Skip to main content
Emerging ThreatsMalware & Ransomware

US Charges 17 Iranians in Massive Cybertheft Campaign

Dimly lit hallway with offices, lined with plants and framed documents.

31.5 terabytes: federal prosecutors say that is the volume of academic data the Tehran-based Mabna Institute stole in a years‑long hacking-for-hire operation that reached into hundreds of universities, dozens of companies and multiple government agencies.

The Mabna Institute and the expanded indictment

A 14‑count superseding indictment unsealed Tuesday charges 17 Iranians affiliated with the Mabna Institute, adding eight defendants to a case first brought in 2018 against nine other members of the firm. Prosecutors say the expanded charges expose a broader network that conducted cyber intrusions for Iran’s Islamic Revolutionary Guard Corps and other Iranian government and university clients.

The indictment alleges Mabna’s founders established the firm to help Iranian universities and research organizations obtain scientific resources from abroad and that the group employed or contracted hackers who carried out phishing attacks, probed for vulnerable systems and traded credentials for compromised accounts.

Scope and scale of the alleged intrusions

According to the Justice Department, the Mabna campaign targeted systems belonging to 144 U.S. universities and 178 universities abroad, at least 42 U.S. companies and 11 foreign companies, and at least five federal and state government agencies, with activity stretching back to around 2013. The victims named by prosecutors include the Labor Department, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF. Prosecutors also said the hackers targeted HBO and unnamed technology firms and defense contractors.

The indictment says the university campaign targeted more than 100,000 professors’ accounts worldwide and successfully compromised approximately 8,000 accounts. Stolen credentials were used to access journals, dissertations, electronic books and other research across medicine, engineering and the social sciences. Prosecutors estimate the targeted materials had been procured or made available to U.S. universities at a cost of more than $3.4 billion, though they did not characterize that entire sum as a loss from the thefts.

Tactics and the market for stolen academic access

Prosecutors describe two Iran‑based websites used to monetize the thefts. One site offered academic resources taken from universities; the other allowed customers to sign in using compromised professors’ credentials and directly access university library systems. The charges allege Mabna members sold stolen material and access to customers in Iran, turning credential theft into a commercial service that fed institutional demand for scientific literature.

Charges, penalties, and incentives for capture

The defendants face offenses that include conspiracy to commit computer intrusions, wire fraud and aggravated identity theft. Some of those charges carry maximum prison sentences of 20 years. Separately, the State Department is offering a reward of up to $10 million for information leading to the location of five of the defendants named in the indictment.

Context: alleged Iran‑aligned activity during the ongoing war

Prosecutors and U.S. officials framed the indictment against a backdrop of broader cyber activity attributed to Iran or Iran‑aligned groups since February, after U.S. and Israeli strikes began. Those incidents, according to the reporting, include a disruptive attack against medical-technology company Stryker, the compromise of FBI Director Kash Patel’s personal email, attacks on industrial‑control systems across several U.S. sectors, and targeting of more than 30 Minnesota water systems plus water infrastructure in several other states in the last month—activity some officials suspect may be tied to Iran. U.S. officials told Nextgov/FCW they expected Iranian and Iran‑aligned cyber operations to continue regardless of whether fighting subsided.

What this means for technologists, policymakers, and universities

  • Technologists and security teams — Monitor and harden credential hygiene and library authentication systems: the indictment centers on harvested professor credentials and phishing-driven access, and prosecutors say compromised accounts were reused to enter campus systems.
  • Policymakers and law enforcement — The expanded charges and a State Department reward underscore a dual strategy of criminal prosecution and targeted incentives to locate alleged operators linked to state clients.
  • Universities and procurement leaders — Institutions face a practical challenge: prosecutors say stolen materials were resold and that tens of thousands of faculty accounts were targeted; colleges will need to reconcile that risk with the $3.4 billion figure prosecutors cited for access to the targeted materials, even though that sum was not framed as a direct measured loss.

The superseding indictment paints a picture of a sustained, commercially organized campaign that treated academic access as both intelligence collection and a product to be sold. Whether criminal charges and a $10 million reward will produce captures or curb similar operations remains a test of law enforcement and diplomatic reach—while universities, companies and agencies named in the indictment confront the operational consequences of credentials and research access being trafficked as commodities.

Original story at Defense One