Published · 22h agoSecurity2 min read
Treasury designates MOIS hackers; the UK plant that stopped for four days is not in the file
Monday's package attributes years of critical infrastructure intrusion to a MOIS team and puts names on a charge sheet. The plant outage everyone is discussing appears nowhere in it.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Four of the men were indicted last week over breaches of employee email accounts tied to the Labor Department, FERC and several United Nations organizations.
- A reported intrusion kept a small British power plant offline for four days, with no customers losing power and no effect on the wider grid.
- Treasury also issued determinations covering digital assets, technology, gold, aviation and shipping, widening the conduct that can draw secondary sanctions later.
- The FBI and NSA warned last Wednesday that unnamed hackers are going after programmable logic controllers used across energy, water and agriculture.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposureThe people newly reachable are not in Tehran: counterparties in the five determined sectors can be designated later for facilitation, which prices fresh diligence into every intermediary bank...
- contradictionTreasury pins extensive US critical infrastructure compromise on this group while the President has denied Iranian culpability for the water attacks, and the department would not say whether the...
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The U.S. sanctioned several Iranian nationals on Monday for cyberattacks on critical infrastructure, days after reports of a cyber intrusion at a small power plant in the United Kingdom.
ReportedView cited source - [2]
At least six men were sanctioned as alleged members of a hacking operation housed within Iran's Ministry of Intelligence and Security, comprising four newly named men (Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, Mojtaba Ghal'eh-Kuhi) and two others previously sanctioned.
ReportedView cited source - [3]
Four of the men were indicted last week for allegedly breaching employee email accounts connected to the Department of Labor, the Federal Energy Regulatory Commission and multiple organizations within the United Nations.
ReportedView cited source - [4]
Treasury said the men are part of a team that since 2023 has conducted cyberattacks on behalf of Iran's MOIS and is responsible for extensive compromises of U.S. critical infrastructure and financially motivated cyber theft.
ReportedView cited source - [5]
The group targeted critical infrastructure sectors including energy companies, defense contractors, healthcare institutions, information technology companies and financial institutions.
ReportedView cited source - [6]
Treasury said that in summer 2024 the group compromised multiple local, state and federal government offices across the United States.
ReportedView cited source
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cyberscoop.comTim StarksyesterdayTreasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
- therecord.mediayesterdayUS sanctions Iranian cyber actors as UK discloses power plant attack


