FAULT LINES
Signals That Move Strategy
Hot Spots · Americas · Cyber

US Sanctions Iranian MOIS Cyber Actors for Critical Infrastructure Breaches; UK Discloses Separate Power Plant Intrusion

The Treasury Department sanctioned six Iranian nationals tied to the Ministry of Intelligence and Security on August 24 for cyberattacks on U.S. critical infrastructure since 2023, including breaches of the Department of Labor, Federal Energy Regulatory Commission, and UN offices. The action coincides with disclosure of an Iranian cyber intrusion that shut down a small British power plant for four days, reigniting concerns about adversary capability against energy and water systems.
AI synthesis, editor-reviewed · 1 source · August 24, 2026
Photo: The Record (Recorded Future)

The sanctions are tactical pressure on an ongoing campaign, not a deterrent — these six operators have been active since 2023 and hit U.S. critical infrastructure through summer 2024, meaning Treasury is naming actors well into their operational lifetime. The real escalation signal is that Iran is now running dual-track cyber operations: espionage and infrastructure disruption in support of the Hormuz blockade, paired with financially motivated theft to fund operations. If the PLC targeting the FBI and NSA warned about last Wednesday is connected to the MOIS team, the U.S. faces a coordinated effort to degrade energy resilience while negotiations over the strait are underway — making cyber attacks a bargaining chip alongside naval blockade.

WHY IT MATTERS

Treasury is escalating sanctions pressure on Iranian cyber operators while the U.S. attempts to reopen the Hormuz Strait — a signal that cyber disruption of critical infrastructure is now a direct cost of Iran's blockade strategy.

The MOIS team has operated since 2023 targeting energy, defense, healthcare, IT, and financial sectors across the U.S., plus water systems in at least 12 states, and the FBI and NSA just warned (last Wednesday) that unnamed attackers are targeting programmable logic controllers (PLCs) used across energy, water, and agricultural industries. Watch whether the next Iranian cyber operation targets a larger or more strategically critical facility — the British power plant shutdown, while limited, proves the access chain works, and the PLC warning suggests the adversary is hunting for higher-impact targets.

WHAT THIS DOESN’T TELL US

Did the Iranian operators who shut down the British power plant belong to the MOIS team Treasury just sanctioned, or is this a separate cell? The timing suggests connection, but the article does not confirm attribution.

Sources: The Record (Recorded Future)
LinkedInX

Fault Lines

Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.

Front page → Get the weekly brief →