Operation Economic Outcast: Treasury Sanctions Nearly 60 Iran-linked Targets and Names Digital Assets a Sanctionable Sector
TRM User Conference
Which mission will you select?
Key takeaways
- Treasury's Operation Economic Outcast designated nearly 60 Iran-linked entities, individuals, and vessels and issued five sectoral sanctions determinations under Executive Order 13902 — covering digital assets, technology, gold, aviation, and shipping.
- Five Mabna Institute members named in the action were also charged in DOJ's August 18 superseding indictment; OFAC listed 30 of their crypto addresses across Bitcoin, Ethereum, and TRON.
- TRM analysis of the 30 addresses found roughly USD 16.8 million in total funds received, with 92% of volume concentrated in one defendant's addresses.
- Compliance teams should screen historical transactions for exposure to the listed addresses and prepare for secondary sanctions risk tied to Iran's digital assets sector.
Treasury action
Operation Economic Outcast
On August 24, 2026, the US Department of the Treasury launched Operation Economic Outcast, describing it as a whole-of-government economic campaign against the Islamic Republic of Iran and its enablers.
According to Treasury, the Office of Foreign Assets Control (OFAC) designated nearly 60 entities, individuals, and vessels in this action, spanning networks involved in nuclear and missile procurement, cyber operations, and oil revenue generation. Secretary of the Treasury Scott Bessent framed the campaign in his statement as an economic onslaught intended to sever the financial connections that sustain the Iranian regime. Additionally, OFAC issued five sectoral sanctions determinations against Iranian industries, including the digital assets sector.
Five of the individuals named in the August 24 designations were also indicted by the Department of Justice (DOJ) on August 18, 2026, for their work with Mabna Institute, an Iran-based company that DOJ said conducted cyber intrusions on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients. Four of those five individuals control cryptocurrency addresses highlighted by Treasury as part of their sanctions designation, whose on-chain activity we’ll analyze below.
Digital assets named a sanctionable sector
Treasury issued five sectoral sanctions determinations under Executive Order 13902. These determinations expand the categories of Iran-related conduct that may be subject to secondary sanctions, and they allow OFAC to sanction any person or entity providing services in support of five sectors of the Iranian economy. Those sectors are digital assets, technology, gold, aviation, and shipping.
What does this mean for digital assets? Under the new sectoral determination, any institution that processes a significant transaction for an Iranian exchange or digital assets business in turn risks its access to the US financial system. TRM has previously covered how EO 13902 secondary-sanctions exposure applies to Iran's designated domestic crypto exchanges.
The August 24 designations follow recent TRM Labs reporting on Shelbit, Zedcex, and Coinex, exchanges TRM identified as functioning as financial rails for Iran and its proxies.
Mabna Institute: DOJ indictment and sanctions designation reveal on-chain footprint
Superseding indictment against the Mabna Institute
Five of the individuals sanctioned today are connected to the Mabna institute, an Iran-based company that the Department of Justice (DOJ) says has conducted a coordinated campaign of cyber intrusions since at least 2013, acting as a hacking-for-hire group. A few days prior on August 18, 2026, the Department of Justice unsealed a superseding indictment charging 17 members of the Mabna Institute with hacking-related offenses, including all five sanctioned today. According to DOJ, the Mabna Institute compromised systems belonging to 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, at least 11 foreign private sector companies, at least five US federal and state government agencies, and at least two non-governmental organizations. DOJ said the Mabna Institute stole more than 31 terabytes of academic data and intellectual property in the course of this campaign.
Nine of the 17 defendants were previously charged in a 2018 indictment. According to DOJ, the superseding indictment adds eight additional defendants and describes continued targeting of American and international institutions, including the compromise of employee email accounts at US federal and state government agencies and international organizations.
Mabna Institute on the blockchain
The OFAC designations against the Mabna Institute listed 30 crypto addresses across Bitcoin, Ethereum, and TRON belonging to four of the 17 defendants. According to TRM, analysis of all 30 addresses found roughly USD 16.8 million in total funds received, with activity stretching back to January 2018.

