Iran TerrorismUS Treasury Officials Targeted by Iranian Hackers

US Treasury Officials Targeted by Iranian Hackers

-

Iranian Hackers

Iran Focus

London, 17 Dec – The personal emails of American officials tasked with enforcing the recently reimposed sanctions were targeted by Iranian hackers last month, according to The Associated Press.

London-based cybersecurity group Certfa tracked a hacking group nicknamed Charming Kitten. The AP believes that the group spent the past month trying to break into the private emails of more than a dozen U.S. Treasury high-profile individuals involved in the nuclear deal between Washington and Tehran. Atomic scientists, Iranian civil society figures, and D.C. think tank employees were also allegedly targeted.

Among those targeted was Frederick Kagan, a scholar at the American Enterprise Institute. He has previously written about Iranian cyber-espionage. He explained, “Presumably, some of this is about figuring out what is going on with sanctions,” and added that he was alarmed by the targeting of foreign nuclear experts. “This is a little more worrisome than I would have expected,” he said.

Charming Kitten mistakenly left one of its servers open to the internet last month, allowing researchers at Certfa to discover the list. They extracted a list of 77 Gmail and Yahoo addresses targeted by the hackers, and gave it to the AP for further analysis. The addresses provide considerable insight into Tehran’s espionage priorities, but it’s not unclear how many of the accounts were successfully compromised. However, Certfa researcher Nariman Gharib said, “The targets are very specific.”

In a report published Thursday, Cerfta tied the hackers to the Iranian government. The hackers seem to have accidentally revealed that they were operating from computers inside Iran. Allison Wikoff, a researcher with Atlanta-based Secureworks, who has tracked Charming Kitten, recognized some of the digital infrastructure in Certfa’s report and said the hackers’ past operations left little doubt they were government-backed.

Iran has denied hacking operations, but the AP analysis of the targets suggests that Charming Kitten is working in close alignment with the Islamic Republic’s interests.

Certfa said that the Charming Kitten campaign relies on a technique is commonly used by hackers — the password-stealing “phishing” that mimics the look and feel of Gmail security alerts. Certfa’s data shows that at least 13 U.S. Treasury employees’ personal emails were targeted. One email account belongs to a director at the Financial Crimes Enforcement Network that fights money laundering and terror financing, and another is used by the Iran licensing chief at the Office of Foreign Asset Control who is in charge of enforcing U.S. sanctions. The signs seem to point to a state-backed operation.

“It doesn’t look like freelancers,” Kagan said.

Latest news

War and its Impact on Children’s Education in Iran

Repeated school closures during the war between the United States and Iran's regime have severely reduced the quality of...

Iran: Violent Transfer of Political Prisoners to the Notorious Ghezel Hesar Prison

On Monday, April 13, seven political prisoners held in Ward 7 of Evin Prison in Tehran were abruptly, violently,...

The German Government Will Not Receive the Son of Iran’s Last Shah

Following reports of Reza Pahlavi, the son of Iran’s last Shah Mohammad Reza Pahlavi, traveling to Germany to attend...

700,000 Jobs Lost in Iran as A Result of War

While the fate of the war in the region remains uncertain, reports from Iran indicate a suffocating livelihood crisis...

Iran: How Pahlavi’s Name Stole the January 2026 Uprising

In the biting cold of mid-January 2026, the air in Tehran’s Vali-e-Asr Square was thick with the scent of...

Escalating Executions in Iran Put EU Policy Under Scrutiny

A conference held at the European Parliament in Brussels on April 22, 2026, brought renewed attention to the escalating...

Must read

70,000 protest in central Tehran

Iran Focus: Tehran, Jun. 22 – Up to 70,000...

Tony Blair failed to see Iran threat, Lord Turnbull tells inquiry

The Times: Tony Blair was so committed to overthrowing...

You might also likeRELATED
Recommended to you