"Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions," stated U.S. Attorney Jamie McDonald.
The federal indictment and the expanded case
The U.S. Department of Justice has returned an expanded criminal case accusing 17 Iranian nationals of participating in years‑long hacking operations alleged to have been run by a hacking‑for‑hire company called Mabna Institute. Nine of the defendants were previously charged in a March 2018 indictment; the latest filing adds eight more names to the case and signals a renewed effort by prosecutors to identify and pursue suspects who operate from abroad.
The Mabna Institute operation: scope, timeline, and quantified losses
According to the DoJ, the operation began around 2013 and focused on accounts used by academics. Investigators say the campaign targeted the accounts of more than 100,000 professors worldwide and successfully compromised roughly 8,000 accounts. Using that access, the defendants allegedly stole 31.5 terabytes of academic data — journals, theses, dissertations, ebooks, and other research — which the government values at approximately $3.4 billion.
The DoJ’s announcement ties that theft to concrete institutional impact: 178 universities were affected (144 of them in the U.S.), at least 53 private firms were hit (42 in the U.S.), two non‑governmental organizations were affected, and at least 10 U.S. state agencies were targeted.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildThe defendants, alleged roles, and reward offers
The DoJ lists eight individuals connected to the newly charged phase of the case: Saeid Houshyar; Behzad Mesri, aka “Skote Vahshat”; Manouchehr Hashemloo; Keyvan Fayaz, aka “Achilles,” “The Joker,” and “bc.monster”; Amir Barati; Saber Shahbazi Ballojeh; Arman Kahzadian; and Mojtaba Galekuhi, aka “Mojtaba Ghaleh Koui.”
The government alleges these Iranians carried out cyber operations on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and paying customers. The DoJ has announced rewards of up to $10 million for information leading to the location of five of the defendants; the State Department separately announced rewards of up to $10,000,000 for information leading to the whereabouts of Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh. A Tor link has been provided to allow anonymous submissions.
Charges filed, potential penalties, and a high‑profile extortion example
The defendants face counts including conspiracy to commit computer intrusions, wire fraud, unauthorized access for financial gain, and aggravated identity theft. Those charges carry maximum individual penalties of up to 20 years in prison on some counts. The DoJ singled out one nonacademic victim: the entertainment company HBO, which the announcement says was extorted for $6 million in Bitcoin.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: the case highlights credential theft and account compromise as central vectors — the DoJ says attackers used professor accounts at scale to harvest research and proprietary material, suggesting defenders should consider account integrity and anomalous access patterns when prioritizing detection and response.
- Policymakers and law enforcement: prosecutors have combined criminal indictments with public reward offers and anonymous submission channels, signaling a continued emphasis on cross‑border attribution and capture efforts tied to nationalist and commercial objectives.
- Affected universities and private firms: institutions listed among the 178 universities and 53 private firms can expect renewed federal engagement, potential requests for cooperation, and the public documentation of both loss estimates (31.5 terabytes; $3.4 billion) and specific incidents such as the HBO extortion.
More than eight years after the original indictments became public, federal prosecutors framed the new charges as proof that time does not erase investigative reach. The case combines large data volumes, quantified economic value, and named defendants with aliases, while the government is offering substantial rewards for information leading to their location. All defendants are presumed innocent until proven guilty in a court of law.




