China firm gave Iran lifeline to collect Hormuz tolls before pulling plug amid US warning

After briefly issuing a web security certificate for a portal linked to Iran’s U.S.-sanctioned Persian Gulf Strait Authority, a Shanghai-based firm revoked it, though the move could still draw scrutiny under U.S. sanctions rules 

Iran’s sanctioned Persian Gulf Straits Authority (PGSA) regained secure online access for four days after a Shanghai-based internet security firm provided and then revoked its web credentials, enabling Tehran to vet vessels, collect Strait of Hormuz tolls and operate despite U.S. digital restrictions, global internet monitors said.

TrustAsia issued an automated domain-validated certificate, a routine process that verifies control of a website domain through server checks and typically does not involve manual vetting or background checks. 

The move prompted U.S. sanctions experts, including Jeremy Paner, a partner at Hughes Hubbard & Reed, to urge TrustAsia to review its compliance program before offering further services to the IRGC-linked maritime authority — with Paner warning them to act “before it is too late.” 

The PGSA first said its website was disrupted Aug. 10 because of “the enemy’s political influence on the internet service provision systems,” according to a post on X.

IRAN REQUESTS TALKS WITH US AS WHITE HOUSE WARNS ‘VIOLENCE WILL BE MET WITH VIOLENCE’

NetBlocks CEO Alp Toker told Fox News Digital that the authority had lost its web security credentials after the entity was added to the U.S. Office of Foreign Assets Control (OFAC) sanctions list on May 27.

The loss of standard SSL/TLS certificates, Toker said, made the PGSA website inaccessible using standard browsers. This forced shipping firms to use unencrypted connections that, according to Toker, could leave their data vulnerable to interception.

While no data breaches resulting from the use of these connections have been made known, and there are no known instances in which a shipping firm’s data was intercepted and used to its detriment because of the certificate expiration, Toker said the site’s inaccessibility resulted in a shift to what he described as “insecure protocols.”

“The digital transparency records are authoritative on this,” he said, adding that the measure forced the traffic into a format that could be readily intercepted.

“This is a class of vulnerability open to government exploitation, rather than a corporate breach or personal data leak.”

Toker claimed this could make it easier for authorities to read communications sent through the platform, potentially identifying shipping firms collaborating with the PGSA.

TRUMP SAYS IRAN WILL PAY — WHAT IT TAKES TO END THE WAR REMAINS UNCLEAR

“The net result was that the website was more difficult to access, because most web browsers strongly encourage the use of secure HTTPS,” Toker said, adding that any form submissions could have been easily “eavesdropped on because they’re no longer encrypted in transit.” 

“The mentioned issue has been resolved, and the secure domain https://pgsa.ir is now once again available for submitting requests using any browser,” the PGSA said six days later on Aug. 17 and in another post shared on X. 

“If the issue recurs in the future, the HTTP domain will again be temporarily available using the Firefox browser.”

Toker confirmed that Iran had turned to Shanghai-based certificate authority TrustAsia Technologies, which he said issued new digital security credentials to the PGSA despite the U.S. sanctions and restoring secure access to its website. 

“Iran’s IRGC extorts vessels transiting the Strait of Hormuz through the so-called Persian Gulf Strait Authority,” the Treasury Department said in May when designating the entity, adding that the PGSA “spearheads an Iranian-controlled scheme that flagrantly violates international law and U.S. sanctions.”

“Anyone cooperating with the so-called strait authority may be providing support to and receiving services from the IRGC, which ultimately benefits from this attempted extortion, and may therefore be exposed to sanctions risk,” the Treasury Department warned.

The Chinese firm bills itself as a “leading and professionally certified certification authority in China with its focus on trusted, secure and cryptographic communications in the digital world.”

Its mission, it says, is to “Build trust everywhere in the digital world.”

“Almost all of these root authorities do business with the U.S., so they tend to comply with U.S. sanctions,” Toker said.

But TrustAsia, he noted, had “gone its own way, building a China-first certificate infrastructure that sidesteps the West.”

Toker said TrustAsia had “simply gone ahead and issued Iran’s PGSA with a new certificate, and Iran was once again collecting revenue from ships passing the Strait via its secure online portal.”

TRUMP CALLS ON ARAB NATIONS TO SIGN ABRAHAM ACCORDS

Paner warned that U.S. authorities would have enforcement powers over such actions.

“The U.S. has incredibly broad authority to impose sanctions on non-Iranian companies that provide any sorts of services to sanctioned Iranian companies,” he told Fox News Digital.

“Many times, that authority will be abbreviated or explained as being providers of material support to sanctioned Iranian companies. But in fact, any level of services whatsoever could be the basis for the United States imposing sanctions against the company for providing services to Iran.”

“Restoration of the certificate is unequivocally sanctionable,” Paner warned.

