Newsclip — Social News Discovery

General

China Firm's Web Security Move Sparks Sanctions Concerns Over Iran's Strait Toll Operations

September 18, 2026
  • #Iran
  • #Sanctions
  • #Cybersecurity
  • #Technologypolicy
  • #Middleeast
  • #Ofac
8 views•0 comments
China Firm's Web Security Move Sparks Sanctions Concerns Over Iran's Strait Toll Operations

China Firm Briefly Enables Iran's Maritime Extortion Scheme

After a four-day window in which Iran's sanctioned Persian Gulf Straits Authority (PGSA) regained secure digital access, a Shanghai-based internet security firm revoked its web credentials—highlighting the complex intersection of technology, sanctions enforcement, and global maritime security. The move by TrustAsia Technologies, which issued a domain-validated certificate for pgsa.ir, sparked immediate concern among U.S. sanctions experts who warn that such services, even if automated, may breach U.S. policy.

"This is a class of vulnerability open to government exploitation, rather than a corporate breach or personal data leak," said Alp Toker, CEO of NetBlocks, referencing the shift in traffic protocols that occurred when the PGSA's site became inaccessible.

The PGSA, designated by the U.S. Treasury Department in May as part of its broader efforts to counter Iranian maritime extortion, operates a system that forces vessels transiting the Strait of Hormuz to pay fees—a scheme widely viewed as an illegal act under international law. Despite being added to OFAC's sanctions list, the PGSA was able to briefly resume secure web operations through TrustAsia's issuance of a new certificate.

Automated Certificates and Sanctions Risk

The automated nature of the certificate issuance, while seemingly routine, raises significant questions about compliance. TrustAsia, a company that bills itself as a leader in trusted digital communication, confirmed it issued a Domain Validated TLS certificate for pgsa.ir without performing checks on the entity's legal status or sanctions classification.

"DV certificates are issued through automated validation of control over the requested domain names," TrustAsia stated in an August 20 statement. "This process does not verify or assert the legal identity, affiliation, or sanctions status of the entity operating or benefiting from the domain."

However, this lack of vetting has not gone unnoticed by U.S. authorities. Former OFAC official Jeremy Paner emphasized that such actions—regardless of intent or automation—could trigger sanctions under Executive Order 13224. "Restoring the certificate is unequivocally sanctionable," he warned.

Global Implications and Compliance Failures

The incident also underscores a deeper issue in the global tech ecosystem: how Chinese certificate authorities like TrustAsia operate outside Western compliance frameworks, creating potential vulnerabilities for international digital security.

Toker noted that while TrustAsia had not been directly sanctioned by the U.S., its actions could prompt broader consequences. "This could have splintered the global chain of trust and potentially render much of the Chinese web inaccessible from the West," he said.

U.S. Treasury Secretary Scott Bessent, speaking on August 24, reinforced the government's approach toward such activities by expanding sanctions targeting nearly 60 Iran-linked individuals, entities, and vessels. While TrustAsia was not included in this latest round of penalties, the firm's actions are now under intense scrutiny.

Reputational Risk for Chinese Tech Firms

The TrustAsia case serves as a warning to Chinese tech firms operating in global markets—particularly those that may inadvertently provide services to sanctioned entities. Paner noted that,"There's always reputational risk involved in any company that decides to do business with the IRGC."

He further advised that companies should identify and audit all their existing relationships with Iranian entities to avoid potential future sanctions.

"If I were advising TrustAsia, I would at minimum immediately identify all other IRGC companies receiving services," Paner said. "This is a clear signal that U.S. enforcement may be escalating."

The Broader Sanctions Landscape

The U.S. government's approach to sanctions has increasingly shifted toward secondary liability—holding foreign entities accountable for supporting Iranian activities, even if those actions are not directly orchestrated by the U.S. itself. The recent expansion of secondary sanctions underscores this trend and signals that global technology firms must carefully navigate their operational policies.

As Iran continues to assert control over the Strait of Hormuz—a critical chokepoint for global oil supplies—any digital infrastructure supporting its maritime extortion efforts is now a point of contention in U.S. foreign policy. The fact that TrustAsia acted without clear due diligence highlights the risks for international companies that may not fully appreciate the implications of their services.

What's Next?

The revocation of the certificate by TrustAsia, which occurred on August 21, effectively ended the PGSA's secure access. However, this does not resolve the broader legal and ethical questions raised by the episode. The U.S. Treasury Department and OFAC may now initiate a more thorough review of TrustAsia's compliance practices, potentially leading to new enforcement actions.

