Table of Contents
Seventeen Iranian hackers charged by the United States now stand accused of running one of the largest academic cyber theft campaigns on record. The Justice Department unsealed an indictment containing 14 counts against members of the Mabna Institute, a company in Iran tied to the Islamic Revolutionary Guard Corps (IRGC), the elite military branch that answers to Iran’s supreme leader.
Prosecutors say the group breached hundreds of universities, companies, and government agencies across two dozen countries starting in 2013.
The State Department is offering rewards of up to $10 million for five of the accused, a sign of how seriously Washington treats intellectual property theft directed by a foreign government.
Iranian Hackers Charged: Key Takeaway
- US prosecutors charged 17 Mabna Institute members over an IRGC campaign that stole more than 31 terabytes of research from hundreds of institutions worldwide.
This section contains affiliate links; we may earn a commission at no cost to you.
Tools to help you find and close these flaws before attackers do:
- Tenable: vulnerability management to locate every affected Oracle instance and prioritize the critical fixes.
- CyberUpgrade: cybersecurity compliance and management to keep patch cycles on track and audit ready.
- Auvik: network monitoring to spot suspicious traffic hitting exposed services.
- IDrive: cloud backup and recovery so a successful attack does not become data loss.
What the US Justice Department Announced
The Justice Department this week unsealed a superseding indictment, meaning an updated charging document that replaces an earlier one, against 17 members of the Mabna Institute.
Federal prosecutors describe the institute as an Iran based company created to help Iranian universities and research bodies obtain scientific material from outside the country by force rather than by license.
The charges include conspiracy to commit computer intrusions, conspiracy to commit wire fraud, computer fraud, wire fraud, and aggravated identity theft, which refers to the criminal use of another person’s login details or identity.
The case was filed in the Southern District of New York and assigned to US District Judge Jesse M. Furman.
The defendants have not been convicted. As the Justice Department stresses, the charges are allegations, and every defendant is presumed innocent unless and until proven guilty in court.
A Case That Began in 2018
This is not a brand new investigation. Nine of the 17 people named in the current indictment were first charged in an earlier document that carried seven counts, announced in March 2018. The 2026 filing adds eight more defendants and paints a fuller picture of the network behind the intrusions.
That eight year gap matters. It shows that US prosecutors continue building a case long after the initial breach, and that indictments can grow as investigators identify more people involved.
Who Are the Iranian Hackers Charged
According to the indictment, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013. The institute then employed, contracted, or otherwise worked with a wider group of operators.
The full roster of Iranian hackers charged includes Abdollah Karima (also known as Vahid Karima), Mostafa Sadeghi, Seyed Ali Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Abuzar Gohari Moqadam, Sajjad Tahmasebi, Saeid Houshyar, Behzad Mesri (also known as Skote Vahshat), Manouchehr Hashemloo, Keyvan Fayaz (who used the handles Achilles, The Joker, and bc.monster), Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian, and Mojtaba Galekuhi (also known as Mojtaba Ghaleh Koui).
Prosecutors say the group acted on behalf of the IRGC as well as other Iranian government and university clients.
Inside the Mabna Institute Operation
The indictment frames the Mabna Institute as an operation that hacked for hire. It served two masters at once: the Iranian state, including the IRGC, and private customers who wanted access to research they could not obtain legally.
How the Intrusions Worked
At the center of the campaign was a simple and durable technique: stealing the login details of people who already had legitimate access. Prosecutors say the defendants targeted more than 100,000 professor accounts worldwide and successfully compromised roughly 8,000 of them.
Those accounts spanned 144 universities in the US and 178 institutions abroad, in countries including Australia, Canada, China, Denmark, Finland, Germany, Ireland, Israel, Italy, Japan, Malaysia, the Netherlands, Norway, Poland, Saudi Arabia, Singapore, South Korea, Spain, Sweden, Switzerland, Turkey, and the United Kingdom.
Stolen Credentials and Compromised Email Accounts
Once the hackers held a professor’s username and password, they logged in as that person and quietly copied out data. In security terms this is called exfiltration, the act of moving stolen files out of a network without being noticed.
The stolen material cut across engineering, medicine, technology, and many other research fields. Because the attackers were using real accounts rather than obvious malware, ordinary defenses that look for viruses often had nothing to flag.
Selling the Stolen Research
The theft was also a business. The indictment alleges that the defendants sold stolen data through two companies, Megapaper and Gigapaper, both linked to Abdollah Karima. These sites gave paying customers access to compromised university accounts and academic databases.
In effect, work that universities and their funders paid for was resold to buyers who never covered the cost of producing it.
Beyond Academia: The HBO Extortion
The group’s reach went past universities. Prosecutors say the defendants also hit private and government targets, including the entertainment company HBO, where one of the accused is tied to a roughly $6 million extortion attempt. That episode shows the same operators moving from quiet data theft to open financial pressure.
The $10 Million Rewards for Justice Bounties
Alongside the charges, the US government is using its Rewards for Justice program, a State Department scheme that pays for tips on threats to national security, to help track the accused down.
The program is offering rewards of up to $10 million for information leading to the arrest of five defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.
Most of the accused are believed to be in Iran, which does not extradite its nationals to the United States. Financial rewards and public indictments are among the few tools available when arrests on home soil are unlikely, and they can restrict a defendant’s ability to travel or move money for years.
