Iran-Linked Attacks on Water and Energy Infrastructure: US Sanctions and UK Power Plant Shutdown
The US Treasury has sanctioned six Iranian MOIS-linked cyber operatives under Operation Economic Outcast, targeting individuals behind sustained attacks on US critical infrastructure including energy companies, defence contractors, hospitals, and financial institutions. Three of those designated — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i — have been conducting network compromise operations against US critical infrastructure since at least late 2023. Blockchain analysis by TRM Labs reveals $16.8 million in on-chain funds across 30 wallets linked to the Mabna Institute actors, with one individual controlling 92% of that volume. The State Department has concurrently offered a $10 million reward for information on foreign-directed cyber attacks against US critical infrastructure.
Separately, Iranian-linked hackers have attacked over 30 water and wastewater utilities across at least 12 US states. CISA and FBI are assisting recovery efforts. The attacks exploited basic vulnerabilities in exposed operational technology, reinforcing that many municipal systems remain dangerously soft targets. This is not speculative — the breaches are confirmed, ongoing, and affecting drinking water systems.
In the UK, suspected Iranian hackers forced a small power plant offline for four days, marking what is believed to be the first successful cyberattack on a British energy facility. The UK government has stated there was no risk to the wider energy system. The incident was first reported by The Telegraph and has not been formally attributed to Iran by either government, though cybersecurity analysts assess Iranian involvement as likely given the operational pattern and timing alongside the broader campaign.
Gitea RCE Added to KEV (CVE-2026-60004)
CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog on August 25, with a remediation deadline of August 28. The vulnerability allows attackers with repository write access to inject malicious code via the diffpatch API endpoint, planting executable Git hooks that run shell commands as the Gitea service account. Gitea patched this in version 1.27.1 (late July). This is the second Gitea exploitation in recent months — CVE-2026-20896 was flagged in early July. Gitea is widely deployed in self-hosted DevOps environments, and a compromised Git host gives attackers direct access to source code and CI/CD pipelines. Upgrade to 1.27.1 immediately. Audit Git hooks and repository access logs for any unauthorised changes.
So What / Action
The convergence of state-directed attacks on water, energy, and healthcare infrastructure with financial motivations ($16.8M in on-chain proceeds) means the threat model has shifted. These are not intelligence-gathering operations alone — the actors are also profit-driven, which lowers the threshold for collateral damage. For CISOs: (1) If you operate water, energy, or healthcare OT systems, treat Iranian-linked IOCs as active threats now, not theoretical. Audit all remote access paths and enforce network segmentation between IT and OT. (2) Gitea instances — upgrade to 1.27.1 and check for modified Git hooks. A compromised Gitea host is a supply chain risk for everything it builds. (3) The $10M State Department reward signals that the US is actively seeking attribution intelligence — share relevant indicators with CISA and FBI. (4) Review the OFAC designations and associated wallet addresses against your own transaction monitoring. These actors operate in both espionage and financially-motivated modes.