“Restoring the certificate is/was a service provided to the PGSA, which can be the basis for imposing sanctions pursuant to Executive Order 13224, as amended.

“That authority does not in any way require that the service be “knowingly” provided to the PGSA. In other words, the automated nature of the service is irrelevant and does not make the service any less sanctionable,” the lawyer added.

In a statement to Fox News Digital on Aug 20, a spokesperson for TrustAsia confirmed that the firm issued a “Domain Validated TLS certificate for pgsa.ir.”

“Thank you for bringing this matter to our attention,” the firm said before clarifying that “DV certificates are issued through automated validation of control over the requested domain names.”

IRAN ACCELERATES EXECUTION CAMPAIGN AGAINST ANTI-REGIME ACTIVISTS AMID INTERNET CENSORSHIP

“This process does not verify or assert the legal identity, affiliation, or sanctions status of the entity operating or benefiting from the domain.

“As a result, the relationship described in your inquiry was not identified during the automated issuance process.” Following the firm’s review, TrustAsia said it “added the entire pgsa.ir domain namespace to our restricted-issuance list to prevent further issuance or renewal. “

“We also expect to complete revocation of the existing certificate within this week,” the spokesman said on Aug. 20.

These actions are precautionary compliance and risk-control measures. They should not be interpreted as a finding that the certificate was technically misissued, TrustAsia said.

Toker confirmed the TrustAsia certificate’s privilege had been withdrawn on Aug. 21 at 12:15:25 UTC. “This usually means the issuer has taken action,” he said.

The internet expert clarified that the revocation will gradually be coming into effect, with the firm “signaling that the PGSA certificate should no longer be trusted, and they’re distributing this notice that privilege is withdrawn, usually meaning customer misuse or breached terms of use.”

“The secure website will stop working in most browsers, unless the owners can find a certificate authority that’s willing to issue a new certificate,” Toker said.

IRAN’S UNSEEN SUPREME LEADER BECOMES WEAPON IN ESCALATING POWER STRUGGLE, EXPERTS SAY

After reviewing TrustAsia’s statement, Paner also said that OFAC would expect the company to “use the discovery as an opportunity to enhance its compliance program before it is too late.”

The former OFAC official clarified that Iran’s revenue collection in the waterway would likely draw high-level scrutiny in Washington.

“Iran’s attempt to extort the world in the movement of oil through the Strait of Hormuz is of the utmost importance to OFAC, which is the agency that implements and enforces U.S. economic sanctions.

Because major U.S. web browsers currently recognize TrustAsia’s root certificates, American systems would have automatically trusted the sanctioned Iranian portal.

Toker claimed the Treasury Department could have found TrustAsia in violation of sanctions for providing material assistance to a blocked entity, potentially forcing tech giants such as Google and Microsoft to revoke trust in TrustAsia.

There is no evidence that this process had begun or was likely to occur.

“This could have splintered the global chain of trust and potentially render much of the Chinese web inaccessible from the West,” Toker warned.

IRAN IS NOT A NORMAL NATION YOU CAN MAKE DEALS WITH; IT’S A NATIONAL SECURITY THREAT

Paner clarified that the certificates authenticate the site, boosting its credibility, and suggested TrustAsia should have weighed the risks of working with sanctioned entities.

“There’s always reputational risk involved in any company that decides to do business with the IRGC.”

“If I were advising TrustAsia, I would at minimum immediately identify all other IRGC companies receiving services.”

Paner added that this latest situation aligned with broader warnings from administration officials.

“I think this dovetails pretty nicely with Secretary Bessent’s comments about how the coming sanctions are going to be unlike any that has come prior. Sanctions require a careful balancing of the costs and the benefits.

“When it’s a Chinese tech company providing necessary services to the IRGC, I’m confident that the U.S. government is going to forego any sort of balancing in that regard.”

The United States on Aug. 24 had sanctioned nearly 60 Iran-linked individuals, entities and vessels and expanded the threat of secondary sanctions, Treasury Secretary Scott Bessent said. These did not include TrustAsia.

Bessent described the measures as part of an “economic onslaught” targeting Tehran’s global financial networks under “Operation Economic Outcast.” 

A Chinese Embassy spokesperson also said in a statement: “I am not aware of the specifics you mentioned. I have no information to provide.”

Fox News Digital reached out to the U.S. Department of the Treasury and The White House for comment.

 31717026-a180-5847-a89c-cf85131309de, fnc, Fox News, fox-news/politics/finance/sanctions, fox-news/world, fox-news/tech/topics/security, fox-news/topic/trending-news, fox-news/politics/executive/national-security, fox-news/world/conflicts/iran, fox-news/politics/defense/wars/war-with-iran, fox-news/world, article 

Leave a Reply

Your email address will not be published. Required fields are marked *