The U.S. Treasury Department has sanctioned four Iranian hackers accused of breaching U.S. healthcare institutions and other critical infrastructure targets.
The Treasury’s Office of Foreign Assets Control designated Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i and Mojtaba Ghal’eh-Kuhi, citing a cyber campaign directed by Iran’s Ministry of Intelligence and Security, per an Aug. 24 news release. Since at least late 2023, three of the four — Mr. Fayyaz Ghareh Blagh, Mr. Shahbazi Balujeh and Mr. Kadkhoda’i — have compromised and exfiltrated data from multiple U.S. companies across critical infrastructure sectors, including energy firms, defense contractors, healthcare institutions, IT companies and financial institutions, according to Treasury.
The action was taken in coordination with the FBI, which on Aug. 18 announced the unsealing of a superseding indictment charging 17 Iranian cyber actors, four of whom are the sanctioned individuals.
“Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone,” Treasury Secretary Scott Bessent said in a statement on the broader campaign, dubbed Operation Economic Outcast.
The designations freeze any U.S.-based assets tied to the individuals and bar Americans from transacting with them, part of a wider action that sanctioned nearly 60 Iran-linked entities, individuals and vessels.