
The sanctions are tactical pressure on an ongoing campaign, not a deterrent — these six operators have been active since 2023 and hit U.S. critical infrastructure through summer 2024, meaning Treasury is naming actors well into their operational lifetime. The real escalation signal is that Iran is now running dual-track cyber operations: espionage and infrastructure disruption in support of the Hormuz blockade, paired with financially motivated theft to fund operations. If the PLC targeting the FBI and NSA warned about last Wednesday is connected to the MOIS team, the U.S. faces a coordinated effort to degrade energy resilience while negotiations over the strait are underway — making cyber attacks a bargaining chip alongside naval blockade.
Treasury is escalating sanctions pressure on Iranian cyber operators while the U.S. attempts to reopen the Hormuz Strait — a signal that cyber disruption of critical infrastructure is now a direct cost of Iran's blockade strategy.
The MOIS team has operated since 2023 targeting energy, defense, healthcare, IT, and financial sectors across the U.S., plus water systems in at least 12 states, and the FBI and NSA just warned (last Wednesday) that unnamed attackers are targeting programmable logic controllers (PLCs) used across energy, water, and agricultural industries. Watch whether the next Iranian cyber operation targets a larger or more strategically critical facility — the British power plant shutdown, while limited, proves the access chain works, and the PLC warning suggests the adversary is hunting for higher-impact targets.
Did the Iranian operators who shut down the British power plant belong to the MOIS team Treasury just sanctioned, or is this a separate cell? The timing suggests connection, but the article does not confirm attribution.
Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.