A Shanghai-based internet security company, TrustAsia, provided Iran’s sanctioned Persian Gulf Straits Authority (PGSA) with secure online credentials, enabling the authority to regain secure web access for four days despite ongoing U.S. digital restrictions and sanctions [1]. This allowed Tehran to vet vessels, collect tolls for the Strait of Hormuz, and operate its website securely, according to global internet monitors [1]. TrustAsia issued an automated domain-validated certificate, a standard process that does not typically involve manual vetting or background checks [1].
The PGSA had lost its web security credentials after being added to the U.S. Office of Foreign Assets Control (OFAC) sanctions list on May 27, which rendered its website inaccessible via standard browsers and forced shipping firms to use unencrypted connections [1]. NetBlocks CEO Alp Toker explained that this shift to insecure protocols increased the risk of government interception and made it easier for authorities to identify shipping firms collaborating with the PGSA, though no data breaches or detrimental use of intercepted data have been reported [1].
U.S. sanctions experts, including Jeremy Paner of Hughes Hubbard & Reed, urged TrustAsia to review its compliance program before providing further services to the IRGC-linked maritime authority, warning of potential consequences if they did not act promptly [1]. The PGSA announced on August 17 that the issue had been resolved and secure access to its website was restored, but also indicated that if the problem recurred, temporary insecure access would again be available [1].
The incident highlights the ongoing challenges and vulnerabilities faced by sanctioned entities in maintaining digital operations and the potential exposure of sensitive data when secure protocols are disrupted [1].
CONCLUSION
The brief restoration of secure web access for Iran’s PGSA by a Chinese firm underscores the complexities of enforcing digital sanctions and the risks posed by insecure connections. While no data breaches were reported, the episode drew warnings from U.S. experts and highlighted the potential for government exploitation of such vulnerabilities.