The volume is concentrated with one defendant. According to TRM, Keyvan Fayaz — who the indictment says used the online handles Achilles, The Joker, and bc.monster — holds ten addresses that received a combined USD 15.5 million between January 6, 2018 and August 20, 2026, accounting for 92% of the network's on-chain volume, a concentration that suggests he may have acted as a treasury of sorts for Mabna's hacking-for-hire operations. Addresses belonging to Behzad Mesri, the defendant separately charged with hacking HBO, show a pattern of layered transactions between his addresses, with hundreds of thousands ultimately funneled to a deposit address at a large centralized exchange, likely to be cashed out — on-chain behavior commonly used to obfuscate source of funds.
.pptx%20(49).png)
According to TRM, the combined residual balance across all 30 addresses is USD 202,662, roughly 1% of the USD 16.8 million that passed through them.
What this means for on-chain compliance teams
While the specific addresses associated with Mabna Institute threat actors named in the August 24 designations hold little residual value, cryptocurrency compliance teams should still check their historical transaction records for on-chain exposure. Additionally, compliance teams should be ready to screen for secondary sanctions risk, and flag incoming transactions from any wallets with exposure to Mabna Institute wallets.
More broadly, the sectoral sanctions against Iran's digital assets industry make it even more important for digital assets businesses to screen out transactions from Iranian entities.
Frequently asked questions (FAQs)
1. What is Operation Economic Outcast?
Operation Economic Outcast is a whole-of-government US economic campaign against Iran and its enablers, announced by the Treasury Department on August 24, 2026. In the opening action, OFAC designated nearly 60 entities, individuals, and vessels spanning nuclear and missile procurement, cyber operations, and oil revenue generation, and issued five sectoral sanctions determinations under Executive Order 13902 covering digital assets, technology, gold, aviation, and shipping. Treasury has described the campaign as an effort to sever the financial connections that sustain the Iranian regime, with teams from the Departments of Treasury, State, and War engaging counterparts abroad and, in Treasury's telling, giving every country a defined timeline to shut down the Iran-related activity it has identified.
2. What are sectoral sanctions, and how do they work in cryptocurrency?
Sectoral sanctions target an entire sector of an economy rather than a list of named individuals and companies. Under the August 24 determinations, OFAC can designate any person or entity that operates in — or provides significant support to — Iran's digital assets, technology, gold, aviation, or shipping sectors, without first identifying and listing each target individually. For digital assets, that means an exchange, payment provider, or other business anywhere in the world that processes a significant transaction for an Iranian exchange or digital assets business risks secondary sanctions and its access to the US financial system, even where the Iranian counterparty has not been separately designated. The practical implication is that screening against listed addresses alone is no longer sufficient: firms need to identify Iranian exposure at the sector level.
3. What is the Mabna Institute?
The Mabna Institute is an Iran-based company that DOJ says has run a coordinated hacking-for-hire campaign since at least 2013 on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients. On August 18, 2026, DOJ unsealed a superseding indictment charging 17 Mabna members, adding eight defendants to the nine charged in a 2018 indictment. According to DOJ, the group compromised systems at 144 US-based universities, 178 foreign universities, at least 42 US-based and 11 foreign private sector companies, at least five US federal and state government agencies, and at least two non-governmental organizations, stealing more than 31 terabytes of academic data and intellectual property. Five of the defendants were also designated by OFAC in the August 24 action.
4. What crypto addresses were designated, and what does TRM's analysis show?
OFAC listed 30 crypto addresses across Bitcoin, Ethereum, and TRON belonging to four of the 17 Mabna Institute defendants. According to TRM, those addresses received roughly USD 16.8 million in total, with activity stretching back to January 2018. The volume is heavily concentrated: ten addresses controlled by Keyvan Fayaz account for USD 15.5 million, or 92% of the network's on-chain volume. The combined residual balance across all 30 addresses is USD 202,662 — about 1% of what passed through them collectively.




