Who Was Affected
Universities and Professors
Universities bore the brunt of the campaign. Prosecutors count 144 US universities and 178 foreign ones among the victims, with thousands of individual professors having their email accounts taken over.
The stolen 31 terabytes of academic data represents years of research effort. The Justice Department puts the figure at about 31.5 terabytes.
Companies, Government Agencies, and NGOs
The reach extended well beyond campuses. The indictment lists at least 42 private companies in the US and 11 abroad, five US federal and state government agencies, and at least two nongovernmental organizations.
In those cases the hackers targeted employee email accounts, opening a door into corporate and government correspondence.
This section contains affiliate links; we may earn a commission at no cost to you.
Harden the accounts, servers, and data these flaws put at risk:
- 1Password: a password manager to tighten the credentials that many of these bugs rely on.
- Plesk: server and hosting management to keep the web tier and its components patched.
- Tresorit: encrypted cloud storage to limit exposure if a file disclosure flaw is exploited.
Implications of State-Sponsored Academic Espionage
The Long Reach of US Cyber Prosecutions
The most striking feature of this case is patience. Eight years after the first charges, prosecutors returned with a bigger indictment and more names. That signals to state linked operators that going quiet does not close a file.
It also lets the US publish detailed attribution, which pressures allies to treat the same actors as hostile and complicates the defendants’ lives abroad even when arrests are out of reach.
Credentials Remain the Weakest Link
This campaign did not rely on exotic tools. It relied on valid usernames and passwords. That is the same weakness behind many modern breaches, and it explains why credential theft, password reuse, and weak email protection keep appearing in major incidents.
Multi factor authentication, strong password management, and monitoring for logins from unusual locations would have raised the cost of these intrusions considerably.
Universities as Soft Targets
Research institutions are hard to defend by design. They value open collaboration, host tens of thousands of accounts, and rarely fund security to the level of a bank or defense contractor. That combination makes them a rich and comparatively easy target for an adversary hunting intellectual property.
Universities that treat research data as a crown jewel, and defend it accordingly, are better placed than those that assume no one wants their academic files.
Hacking for Hire as an Instrument of the State
The Mabna Institute blurred the line between a government operation and a commercial one. It stole for the IRGC and sold to private buyers at the same time.
This model lets a state gain deniability while spreading the cost, and it means defenders cannot always tell whether they face a nation, a criminal group, or both at once. Treating the intent as hostile, regardless of the label, is the safer posture.
Conclusion
The indictment of 17 Mabna Institute members is one of the broadest academic espionage cases the United States has brought. Prosecutors describe a campaign that ran for years, hit hundreds of universities, companies, and agencies, and moved more than 31 terabytes of research and intellectual property.
The method was not sophisticated so much as relentless. Stolen professor credentials, quiet data exfiltration, and resale through front companies did most of the work, which is a reminder that basic account security still stops a great deal of harm.
With five defendants carrying $10 million bounties and most beyond the reach of arrest, the practical payoff of this case is attribution and pressure rather than a courtroom. For defenders, the lesson is plainer: protect credentials, watch for quiet logins, and assume research data has a buyer.
Questions Worth Answering
Who was charged in the Mabna Institute case?
- The US charged 17 members of the Iran based Mabna Institute, including founders Gholamreza Rafatnejad and Ehsan Mohammadi, over a cyber theft campaign tied to the IRGC.
What is the Mabna Institute?
- Prosecutors describe it as a company in Iran, founded around 2013, that helped Iranian universities and research bodies steal scientific resources from outside the country and operated as a hacking for hire service.
How much data did the hackers allegedly steal?
- More than 31 terabytes of academic data and intellectual property, which the Justice Department puts at roughly 31.5 terabytes, along with many employee email accounts.
Who were the victims?
- 144 US universities, 178 foreign universities, at least 42 US companies, 11 foreign companies, five US federal and state government agencies, and at least two nongovernmental organizations.
How did the attackers get in?
- They stole and used the login credentials of professors and employees, then logged in as those people to copy out data, rather than relying mainly on malware.
What is the $10 million reward about?
- Through the State Department’s Rewards for Justice program, the US is offering up to $10 million for information leading to the arrest of five defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh.
Is this a new investigation?
- No. Nine of the 17 defendants were first charged in March 2018, and the 2026 superseding indictment adds eight more names and further detail.
What does the IRGC have to do with it?
- Prosecutors say the group carried out many intrusions on behalf of Iran’s Islamic Revolutionary Guard Corps, as well as other Iranian government and university clients.
Did the hackers target anything besides universities?
- Yes. The indictment ties the group to attacks on private companies and government agencies, including a roughly $6 million extortion attempt against HBO.
Will the defendants face trial?
- Most are believed to be in Iran, which does not extradite its nationals to the US, so arrests are unlikely in the near term. The charges remain allegations, and the defendants are presumed innocent.
Affiliate links; we may earn a commission at no cost to you.
Also worth a look: lock down logins with Passpack, stop email spoofing with EasyDMARC, and scrub your exposed personal data from broker sites with Optery.
Sources
- SecurityWeek, primary report: https://www.securityweek.com/us-charges-17-iranian-hackers-offers-10-million-rewards-for-5-of-them/
- US Department of Justice press release: https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary
- State Department Rewards for Justice program: https://rewardsforjustice.net/