the objective is clear: "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone."
## Targeting Malicious Cyber Groups
A key focus of these sanctions is a malicious cyber group affiliated with Iran's **Ministry of Intelligence and Security (MOIS)**. This group is implicated in extensive compromises of U.S. critical infrastructure and financially motivated cyber theft. The Treasury states that the **MOIS** directs several networks of cyber threat actors involved in cyber espionage, supporting Iran's political goals, which include harming American civilians.
Among those sanctioned are five individuals who were recently indicted by the **U.S. Justice Department** for widespread compromises against U.S. entities. These individuals are alleged members of the Tehran-based **Mabna Institute**:
* **Behzad Mesri**
* **Mojtaba Ghal'eh-Kuhi**
* **Keyvan Fayyaz Ghareh Blagh**
* **Saber Shahbazi Balujeh**
* **Mohammad Reza Kadkhoda'i**
* **Arman Kahzadian**
**Keyvan Fayyaz Ghareh Blagh**, **Saber Shahbazi Balujeh**, and **Mohammad Reza Kadkhoda'i** are accused of conducting the majority of network compromise activities. Since at least late 2023, they have successfully breached and exfiltrated data from numerous U.S. critical infrastructure companies, including those in energy, defense, healthcare, information technology, and finance.
The Treasury notes that while this group frequently conducts cyber exploitations for the **MOIS**, some members are also heavily motivated by personal enrichment, even targeting Iranian companies for profit.
## Cryptocurrency Heists and Financial Flows
**Arman Kahzadian**, for instance, has reportedly focused on cryptocurrency heists, illicitly gaining control of a wallet containing over $30,000 worth of Bitcoin in summer 2023.

Blockchain analytics firm **TRM Labs** analyzed 30 wallets linked to the five **Mabna Institute** members, revealing approximately $16.8 million in total received funds. **Keyvan Fayyaz Ghareh Blagh** alone holds 10 addresses that received a collective $15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network's on-chain volume. Similarly, 15 wallet addresses associated with **Behzad Mesri** received $1.2 million between July 12, 2019, and August 22, 2026.
Earlier this year, **TRM Labs** also exposed how two U.K.-based front companies, **Zedcex** and **Zedxion**, facilitated over $1 billion in stablecoin transactions for the **Islamic Revolutionary Guard Corps (IRGC)**. **DomainTools** further corroborated this, describing the **Zedxion-Zedcex** constellation as a "financial faΓ§ade ecosystem."
Ari Redbord, Global Head of Policy at **TRM Labs**, emphasized the broader implications: "Iran is not the only target here. In fact, the focus is secondary sanctions. That is the Treasury's max pressure move. The Treasury is putting every country and platform still doing business with Iran on notice and the digital assets space is a focus of Operation Economic Outcast."
## Rewards for Information and Broader Cyber Activity

In parallel, the **U.S. Department of State's Rewards for Justice** program has announced a reward of up to $10 million for information leading to the identification or location of individuals engaged in malicious cyber activities against U.S. critical infrastructure under the direction or control of a foreign government.
Iranian threat actors have been linked to numerous hacking campaigns, including the breach of **FBI** Director Kash Patel's personal email account and recent attacks targeting over 30 water and wastewater utilities in at least 12 U.S. states. The cyber activities have also extended to U.S. allies, with suspected Iranian hackers blamed for a four-day shutdown of a small power plant in the U.K. last month.
**SentinelOne** characterizes Iran-linked activity as a multi-pronged threat, comprising various clusters with distinct missions, targeting, and tradecraft. These range from data collection and destruction to social engineering, cloud compromise, surveillance of dissidents, and opportunistic targeting of exposed operational technology assets.