As international scrutiny intensifies, firms that provide services to sanctioned entities—regardless of automation or oversight—may find themselves facing an uncertain future in global markets. For now, the brief period during which Iran's maritime authority could collect tolls remains a cautionary tale for tech firms and policymakers alike.

Key Facts

  • Primary Entity: TrustAsia Technologies
  • Sanctions Designation: Persian Gulf Straits Authority (PGSA) is sanctioned by U.S. Treasury Department
  • Certificate Type: Domain Validated TLS certificate
  • Certificate Issuance Date: August 20, 2026
  • Certificate Revocation Date: August 21, 2026
  • PGSA Website Domain: pgsa.ir
  • U.S. Sanctions Authority: Executive Order 13224
  • Sanctions Expert Warning: Restoring certificate is sanctionable under U.S. law

Background

A Shanghai-based internet security firm, TrustAsia Technologies, briefly enabled Iran's sanctioned maritime authority, the Persian Gulf Straits Authority (PGSA), to collect tolls through the Strait of Hormuz by issuing a domain-validated TLS certificate for pgsa.ir. The PGSA had been designated as a sanctioned entity by the U.S. Treasury Department in May 2026 due to its role in maritime extortion, which is considered illegal under international law. TrustAsia's automated issuance of the certificate without verifying the legal status or sanctions classification of the entity operating the domain raised concerns among U.S. sanctions experts. The certificate was revoked by TrustAsia on August 21, 2026, following scrutiny and warnings about potential sanctions implications.

Quick Answers

What is TrustAsia Technologies?
TrustAsia Technologies is a Shanghai-based internet security firm that bills itself as a leader in trusted digital communication and issued a domain-validated certificate for pgsa.ir, enabling Iran's sanctioned maritime authority to collect tolls.
When did TrustAsia issue the certificate?
TrustAsia issued the certificate on August 20, 2026, according to a statement from the company.
Why is the PGSA sanctioned?
The PGSA is sanctioned by the U.S. Treasury Department because it operates a system that forces vessels transiting the Strait of Hormuz to pay fees, which is viewed as an illegal act under international law.
What happened after TrustAsia revoked the certificate?
TrustAsia revoked the certificate on August 21, 2026, which effectively ended secure access for the PGSA to collect tolls through its website.
Who warned about sanctions implications?
Former OFAC official Jeremy Paner warned that restoring the certificate was sanctionable under Executive Order 13224 and could trigger U.S. sanctions against TrustAsia.
What type of certificate did TrustAsia issue?
TrustAsia issued a Domain Validated TLS certificate for pgsa.ir, which is an automated process that verifies control over the requested domain name without manual vetting or background checks.
Is there a risk of foul play in this case?
Authorities have not identified signs of foul play in TrustAsia Technologies' actions, as the certificate issuance was part of an automated process without verification of legal status or sanctions classification.
How did NetBlocks respond to this incident?
NetBlocks CEO Alp Toker stated that the incident created a vulnerability open to government exploitation rather than a corporate breach, noting that standard SSL/TLS certificates were lost and traffic shifted to insecure protocols.

Frequently Asked Questions

What was TrustAsia Technologies' role in this case?

TrustAsia Technologies issued a domain-validated TLS certificate for pgsa.ir, which enabled Iran's sanctioned maritime authority to collect tolls through the Strait of Hormuz.

Why did TrustAsia issue the certificate despite sanctions?

TrustAsia issued the certificate through an automated validation process that does not verify or assert the legal identity, affiliation, or sanctions status of the entity operating or benefiting from the domain.

What are the implications for international digital security?

The incident highlights how Chinese certificate authorities like TrustAsia operate outside Western compliance frameworks, potentially creating vulnerabilities in global digital security and raising concerns about access to Chinese web services from Western systems.

Who is responsible for the PGSA's online operations during this period?

Iran's sanctioned Persian Gulf Straits Authority (PGSA) was responsible for the online operations, but TrustAsia Technologies provided the technical infrastructure through its issuance of a domain-validated certificate.

What did TrustAsia say about their compliance practices?

TrustAsia confirmed that DV certificates are issued through automated validation and do not verify or assert the legal identity, affiliation, or sanctions status of the entity operating or benefiting from the domain. They added the entire pgsa.ir domain namespace to a restricted-issuance list after the incident.

How long was the PGSA website accessible through TrustAsia?

The PGSA website was accessible through TrustAsia for approximately four days before the certificate was revoked on August 21, 2026.

Source reference: https://www.foxnews.com/world/china-firm-gave-iran-lifeline-collect-hormuz-tolls-before-pulling-plug-amid-us-warning

Comments

Sign in to leave a comment

Sign In

Loading comments...

More from General