Iran flag
Image: Mostafa Meraji / Unsplash

US sanctions Iranian cyber actors as UK discloses power plant attack

The U.S. sanctioned several Iranian nationals on Monday for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

Treasury Secretary Scott Bessent unveiled a slate of new sanctions and measures designed to pressure the government of Iran as the U.S. attempts to reopen the critical Strait of Hormuz.

Among those sanctioned were at least six men accused of being part of a hacking operation housed within Iran’s Ministry of Intelligence and Security (MOIS). Four of the men were indicted last week for allegedly breaching employee email accounts connected to the Department of Labor, the Federal Energy Regulatory Commission and multiple organizations within the United Nations.

The Treasury Department said the men — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, Mojtaba Ghal’eh-Kuhi and two others who had previously been sanctioned — are part of a team that since 2023 has conducted cyberattacks on behalf of Iran’s MOIS and “is responsible for extensive compromises of U.S. critical infrastructure and financially motivated cyber theft.”

“The MOIS directs several networks of cyber threat actors involved in cyber espionage in support of Iran’s political goals, which include harming American civilians,” the agency said. 

According to Treasury officials, Blagh, Balujeh and Kadkhoda’i conducted the majority of the group’s initial intrusions and data thefts.

The group targeted critical infrastructure sectors including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions. 

“Additionally, in summer 2024, they compromised multiple local, state, and federal government offices across the United States,” the Treasury Department added. “The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS.” 

Several members of the group have also allegedly targeted Iranian companies or stolen cryptocurrency from local coin holders. 

Iranian threat actors have been accused of several hacking campaigns since the U.S. began conducting airstrikes against the country in February, including recent attacks targeting water systems in at least 12 states. Tehran also took credit for cyberattacks on a prominent medical device company as well as the personal email account of the FBI director

Iran’s hackers have also hit U.S. allies, and were reportedly able to shut down a small British power plant for four days. No one lost power and the attack did not affect the overall power grid, the Telegraph reported, the Telegraph reported

The incident reignited concerns that Iranian actors have the capability to breach critical infrastructure organizations responsible for water, power and other utilities. 

U.K. Energy Minister Michael Shanks said in social media posts that the government has briefed energy CEOs and shared further advice with companies on the steps they should take to stay secure. 

Last Wednesday, the FBI and National Security Agency warned that unnamed hackers are targeting specific operational technology — known as programmable logic controllers (PLC) — that are used widely by the energy, water and agricultural industries. 

Markus Mueller, a security official at Nozomi Networks with experience working at power plants, called the attack a “major escalation” from the targeting of water utilities. 

“This is the type of facility that a capable adversary that understands the systems could cause real damage to,” he said, noting there are reports the incident involved a PLC that was not secured. 

“If an adversary can get into the main control system that runs the turbine or boiler there is a greater safety risk.”

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.